Facebook pixel tracking

The Science and Information (SAI) Organization publishes open-access peer-reviewed journals in computer science and artificial intelligence.

Contact Info
Website thesai.org
Follow Us
Contact Info
Follow Us
Research Article | Open Access |

A Deep Learning-Based Dual-Model Framework for Real-Time Malware and Network Anomaly Detection with MITRE ATT&CK Integration

Author 1: Migara H. M. S Author 2: Sandakelum M. D. B Author 3: Maduranga D. B. W. N Author 4: Kumara D. D. K. C Author 5: Harinda Fernando Author 6: Kavinga Abeywardena
International Journal of Advanced Computer Science and Applications (IJACSA) · Vol. 16, No. 7 · Published 2025

DOI: https://doi.org/10.14569/IJACSA.2025.0160728

Abstract

The contemporary world of high connectivity in the digital realm has presented cybersecurity with more advanced threats, such as advanced malware and network attacks, which in most cases will not be detected using traditional detection tools. Static cybersecurity tools, which are traditional, often fail to deal with dynamic and hitherto unseen attacks, including signature-based antivirus systems and rule-based intrusion detection. To address this issue, we would suggest a two-part, AI-powered solution to cybersecurity which would allow real-time threat detection on an endpoint and a network level. The first element uses a Feed-forward Neural Network (FNN) to categorize Windows Porta-ble Executable (PE) files, whether they are benign or malicious, by using structured static features. The second component im-proves network anomaly detection with a deep learning model that is augmented by Generative Adversarial Networks (GAN) and effectively addresses the data imbalance issue and sensitivi-ty to rare cyber-attacks. To enhance its performance further, the system is integrated with the MITRE ATT&CK adversarial tactics and techniques, which correlate real-time detection re-sults with adversarial tactics and techniques, thus offering ac-tionable context to incident response teams. Tests based on open-source datasets provided accuracies of 98.0 per cent of malware detection and 96.2 per cent of network anomaly detec-tion. Data augmentation using GAN was very effective in im-proving the detection of less popular attacks, including SQL injections and internal reconnaissance. Moreover, the system is horizontally scalable and responsive in real-time due to Docker-based deployment. The suggested framework is an effective, explainable and scalable cybersecurity defense system, which is perfectly applicable to Managed Security Service Providers (MSSPs) and Security Operations Centers (SOCs), greatly in-creasing the precision rate and contextual insight of threat detection.

Keywords

How to Cite this Article

S, M. H. M., B, S. M. D., N, M. D. B. W., C, K. D. D. K., Fernando, H., & Abeywardena, K. (2025). A Deep Learning-Based Dual-Model Framework for Real-Time Malware and Network Anomaly Detection with MITRE ATT&CK Integration. International Journal of Advanced Computer Science and Applications, 16(7). https://doi.org/10.14569/IJACSA.2025.0160728

S, Migara H. M., et al.. "A Deep Learning-Based Dual-Model Framework for Real-Time Malware and Network Anomaly Detection with MITRE ATT&CK Integration." International Journal of Advanced Computer Science and Applications, vol. 16, no. 7, 2025, https://doi.org/10.14569/IJACSA.2025.0160728.

@article{S2025,
  title     = {A Deep Learning-Based Dual-Model Framework for Real-Time Malware and Network Anomaly Detection with MITRE ATT&CK Integration},
  journal   = {International Journal of Advanced Computer Science and Applications},
  volume    = {16},
  number    = {7},
  year      = {2025},
  publisher = {The Science and Information Organization},
  author    = {Migara H. M. S and Sandakelum M. D. B and Maduranga D. B. W. N and Kumara D. D. K. C and Harinda Fernando and Kavinga Abeywardena},
  doi       = {10.14569/IJACSA.2025.0160728},
  url       = {https://doi.org/10.14569/IJACSA.2025.0160728}
}

Open Access — licensed under a Creative Commons Attribution 4.0 International License. Unrestricted use, distribution, and reproduction in any medium, even commercially, as long as the original work is properly cited.