Anomeryx Endpoint Prototype for Behaviour-Based Risk Scoring and Malware Classification

Authors

Nurain Farhana Asilah Binti Sharudin

Faculty of Artificial Intelligence and Cyber Security Universiti Teknikal Malaysia Melaka (UTeM), Melaka (Malaysia)

Muhammad Bin Amran

Faculty of Artificial Intelligence and Cyber Security Universiti Teknikal Malaysia Melaka (UTeM), Melaka (Malaysia)

Article Information

DOI: 10.47772/IJRISS.2026.100900176

Subject Category: Social science

Volume/Issue: 10/9 | Page No: 2469-2475

Publication Timeline

Submitted: 2026-09-20

Accepted: 2026-09-25

Published: 2026-10-05

Abstract

Anomeryx is a local Windows endpoint prototype that integrates malware classification, behavioural risk scoring and persistent alert logging. The study evaluates classifier performance on API-call data, the functional response of the scoring mechanism and resource utilisation in a controlled virtual machine. API-call sequences from MalBehavD-V1 are converted into frequency features, selected using particle swarm optimisation (PSO) and classified by a multilayer perceptron (MLP). A weighted scoring layer combines classifier confidence with normalised file entropy, file-change rate, registry activity and process anomaly to assign five severity levels. Evaluation of 514 benign and malicious samples produced 92.22% accuracy, 97.38% precision, 86.77% recall and 91.77% F1-score. Controlled ransomware-like simulation exercised the scoring and logging functions, including a Critical scenario with a score of 91. Observed CPU utilisation was approximately 3% during live monitoring and 51% during training. The findings demonstrate functional integration within the prototype’s scope. Classification results remain preliminary because independence between feature selection and the test partition is not established. General malware labels, simulated behavioural indicators and testing on one virtual machine also limit ransomware-specific and deployment claims. Further validation involves independent test partitions, ransomware-labelled data, comparative scoring experiments and repeated measurements with live endpoint telemetry.

Keywords

endpoint security; malware classification; ransomware; behavioural risk scoring; multilayer perceptron.

Downloads

References

1. Masum, M., Faruk, M. J. H., Shahriar, H., Qian, K., Lo, D., & Adnan, M. I. (2022). Ransomware classification and detection with machine learning algorithms. In 2022 IEEE 12th Annual Computing and Communication Workshop and Conference (CCWC) (pp. 316–322). IEEE. https://doi.org/10.1109/CCWC54503.2022.9720869 [Google Scholar] [Crossref]

2. Abbasi, M. S. (2023). Automating behavior-based ransomware analysis, detection, and classification using machine learning [Doctoral thesis, Victoria University of Wellington]. https://openaccess.wgtn.ac.nz/articles/thesis/22180858 [Google Scholar] [Crossref]

3. Begovic, K., Al-Ali, A., & Malluhi, Q. (2023). Cryptographic ransomware encryption detection: Survey. arXiv. https://doi.org/10.48550/arXiv.2306.12008 [Google Scholar] [Crossref]

4. Ferdous, J., et al. (2024). AI-based ransomware detection: A comprehensive review. IEEE Access, 12, 136666–136695. https://doi.org/10.1109/ACCESS.2024.3461965 [Google Scholar] [Crossref]

5. Brodzik, A., et al. (2024). Ransomware detection using machine learning in the Linux kernel. arXiv. https://doi.org/10.48550/arXiv.2409.06452 [Google Scholar] [Crossref]

6. Davidian, M., Kiperberg, M., & Vanetik, N. (2024). Early ransomware detection with deep learning models. Future Internet, 16(8), Article 291. https://doi.org/10.3390/fi16080291 [Google Scholar] [Crossref]

7. Gurukala, N. K. Y., & Verma, D. K. (2024). Feature selection using particle swarm optimization and ensemble-based machine learning models for ransomware detection. SN Computer Science, 5. https://doi.org/10.1007/s42979-024-03454-4 [Google Scholar] [Crossref]

8. Chew, C. J. W., Kumar, V., Patros, P., & Malik, R. (2024). Real-time system call-based ransomware detection. International Journal of Information Security, 23, 1839–1858. https://doi.org/10.1007/s10207-024-00819-x [Google Scholar] [Crossref]

9. Putrevu, M. A., et al. (2024). A comprehensive analysis of machine learning based file trap selection methods to detect crypto ransomware. arXiv. https://doi.org/10.48550/arXiv.2409.11428 [Google Scholar] [Crossref]

10. Arányi, G., Miseta, T., & Szücs, V. (2026). Ransomware detection based on server-side file operation logs using machine learning. Journal on Information Security, 2026, Article 8. https://doi.org/10.1186/s13635-026-00229-7 [Google Scholar] [Crossref]

11. mpasco. (n.d.). MalBehavD-V1: A dataset of API calls extracted from malware and benign executable files in Windows [Data set]. GitHub. Retrieved September 22, 2026, from https://github.com/mpasco/MalbehavD-V1 [Google Scholar] [Crossref]

Metrics

Views & Downloads

Similar Articles