Anomeryx Endpoint Prototype for Behaviour-Based Risk Scoring and Malware Classification
Authors
Nurain Farhana Asilah Binti Sharudin
Faculty of Artificial Intelligence and Cyber Security Universiti Teknikal Malaysia Melaka (UTeM), Melaka (Malaysia)
Faculty of Artificial Intelligence and Cyber Security Universiti Teknikal Malaysia Melaka (UTeM), Melaka (Malaysia)
Article Information
DOI: 10.47772/IJRISS.2026.100900176
Subject Category: Social science
Volume/Issue: 10/9 | Page No: 2469-2475
Publication Timeline
Submitted: 2026-09-20
Accepted: 2026-09-25
Published: 2026-10-05
Abstract
Anomeryx is a local Windows endpoint prototype that integrates malware classification, behavioural risk scoring and persistent alert logging. The study evaluates classifier performance on API-call data, the functional response of the scoring mechanism and resource utilisation in a controlled virtual machine. API-call sequences from MalBehavD-V1 are converted into frequency features, selected using particle swarm optimisation (PSO) and classified by a multilayer perceptron (MLP). A weighted scoring layer combines classifier confidence with normalised file entropy, file-change rate, registry activity and process anomaly to assign five severity levels. Evaluation of 514 benign and malicious samples produced 92.22% accuracy, 97.38% precision, 86.77% recall and 91.77% F1-score. Controlled ransomware-like simulation exercised the scoring and logging functions, including a Critical scenario with a score of 91. Observed CPU utilisation was approximately 3% during live monitoring and 51% during training. The findings demonstrate functional integration within the prototype’s scope. Classification results remain preliminary because independence between feature selection and the test partition is not established. General malware labels, simulated behavioural indicators and testing on one virtual machine also limit ransomware-specific and deployment claims. Further validation involves independent test partitions, ransomware-labelled data, comparative scoring experiments and repeated measurements with live endpoint telemetry.
Keywords
endpoint security; malware classification; ransomware; behavioural risk scoring; multilayer perceptron.
Downloads
References
1. Masum, M., Faruk, M. J. H., Shahriar, H., Qian, K., Lo, D., & Adnan, M. I. (2022). Ransomware classification and detection with machine learning algorithms. In 2022 IEEE 12th Annual Computing and Communication Workshop and Conference (CCWC) (pp. 316–322). IEEE. https://doi.org/10.1109/CCWC54503.2022.9720869 [Google Scholar] [Crossref]
2. Abbasi, M. S. (2023). Automating behavior-based ransomware analysis, detection, and classification using machine learning [Doctoral thesis, Victoria University of Wellington]. https://openaccess.wgtn.ac.nz/articles/thesis/22180858 [Google Scholar] [Crossref]
3. Begovic, K., Al-Ali, A., & Malluhi, Q. (2023). Cryptographic ransomware encryption detection: Survey. arXiv. https://doi.org/10.48550/arXiv.2306.12008 [Google Scholar] [Crossref]
4. Ferdous, J., et al. (2024). AI-based ransomware detection: A comprehensive review. IEEE Access, 12, 136666–136695. https://doi.org/10.1109/ACCESS.2024.3461965 [Google Scholar] [Crossref]
5. Brodzik, A., et al. (2024). Ransomware detection using machine learning in the Linux kernel. arXiv. https://doi.org/10.48550/arXiv.2409.06452 [Google Scholar] [Crossref]
6. Davidian, M., Kiperberg, M., & Vanetik, N. (2024). Early ransomware detection with deep learning models. Future Internet, 16(8), Article 291. https://doi.org/10.3390/fi16080291 [Google Scholar] [Crossref]
7. Gurukala, N. K. Y., & Verma, D. K. (2024). Feature selection using particle swarm optimization and ensemble-based machine learning models for ransomware detection. SN Computer Science, 5. https://doi.org/10.1007/s42979-024-03454-4 [Google Scholar] [Crossref]
8. Chew, C. J. W., Kumar, V., Patros, P., & Malik, R. (2024). Real-time system call-based ransomware detection. International Journal of Information Security, 23, 1839–1858. https://doi.org/10.1007/s10207-024-00819-x [Google Scholar] [Crossref]
9. Putrevu, M. A., et al. (2024). A comprehensive analysis of machine learning based file trap selection methods to detect crypto ransomware. arXiv. https://doi.org/10.48550/arXiv.2409.11428 [Google Scholar] [Crossref]
10. Arányi, G., Miseta, T., & Szücs, V. (2026). Ransomware detection based on server-side file operation logs using machine learning. Journal on Information Security, 2026, Article 8. https://doi.org/10.1186/s13635-026-00229-7 [Google Scholar] [Crossref]
11. mpasco. (n.d.). MalBehavD-V1: A dataset of API calls extracted from malware and benign executable files in Windows [Data set]. GitHub. Retrieved September 22, 2026, from https://github.com/mpasco/MalbehavD-V1 [Google Scholar] [Crossref]
Metrics
Views & Downloads
Similar Articles
- The Impact of Ownership Structure on Dividend Payout Policy of Listed Plantation Companies in Sri Lanka
- Urban Sustainability in North-East India: A Study through the lens of NER-SDG index
- Performance Assessment of Predictive Forecasting Techniques for Enhancing Hospital Supply Chain Efficiency in Healthcare Logistics
- The Fractured Self in Julian Barnes' Postmodern Fiction: Identity Crisis and Deflation in Metroland and the Sense of an Ending
- Impact of Flood on the Employment, Labour Productivity and Migration of Agricultural Labour in North Bihar