Adaptive Feature Optimization for Machine Learning-Based Malware Family Classification
Abstract
Malware family classification is essential for understanding malicious software behaviour and supporting cybersecurity analysis. Existing machine learning approaches have demonstrated promising classification performance; however, many rely on high-dimensional feature sets that increase computational complexity and include redundant information with limited contribution to prediction. This paper proposes an Adaptive Feature Optimization (AFO) framework for malware family classification that improves the quality of input data before model training. The proposed method performs data cleaning followed by the removal of duplicate, low-variance, and highly correlated features, and then ranks the remaining attributes according to their importance for malware classification. The optimized feature subset is used to train a Random Forest classifier for identifying malware families using the CIC-MalMem-2022 dataset, which contains memory-based behavioural features collected from malware and benign software samples. The framework was implemented in Python and evaluated using standard experimental settings. The proposed model achieved an overall classification accuracy of 88.91%, demonstrating that feature optimization can simplify the learning process while maintaining reliable prediction performance. The proposed approach provides an interpretable and computationally efficient malware classification framework that is suitable for academic research and can serve as a practical baseline for future cybersecurity studies involving lightweight machine learning models.