{"id":"https://openalex.org/W4406563968","doi":"https://doi.org/10.1016/j.hcc.2025.100299","title":"Reinforcement learning for an efficient and effective malware investigation during cyber incident response","display_name":"Reinforcement learning for an efficient and effective malware investigation during cyber incident response","publication_year":2025,"publication_date":"2025-01-18","ids":{"openalex":"https://openalex.org/W4406563968","doi":"https://doi.org/10.1016/j.hcc.2025.100299"},"language":"en","primary_location":{"id":"doi:10.1016/j.hcc.2025.100299","is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.hcc.2025.100299","pdf_url":null,"source":{"id":"https://openalex.org/S4210186527","display_name":"High-Confidence Computing","issn_l":"2667-2952","issn":["2667-2952"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"High-Confidence Computing","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1016/j.hcc.2025.100299","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5025816613","display_name":"Dipo Dunsin","orcid":"https://orcid.org/0009-0009-7376-0477"},"institutions":[{"id":"https://openalex.org/I126193024","display_name":"London Metropolitan University","ror":"https://ror.org/00ae33288","country_code":"GB","type":"education","lineage":["https://openalex.org/I126193024"]}],"countries":["GB"],"is_corresponding":true,"raw_author_name":"Dipo Dunsin","raw_affiliation_strings":["Cyber Security Research Centre, London Metropolitan University, London N7 8DB, UK","Cyber Security Research Centre, London Metropolitan University, London UK","Cyber Security Research Centre, London Metropolitan University, London, UK"],"raw_orcid":"https://orcid.org/0009-0009-7376-0477","affiliations":[{"raw_affiliation_string":"Cyber Security Research Centre, London Metropolitan University, London N7 8DB, UK","institution_ids":["https://openalex.org/I126193024"]},{"raw_affiliation_string":"Cyber Security Research Centre, London Metropolitan University, London UK","institution_ids":["https://openalex.org/I126193024"]},{"raw_affiliation_string":"Cyber Security Research Centre, London Metropolitan University, London, UK","institution_ids":["https://openalex.org/I126193024"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101549630","display_name":"Mohamed Chahine Ghanem","orcid":"https://orcid.org/0000-0002-7067-7848"},"institutions":[{"id":"https://openalex.org/I126193024","display_name":"London Metropolitan University","ror":"https://ror.org/00ae33288","country_code":"GB","type":"education","lineage":["https://openalex.org/I126193024"]},{"id":"https://openalex.org/I146655781","display_name":"University of Liverpool","ror":"https://ror.org/04xs57h96","country_code":"GB","type":"education","lineage":["https://openalex.org/I146655781"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Mohamed Chahine Ghanem","raw_affiliation_strings":["Cyber Security Research Centre, London Metropolitan University, London N7 8DB, UK","Department of Computer Science, University of Liverpool, Liverpool L69 7ZX, UK","Cyber Security Research Centre, London Metropolitan University, London UK","Cyber Security Research Centre, London Metropolitan University, London, UK"],"raw_orcid":"https://orcid.org/0000-0002-7067-7848","affiliations":[{"raw_affiliation_string":"Cyber Security Research Centre, London Metropolitan University, London N7 8DB, UK","institution_ids":["https://openalex.org/I126193024"]},{"raw_affiliation_string":"Department of Computer Science, University of Liverpool, Liverpool L69 7ZX, UK","institution_ids":["https://openalex.org/I146655781"]},{"raw_affiliation_string":"Cyber Security Research Centre, London Metropolitan University, London UK","institution_ids":["https://openalex.org/I126193024"]},{"raw_affiliation_string":"Cyber Security Research Centre, London Metropolitan University, London, UK","institution_ids":["https://openalex.org/I126193024"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5014413828","display_name":"Karim Ouazzane","orcid":"https://orcid.org/0000-0002-7129-5809"},"institutions":[{"id":"https://openalex.org/I126193024","display_name":"London Metropolitan University","ror":"https://ror.org/00ae33288","country_code":"GB","type":"education","lineage":["https://openalex.org/I126193024"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Karim Ouazzane","raw_affiliation_strings":["Cyber Security Research Centre, London Metropolitan University, London N7 8DB, UK","Cyber Security Research Centre, London Metropolitan University, London UK","Cyber Security Research Centre, London Metropolitan University, London, UK"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Cyber Security Research Centre, London Metropolitan University, London N7 8DB, UK","institution_ids":["https://openalex.org/I126193024"]},{"raw_affiliation_string":"Cyber Security Research Centre, London Metropolitan University, London UK","institution_ids":["https://openalex.org/I126193024"]},{"raw_affiliation_string":"Cyber Security Research Centre, London Metropolitan University, London, UK","institution_ids":["https://openalex.org/I126193024"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5062364356","display_name":"Vassil Vassilev","orcid":"https://orcid.org/0000-0003-4361-4830"},"institutions":[{"id":"https://openalex.org/I126193024","display_name":"London Metropolitan University","ror":"https://ror.org/00ae33288","country_code":"GB","type":"education","lineage":["https://openalex.org/I126193024"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Vassil Vassilev","raw_affiliation_strings":["Cyber Security Research Centre, London Metropolitan University, London N7 8DB, UK","Cyber Security Research Centre, London Metropolitan University, London UK","Cyber Security Research Centre, London Metropolitan University, London, UK"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Cyber Security Research Centre, London Metropolitan University, London N7 8DB, UK","institution_ids":["https://openalex.org/I126193024"]},{"raw_affiliation_string":"Cyber Security Research Centre, London Metropolitan University, London UK","institution_ids":["https://openalex.org/I126193024"]},{"raw_affiliation_string":"Cyber Security Research Centre, London Metropolitan University, London, UK","institution_ids":["https://openalex.org/I126193024"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5025816613"],"corresponding_institution_ids":["https://openalex.org/I126193024"],"apc_list":{"value":1500,"currency":"USD","value_usd":1500},"apc_paid":{"value":1500,"currency":"USD","value_usd":1500},"fwci":10.7392,"has_fulltext":true,"cited_by_count":17,"citation_normalized_percentile":{"value":0.98926048,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":99,"max":100},"biblio":{"volume":"5","issue":"3","first_page":"100299","last_page":"100299"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9976000189781189,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9868999719619751,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.6766939163208008},{"id":"https://openalex.org/keywords/incident-response","display_name":"Incident response","score":0.6739110946655273},{"id":"https://openalex.org/keywords/reinforcement","display_name":"Reinforcement","score":0.619932234287262},{"id":"https://openalex.org/keywords/reinforcement-learning","display_name":"Reinforcement learning","score":0.48098933696746826},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.4670119881629944},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4154902696609497},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.308184951543808},{"id":"https://openalex.org/keywords/psychology","display_name":"Psychology","score":0.277160108089447},{"id":"https://openalex.org/keywords/social-psychology","display_name":"Social psychology","score":0.1207132637500763}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.6766939163208008},{"id":"https://openalex.org/C2985105721","wikidata":"https://www.wikidata.org/wiki/Q13479512","display_name":"Incident response","level":2,"score":0.6739110946655273},{"id":"https://openalex.org/C67203356","wikidata":"https://www.wikidata.org/wiki/Q1321905","display_name":"Reinforcement","level":2,"score":0.619932234287262},{"id":"https://openalex.org/C97541855","wikidata":"https://www.wikidata.org/wiki/Q830687","display_name":"Reinforcement learning","level":2,"score":0.48098933696746826},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.4670119881629944},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4154902696609497},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.308184951543808},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.277160108089447},{"id":"https://openalex.org/C77805123","wikidata":"https://www.wikidata.org/wiki/Q161272","display_name":"Social psychology","level":1,"score":0.1207132637500763}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1016/j.hcc.2025.100299","is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.hcc.2025.100299","pdf_url":null,"source":{"id":"https://openalex.org/S4210186527","display_name":"High-Confidence Computing","issn_l":"2667-2952","issn":["2667-2952"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"High-Confidence Computing","raw_type":"journal-article"},{"id":"pmh:oai:repository.londonmet.ac.uk:9838","is_oa":true,"landing_page_url":null,"pdf_url":"https://repository.londonmet.ac.uk/9838/1/Reinforcement_Learning_for_an_Efficient_and_Effective_Malware_Investigation_during_Cyber_Incident_Response-ACCEPTED.pdf","source":{"id":"https://openalex.org/S4306400140","display_name":"London Met Repository (London Metropolitan University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I126193024","host_organization_name":"London Metropolitan University","host_organization_lineage":["https://openalex.org/I126193024"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},{"id":"pmh:oai:doaj.org/article:c4cd04b6040b4ef2bf531fb8c7cb6f3a","is_oa":true,"landing_page_url":"https://doaj.org/article/c4cd04b6040b4ef2bf531fb8c7cb6f3a","pdf_url":null,"source":{"id":"https://openalex.org/S4306401280","display_name":"DOAJ (DOAJ: Directory of Open Access Journals)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"High-Confidence Computing, Vol 5, Iss 3, Pp 100299- (2025)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.1016/j.hcc.2025.100299","is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.hcc.2025.100299","pdf_url":null,"source":{"id":"https://openalex.org/S4210186527","display_name":"High-Confidence Computing","issn_l":"2667-2952","issn":["2667-2952"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"High-Confidence Computing","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":36,"referenced_works":["https://openalex.org/W51113573","https://openalex.org/W1673923490","https://openalex.org/W2062324702","https://openalex.org/W2129727551","https://openalex.org/W2257979135","https://openalex.org/W2784452215","https://openalex.org/W2800244495","https://openalex.org/W2931858311","https://openalex.org/W2932977083","https://openalex.org/W2963178695","https://openalex.org/W2991680373","https://openalex.org/W2998074434","https://openalex.org/W3109594330","https://openalex.org/W3134215180","https://openalex.org/W3158179156","https://openalex.org/W3182015545","https://openalex.org/W4221154652","https://openalex.org/W4235928690","https://openalex.org/W4243417494","https://openalex.org/W4254197915","https://openalex.org/W4297477879","https://openalex.org/W4309089711","https://openalex.org/W4313216189","https://openalex.org/W4323565799","https://openalex.org/W4365514507","https://openalex.org/W4388676551","https://openalex.org/W4388722750","https://openalex.org/W4394673362","https://openalex.org/W4403574142","https://openalex.org/W6745899033","https://openalex.org/W6757096292","https://openalex.org/W6779385888","https://openalex.org/W6780442186","https://openalex.org/W6786915083","https://openalex.org/W6787013399","https://openalex.org/W7015966957"],"related_works":["https://openalex.org/W2097492617","https://openalex.org/W2753240997","https://openalex.org/W1764168690","https://openalex.org/W2537959205","https://openalex.org/W2740895074","https://openalex.org/W2772446090","https://openalex.org/W4284893819","https://openalex.org/W4310083477","https://openalex.org/W2328553770","https://openalex.org/W2914307994"],"abstract_inverted_index":{"The":[0,31,66,102,118,130],"ever-escalating":[1],"prevalence":[2],"of":[3,63,79,137,173,209],"malware":[4,24,49,64,100,166,210],"is":[5],"a":[6,20,42,169],"serious":[7],"cybersecurity":[8],"threat,":[9],"often":[10],"requiring":[11],"advanced":[12,196],"post-incident":[13,165,186],"forensic":[14,106,211],"investigation":[15],"techniques.":[16],"This":[17,56,156],"paper":[18],"proposes":[19],"framework":[21,67,92],"to":[22,73,184,204],"enhance":[23,206],"forensics":[25,187],"by":[26,39],"leveraging":[27],"reinforcement":[28],"learning":[29,131],"(RL).":[30],"approach":[32],"combines":[33],"heuristic":[34],"and":[35,54,61,70,77,82,108,114,148,199],"signature-based":[36],"methods,":[37],"supported":[38],"RL":[40,103,197],"through":[41,112],"unified":[43],"MDP":[44,139],"model,":[45],"which":[46],"breaks":[47],"down":[48],"analysis":[50],"into":[51],"distinct":[52],"states":[53],"actions.":[55],"optimisation":[57],"enhances":[58],"the":[59,75,90,135,138,161,207],"identification":[60],"classification":[62],"variants.":[65],"employs":[68],"Q-learning":[69,125],"other":[71],"techniques":[72],"boost":[74],"speed":[76],"accuracy":[78,171],"detecting":[80],"new":[81],"unknown":[83],"malware,":[84],"outperforming":[85],"traditional":[86],"methods.":[87],"We":[88],"tested":[89],"experimental":[91],"across":[93],"multiple":[94],"virtual":[95],"environments":[96],"infected":[97],"with":[98,124],"various":[99],"types.":[101],"agent":[104],"collected":[105],"evidence":[107],"improved":[109],"its":[110],"performance":[111],"Q-tables":[113],"temporal":[115],"difference":[116],"learning.":[117],"epsilon-greedy":[119],"exploration":[120],"strategy,":[121],"in":[122,142,150,176,189],"conjunction":[123],"updates,":[126],"effectively":[127],"facilitated":[128],"transitions.":[129],"rate":[132,172],"depended":[133],"on":[134],"complexity":[136],"environment:":[140],"higher":[141],"simpler":[143],"ones":[144,153],"for":[145,154,164],"quicker":[146],"convergence":[147],"lower":[149],"more":[151,195],"complex":[152],"stability.":[155],"RL-enhanced":[157],"model":[158],"significantly":[159],"reduced":[160],"time":[162],"required":[163],"investigations,":[167],"achieving":[168],"high":[170],"94":[174],"%":[175],"identifying":[177],"malware.":[178],"These":[179],"results":[180],"indicate":[181],"RL\u2019s":[182],"potential":[183],"revolutionise":[185],"investigations":[188],"cybersecurity.":[190],"Future":[191],"work":[192],"will":[193],"incorporate":[194],"algorithms":[198],"large":[200],"language":[201],"models":[202],"(LLMs)":[203],"further":[205],"effectiveness":[208],"analysis.":[212]},"counts_by_year":[{"year":2026,"cited_by_count":7},{"year":2025,"cited_by_count":10}],"updated_date":"2026-07-28T07:46:37.118299","created_date":"2025-10-10T00:00:00"}
