Implementasi Sistem Deteksi Malware Berbasis Random Forest pada File Portable Executable Windows

dc.contributor.advisorKushardianto, Nur Cahyono
dc.contributor.authorTampubolon, Cindy Laura
dc.date.accessioned2026-08-24T07:57:26Z
dc.date.issued2026-08-14
dc.description.abstractThis research addresses the limitations of signature based malware detection against new variants in Windows Portable Executable files, along with the absence of an automated system with real time monitoring that requires no user intervention. Limited and homogeneous benign samples also introduce bias and a high false positive rate. To address this, the research develops a Random Forest based malware detection system integrated with a web dashboard and event driven file monitoring. The contribution includes designing an automated system, extracting static features from PE headers without executing files, and presenting confidence scores and feature importance on a web interface. The method involves feature extraction with the pefile library, directory monitoring with the Watchdog library, and training a Random Forest model on the PE-Malware-Dataset containing malware samples from five families along with benign samples from the Windows system. The research began modeling with an exploration of multi class classification, but accuracy remained low because header features did not sufficiently distinguish between families, so the final approach was set as binary classification, malware versus benign. Real time testing results confirmed that the end to end pipeline runs automatically. Initial evaluation on a small test set showed the model captured all malware samples but produced false positives on benign files, resulting in high recall paired with low precision and a moderate F score. Most false positives came from third party administrative utilities with a Portable Executable structure similar to malware. In conclusion, the system functions as a proof of concept for real time detection based on Random Forest and a web dashboard, but real world performance remains limited by benign data bias, so diversifying benign samples is needed to reduce false positives.
dc.identifier.citationIEEE
dc.identifier.kodeprodiKODEPRODI57302#Rekayasa Keamanan Siber
dc.identifier.nidnNIDN1011027902
dc.identifier.nimNIM4332211015
dc.identifier.urihttps://repository.polibatam.ac.id//handle/PL29/5860
dc.language.isoother
dc.publisherPoliteknik Negeri Batam
dc.subjectSOCIAL SCIENCES::Social sciences::Education
dc.subjectSOCIAL SCIENCES::Statistics, computer and systems science::Informatics, computer and systems science
dc.titleImplementasi Sistem Deteksi Malware Berbasis Random Forest pada File Portable Executable Windows
dc.typeArticle

Files

Original bundle

Now showing 1 - 3 of 3
Loading...
Thumbnail Image
Name:
Lembar_Pengesahan .pdf
Size:
117.37 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
4332211015_Rekayasa Keamanan Siber.pdf
Size:
617.44 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
Borang_Publikasi.pdf
Size:
209.47 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: