Time Series Approach for Analysis and Prediction of Malware Trends Based on Open Source Intelligence

Authors

  • Tommy Nugraha Manoppo Universitas Sulawesi Barat
  • Abdul Gani Fadhlulrahman Universitas Negeri Gorontalo
  • Yudi Prayudi Universitas Islam Indonesia

DOI:

https://doi.org/10.57152/malcom.v6i2.2580

Keywords:

ARIMA, Digital Forensic Readiness, Open Source Intelligence, Time Series Forecasting, Malware Trends

Abstract

The growing threat of malware requires monitoring approaches that provide a continuous, measurable overview of threat trends. This study proposes an open-source intelligence-based malware trend monitoring system using time series forecasting and anomaly signaling. Data are obtained from the MalwareBazaar repository and processed into a daily malware activity time series, with contextual aggregation to identify dominant malware families. The AutoRegressive Integrated Moving Average (ARIMA) model is applied for short-horizon prediction, and statistical anomaly detection is implemented using Z-scores to flag activity deviations. The system is delivered as an interactive dashboard that visualizes daily malware trends, dominant malware families, forecasting outputs, and anomaly indicators. Experimental results show that ARIMA(2,0,0) provides measurable improvement over a naive persistence baseline, reducing MAE from 102.75 to 92.67 and RMSE from 125.13 to 109.73, while improving sMAPE from 26.74% to 24.48% on the evaluation window. The novelty of this work lies in integrating an OSINT malware repository signal, benchmarked statistical forecasting, quantitative evaluation, and anomaly signaling into a single monitoring dashboard. Practically, the system can support SOC analysts by providing early-warning cues for monitoring prioritization and support digital forensic practitioners by strengthening digital forensic readiness through earlier visibility emerging malware activity dynamics and dominant artifact categories.

Downloads

Download data is not yet available.

References

M. Landauer, F. Skopik, B. Stojanovi?, A. Flatscher, and T. Ullrich, “A review of time-series analysis for cyber security analytics: from intrusion detection to attack prediction,” International Journal of Information Security, vol. 24, no. 1, Art. no. 3, 2024, doi: 10.1007/s10207-024-00921-0.

E. Condon, A. He, and M. Cukier, “Analysis of Computer Security Incident Data Using Time Series Models,” in Proc. IEEE International Symposium on Software Reliability Engineering (ISSRE), 2008, pp. 77–86, doi: 10.1109/ISSRE.2008.39.

W. Tounsi and H. Rais, “A survey on technical threat intelligence in the age of sophisticated cyber attacks,” Computers & Security, vol. 72, pp. 212–233, 2018, doi: 10.1016/j.cose.2017.09.001.

Y.-T. Huang, C.-Y. Lin, Y.-R. Guo, K.-C. Lo, Y. S. Sun, and M.-C. Chen, “Open Source Intelligence for Malicious Behavior Discovery and Interpretation,” IEEE Transactions on Dependable and Secure Computing, vol. 19, no. 2, pp. 776–789, 2022, doi: 10.1109/TDSC.2021.3119008.

Abuse.ch, “MalwareBazaar: Malware sample exchange platform,” 2026. [Online]. Available: bazaar.abuse.ch. Accessed: Mar. 5, 2026.

C. Wagner, A. Dulaunoy, G. Wagener, and A. Iklody, “MISP: The Design and Implementation of a Collaborative Threat Intelligence Sharing Platform,” in Proc. ACM Workshop on Information Sharing and Collaborative Security (WISCS), 2016, pp. 49–56, doi: 10.1145/2994539.2994542.

M. Vielberth, F. Böhm, I. Fichtinger, and G. Pernul, “Security Operations Center: A Systematic Study and Open Challenges,” IEEE Access, vol. 8, pp. 7756–7782, 2020, doi: 10.1109/ACCESS.2020.3045514.

A. Taiwo, F. Bankole, and I. Claims, “An extended digital forensic readiness and maturity model,” Forensic Science International: Digital Investigation, vol. 40, Art. no. 301348, 2022, doi: 10.1016/j.fsidi.2022.301348.

Y. Prayudi, A. Ashari, and T. K. Priyambodo, “The Framework to Support the Digital Evidence Handling: A Case Study of Procedures for the Management of Evidence in Indonesia,” Journal of Cases on Information Technology, vol. 22, no. 3, 2020, doi: 10.4018/JCIT.2020070104.

J. Kohlrausch and E. A. Brin, “ARIMA Supplemented Security Metrics for Quality Assurance and Situational Awareness,” Digital Threats: Research and Practice, vol. 1, no. 1, 2020, doi: 10.1145/3376926.

V. Chandola, A. Banerjee, and V. Kumar, “Anomaly detection: A survey,” ACM Computing Surveys, vol. 41, no. 3, 2009, doi: 10.1145/1541880.1541882.

R. J. Hyndman and A. B. Koehler, “Another look at measures of forecast accuracy,” International Journal of Forecasting, vol. 22, no. 4, pp. 679–688, 2006, doi: 10.1016/j.ijforecast.2006.03.001.

R. J. Hyndman and G. Athanasopoulos, Forecasting: Principles and Practice, 3rd ed. Melbourne, Australia: OTexts, 2021.

G. E. P. Box, G. M. Jenkins, G. C. Reinsel, and G. M. Ljung, Time Series Analysis: Forecasting and Control, 5th ed. Hoboken, NJ, USA: Wiley, 2015.

Statsmodels Developers, “ARIMA model (statsmodels.tsa.arima.model.ARIMA) documentation,” accessed Mar. 5, 2026.

H. Hewamalage, K. Ackermann, and C. Bergmeir, “Forecast evaluation for data scientists: common pitfalls and best practices,” Data Mining and Knowledge Discovery, 2023, doi: 10.1007/s10618-022-00894-5.

S. Makridakis, E. Spiliotis, and V. Assimakopoulos, “Statistical and machine learning forecasting methods: Concerns and ways forward,” PLOS ONE, vol. 13, no. 3, e0194889, 2018, doi: 10.1371/journal.pone.0194889.

S. Makridakis, E. Spiliotis, and V. Assimakopoulos, “The M4 Competition: 100,000 time series and 61 forecasting methods,” International Journal of Forecasting, vol. 36, no. 1, pp. 54–74, 2020, doi: 10.1016/j.ijforecast.2019.04.014.

Z. Zamanzadeh Darban, G. I. Webb, S. Pan, C. C. Aggarwal, and M. Salehi, “Deep Learning for Time Series Anomaly Detection: A Survey,” ACM Computing Surveys, vol. 57, no. 1, Art. no. 15, 2024, doi: 10.1145/3691338.

C. Johnson et al., “Guide to Cyber Threat Information Sharing,” NIST Special Publication 800-150, 2016.

E. M. Hutchins, M. J. Cloppert, and R. M. Amin, “Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains,” Lockheed Martin white paper, 2011.

FIRST CTI SIG, “Methods and Methodology: Cyber Threat Intelligence cycle and workflow,” accessed Mar. 5, 2026.

C. Johnson et al., “Guide to Cyber Threat Information Sharing,” NIST SP 800-150, accessed Mar. 5, 2026.

Verizon, 2025 Data Breach Investigations Report (DBIR), 2025.

S. Baratsas et al., “A hybrid statistical and machine learning based forecasting framework for the energy sector,” Computers & Chemical Engineering, 2024, doi: 10.1016/j.compchemeng.2024.108740.

Downloads

Published

2026-04-19

How to Cite

Manoppo, T. N., Fadhlulrahman, A. G., & Prayudi, Y. (2026). Time Series Approach for Analysis and Prediction of Malware Trends Based on Open Source Intelligence. MALCOM: Indonesian Journal of Machine Learning and Computer Science, 6(2), 568-576. https://doi.org/10.57152/malcom.v6i2.2580