TY - GEN
T1 - Hybrid Intelligence Endpoint Defense (HIED)
T2 - 5th IEEE International Conference on AI in Cybersecurity, ICAIC 2026
AU - Jaworski, Michal
AU - Pahlevanzadeh, Bahareh
N1 - Publisher Copyright:
© 2026 IEEE.
PY - 2026
Y1 - 2026
N2 - We present Hybrid Intelligence Endpoint Defense (HIED), which combines Endpoint Detection and Response (EDR) telemetry with Cyber Threat Intelligence (CTI) to improve malware detection using data already available in enterprises. We use Windows 10 Sysmon logs (synthetic and real) and enrich them with AlienVault Open Threat Exchange (OTX) indicators (e.g., domains, IPs, hashes). We evaluate four ways to fuse the two sources: feature-level (early), decision-level (late) with two variants, and a combined scheme, training Random Forest, XGBoost, and Local Outlier Factor. Rather than attaching CTI via post-hoc lookups, we inject CTI at the feature stage and measure early versus late fusion directly. Early fusion performs best, raising the Matthews Correlation Coefficient from 0.94 (EDR-only) to 0.98, increasing recall from 87.58% to 99.60%, and cutting the false-positive rate from 0.09% to 0.02% on a held-out validation set. The gains come from adding external threat context that helps the classifier separate benign activity from ransomware-like behavior, reducing alert fatigue. The study fits ICAIC'2026 Tracks 8 (AI in Cyber Security), 12 (AI in Malware Analysis/Digital Forensics), and 6 (AI in IT Infrastructure) and shows that standard Sysmon logs plus open CTI can go further - no new sensors required. We also note deployment considerations and current limitations, and we outline next steps: real-time fusion, multi-feed CTI, and broader malware coverage.
AB - We present Hybrid Intelligence Endpoint Defense (HIED), which combines Endpoint Detection and Response (EDR) telemetry with Cyber Threat Intelligence (CTI) to improve malware detection using data already available in enterprises. We use Windows 10 Sysmon logs (synthetic and real) and enrich them with AlienVault Open Threat Exchange (OTX) indicators (e.g., domains, IPs, hashes). We evaluate four ways to fuse the two sources: feature-level (early), decision-level (late) with two variants, and a combined scheme, training Random Forest, XGBoost, and Local Outlier Factor. Rather than attaching CTI via post-hoc lookups, we inject CTI at the feature stage and measure early versus late fusion directly. Early fusion performs best, raising the Matthews Correlation Coefficient from 0.94 (EDR-only) to 0.98, increasing recall from 87.58% to 99.60%, and cutting the false-positive rate from 0.09% to 0.02% on a held-out validation set. The gains come from adding external threat context that helps the classifier separate benign activity from ransomware-like behavior, reducing alert fatigue. The study fits ICAIC'2026 Tracks 8 (AI in Cyber Security), 12 (AI in Malware Analysis/Digital Forensics), and 6 (AI in IT Infrastructure) and shows that standard Sysmon logs plus open CTI can go further - no new sensors required. We also note deployment considerations and current limitations, and we outline next steps: real-time fusion, multi-feed CTI, and broader malware coverage.
KW - AI in Cyber Security
KW - Cyber Threat Intelligence
KW - Data Fusion
KW - Digital Forensics
KW - Endpoint Detection and Response
KW - FastText
KW - IT Infrastructure
KW - Malware Analysis
KW - Sysmon
UR - https://www.scopus.com/pages/publications/105041770615
U2 - 10.1109/ICAIC67076.2026.11395833
DO - 10.1109/ICAIC67076.2026.11395833
M3 - Conference contribution
AN - SCOPUS:105041770615
T3 - 2026 IEEE 5th International Conference on AI in Cybersecurity, ICAIC 2026
BT - 2026 IEEE 5th International Conference on AI in Cybersecurity, ICAIC 2026
PB - Institute of Electrical and Electronics Engineers Inc.
Y2 - 18 February 2026 through 20 February 2026
ER -