Early Ransomware Detection with Deep Learning Models

被引:0
|
作者
Davidian, Matan [1 ]
Kiperberg, Michael [1 ]
Vanetik, Natalia [1 ]
机构
[1] Shamoon Coll Engn, Dept Software Engn, IL-84100 Beer Sheva, Israel
关键词
ransomware; deep learning; API call sequences; cybersecurity; malware detection; behavioral analysis;
D O I
10.3390/fi16080291
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Ransomware is a growing-in-popularity type of malware that restricts access to the victim's system or data until a ransom is paid. Traditional detection methods rely on analyzing the malware's content, but these methods are ineffective against unknown or zero-day malware. Therefore, zero-day malware detection typically involves observing the malware's behavior, specifically the sequence of application programming interface (API) calls it makes, such as reading and writing files or enumerating directories. While previous studies have used machine learning (ML) techniques to classify API call sequences, they have only considered the API call name. This paper systematically compares various subsets of API call features, different ML techniques, and context-window sizes to identify the optimal ransomware classifier. Our findings indicate that a context-window size of 7 is ideal, and the most effective ML techniques are CNN and LSTM. Additionally, augmenting the API call name with the operation result significantly enhances the classifier's precision. Performance analysis suggests that this classifier can be effectively applied in real-time scenarios.
引用
收藏
页数:37
相关论文
共 50 条
  • [31] Ransomware detection using machine learning algorithms
    Bae, Seong Il
    Lee, Gyu Bin
    Im, Eul Gyu
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2020, 32 (18):
  • [32] Ransomware Classification and Detection With Machine Learning Algorithms
    Masum, Mohammad
    Faruk, Md Jobair Hossain
    Shahriar, Hossain
    Qian, Kai
    Lo, Dan
    Adnan, Muhaiminul Islam
    2022 IEEE 12TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE (CCWC), 2022, : 316 - 322
  • [33] Ransomware Detection Using Machine Learning: A Survey
    Alraizza, Amjad
    Algarni, Abdulmohsen
    BIG DATA AND COGNITIVE COMPUTING, 2023, 7 (03)
  • [34] Evaluating Explainable AI Methods in Deep Learning Models for Early Detection of Cerebral Palsy
    Pellano, Kimji N.
    Strumke, Inga
    Groos, Daniel
    Adde, Lars
    Ihlen, Espen F. Alexander
    IEEE ACCESS, 2025, 13 : 10126 - 10138
  • [35] Evaluating Shallow and Deep Networks for Ransomware Detection and Classification
    Vinayakumar, R.
    Soman, K. P.
    Velan, K. K. Senthil
    Ganorkar, Shaunak
    2017 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2017, : 259 - 265
  • [36] Change Point Detection with Machine Learning for Rapid Ransomware Detection
    Melaragno, Anthony
    Casey, William
    2022 IEEE INTL CONF ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING, INTL CONF ON PERVASIVE INTELLIGENCE AND COMPUTING, INTL CONF ON CLOUD AND BIG DATA COMPUTING, INTL CONF ON CYBER SCIENCE AND TECHNOLOGY CONGRESS (DASC/PICOM/CBDCOM/CYBERSCITECH), 2022, : 154 - 162
  • [37] Deep Learning Models for Automatic Makeup Detection
    Alzahrani, Theiab
    Al-Bander, Baidaa
    Al-Nuaimy, Waleed
    AI, 2021, 2 (04) : 497 - 511
  • [38] On Deep Learning Models for Detection of Thunderstorm Gale
    Li, Yan
    Li, Haifeng
    Li, Xutao
    Li, Xian
    Xie, Pengfei
    JOURNAL OF INTERNET TECHNOLOGY, 2020, 21 (04): : 909 - 917
  • [39] Optimizing Deep Learning Models for Object Detection
    Barburescu, Calin-George
    Iuhasz, Gabriel
    2020 22ND INTERNATIONAL SYMPOSIUM ON SYMBOLIC AND NUMERIC ALGORITHMS FOR SCIENTIFIC COMPUTING (SYNASC 2020), 2020, : 270 - 277
  • [40] Early Ransomware Detection System Based on Network Behavior
    Abu-Helo, Hamdi
    Ashqar, Huthaifa
    ADVANCED INFORMATION NETWORKING AND APPLICATIONS, VOL 5, AINA 2024, 2024, 203 : 447 - 458