Early Ransomware Detection with Deep Learning Models

被引:0
|
作者
Davidian, Matan [1 ]
Kiperberg, Michael [1 ]
Vanetik, Natalia [1 ]
机构
[1] Shamoon Coll Engn, Dept Software Engn, IL-84100 Beer Sheva, Israel
关键词
ransomware; deep learning; API call sequences; cybersecurity; malware detection; behavioral analysis;
D O I
10.3390/fi16080291
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Ransomware is a growing-in-popularity type of malware that restricts access to the victim's system or data until a ransom is paid. Traditional detection methods rely on analyzing the malware's content, but these methods are ineffective against unknown or zero-day malware. Therefore, zero-day malware detection typically involves observing the malware's behavior, specifically the sequence of application programming interface (API) calls it makes, such as reading and writing files or enumerating directories. While previous studies have used machine learning (ML) techniques to classify API call sequences, they have only considered the API call name. This paper systematically compares various subsets of API call features, different ML techniques, and context-window sizes to identify the optimal ransomware classifier. Our findings indicate that a context-window size of 7 is ideal, and the most effective ML techniques are CNN and LSTM. Additionally, augmenting the API call name with the operation result significantly enhances the classifier's precision. Performance analysis suggests that this classifier can be effectively applied in real-time scenarios.
引用
收藏
页数:37
相关论文
共 50 条
  • [41] TLERAD: Transfer Learning for Enhanced Ransomware Attack Detection
    Sood, Isha
    Sharma, Varsha
    CMC-COMPUTERS MATERIALS & CONTINUA, 2024, 81 (02): : 2791 - 2818
  • [42] Enhancing Early Breast Cancer Detection with Infrared Thermography: A Comparative Evaluation of Deep Learning and Machine Learning Models
    Jalloul, Reem
    Krishnappa, Chethan Hasigala
    Agughasi, Victor Ikechukwu
    Alkhatib, Ramez
    TECHNOLOGIES, 2025, 13 (01)
  • [43] Ransomware early detection by the analysis of file sharing traffic
    Morato, Daniel
    Berrueta, Eduardo
    Magana, Eduardo
    Izal, Mikel
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2018, 124 : 14 - 32
  • [44] Proposed Ransomware Detection Model Based on Machine Learning
    Gonza, Karen
    Torres, Juan
    Curioso, Mars
    Ticona, Wilfredo
    CYBERNETICS AND CONTROL THEORY IN SYSTEMS, VOL 2, CSOC 2024, 2024, 1119 : 287 - 299
  • [45] Deep Learning and Machine Learning for Early Detection of Stroke and Haemorrhage
    Al-Mekhlafi, Zeyad Ghaleb
    Senan, Ebrahim Mohammed
    Rassem, Taha H.
    Mohammed, Badiea Abdulkarem
    Makbol, Nasrin M.
    Alanazi, Adwan Alownie
    Almurayziq, Tariq S.
    Ghaleb, Fuad A.
    CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 72 (01): : 775 - 796
  • [46] Ransomware Detection in Executable Files Using Machine Learning
    Ganta, Venkata Gopi
    Harish, G. Venkata
    Kumar, V. Prem
    Rao, G. Rama Koteswar
    2020 5TH IEEE INTERNATIONAL CONFERENCE ON RECENT TRENDS ON ELECTRONICS, INFORMATION, COMMUNICATION & TECHNOLOGY (RTEICT-2020), 2020, : 282 - 286
  • [47] Attention-Based Light Weight Deep Learning Models for Early Potato Disease Detection
    Kasana, Singara Singh
    Rathore, Ajayraj Singh
    APPLIED SCIENCES-BASEL, 2024, 14 (17):
  • [48] Recent deep learning models for dementia as point-of-care testing: Potential for early detection
    Karako, Kenji
    Song, Peipei
    Chen, Yu
    INTRACTABLE & RARE DISEASES RESEARCH, 2023, 12 (01) : 1 - 4
  • [49] Android Ransomware Attacks Detection with Optimized Ensemble Learning
    Sifat, Shaharia
    Hossain, Md Sakir
    Tonny, Sadia Afrin
    Majumder, Bejoy
    Mahajabin, Riftana
    Shakhawat, Hossain Md
    ADVANCES IN CYBERSECURITY, CYBERCRIMES, AND SMART EMERGING TECHNOLOGIES, 2023, 4 : 41 - 53
  • [50] Machine Learning Models and Applications for Early Detection
    Zapata-Cortes, Orlando
    Arango-Serna, Martin Dario
    Zapata-Cortes, Julian Andres
    Restrepo-Carmona, Jaime Alonso
    SENSORS, 2024, 24 (14)