Early Ransomware Detection with Deep Learning Models

被引:0
|
作者
Davidian, Matan [1 ]
Kiperberg, Michael [1 ]
Vanetik, Natalia [1 ]
机构
[1] Shamoon Coll Engn, Dept Software Engn, IL-84100 Beer Sheva, Israel
关键词
ransomware; deep learning; API call sequences; cybersecurity; malware detection; behavioral analysis;
D O I
10.3390/fi16080291
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Ransomware is a growing-in-popularity type of malware that restricts access to the victim's system or data until a ransom is paid. Traditional detection methods rely on analyzing the malware's content, but these methods are ineffective against unknown or zero-day malware. Therefore, zero-day malware detection typically involves observing the malware's behavior, specifically the sequence of application programming interface (API) calls it makes, such as reading and writing files or enumerating directories. While previous studies have used machine learning (ML) techniques to classify API call sequences, they have only considered the API call name. This paper systematically compares various subsets of API call features, different ML techniques, and context-window sizes to identify the optimal ransomware classifier. Our findings indicate that a context-window size of 7 is ideal, and the most effective ML techniques are CNN and LSTM. Additionally, augmenting the API call name with the operation result significantly enhances the classifier's precision. Performance analysis suggests that this classifier can be effectively applied in real-time scenarios.
引用
收藏
页数:37
相关论文
共 50 条
  • [21] XRan: Explainable deep learning-based ransomware detection using dynamic analysis
    Gulmez, Sibel
    Kakisim, Arzu Gorgulu
    Sogukpinar, Ibrahim
    COMPUTERS & SECURITY, 2024, 139
  • [22] Visualizing Portable Executable Headers for Ransomware Detection: A Deep Learning-Based Approach
    Dam, Tien Quang
    Nguyen, Nghia Thinh
    Le, Trung Viet
    Le, Tran Duc
    Uwizeyemungu, Sylvestre
    Le-Dinh, Thang
    JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2024, 30 (02) : 262 - 286
  • [23] Novel Ransomware Detection Exploiting Uncertainty and Calibration Quality Measures Using Deep Learning
    Gazzan, Mazen
    Sheldon, Frederick T.
    INFORMATION, 2024, 15 (05)
  • [24] Multimodal deep learning models for early detection of Alzheimer’s disease stage
    Janani Venugopalan
    Li Tong
    Hamid Reza Hassanzadeh
    May D. Wang
    Scientific Reports, 11
  • [25] Ransomware detection with CNN and deep learning based on multiple features of portable executable files
    Yang, Chia-Cheng
    Hsu, Jia-Ming
    Leu, Jenq-Shiou
    Hsieh, Wen-Bin
    JOURNAL OF SUPERCOMPUTING, 2025, 81 (05):
  • [26] API-Based Ransomware Detection Using Machine Learning-Based Threat Detection Models
    Almousa, May
    Basavaraju, Sai
    Anwar, Mohd
    2021 18TH INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2021,
  • [27] Authentic Learning of Machine Learning to Ransomware Detection and Prevention
    Faruk, Md Jobair Hossain
    Masum, Mohammad
    Shahriar, Hossain
    Qian, Kai
    Lo, Dan
    2022 IEEE 46TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE (COMPSAC 2022), 2022, : 442 - 443
  • [28] Deep learning delivers early detection
    Svoboda, Elizabeth
    NATURE, 2020, 587 (7834) : S20 - S22
  • [29] Machine Learning Algorithms and Frameworks in Ransomware Detection
    Smith, Daryle
    Khorsandroo, Sajad
    Roy, Kaushik
    IEEE ACCESS, 2022, 10 : 117597 - 117610
  • [30] Comparative Analysis of Botnet and Ransomware for Early Detection
    Honnavalli B, Prasad
    Sushma, Ethadi
    Rao, Aditya
    Girimaji, Varun
    Girimaji, Vrinda
    Katta, Achyuta
    INTERNET OF THINGS, SMART SPACES, AND NEXT GENERATION NETWORKS AND SYSTEMS, PT I, NEW2AN 2023, RUSMART 2023, 2024, 14542 : 296 - 308