Dynamic Feature Dataset for Ransomware Detection Using Machine Learning Algorithms

被引:13
|
作者
Herrera-Silva, Juan A. [1 ]
Hernandez-alvarez, Myriam [1 ]
机构
[1] Escuela Politec Nacl, Dept Informat & Ciencias Comp, Ladron Guevara E11 25 & Andalucia,Edificio Sistem, Quito 170525, Ecuador
关键词
classification; dataset; dynamic; analysis; encryptor; features; locker; machine learning; ransomware; SOFTWARE-DEFINED NETWORKING;
D O I
10.3390/s23031053
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Ransomware-related cyber-attacks have been on the rise over the last decade, disturbing organizations considerably. Developing new and better ways to detect this type of malware is necessary. This research applies dynamic analysis and machine learning to identify the ever-evolving ransomware signatures using selected dynamic features. Since most of the attributes are shared by diverse ransomware-affected samples, our study can be used for detecting current and even new variants of the threat. This research has the following objectives: (1) Execute experiments with encryptor and locker ransomware combined with goodware to generate JSON files with dynamic parameters using a sandbox. (2) Analyze and select the most relevant and non-redundant dynamic features for identifying encryptor and locker ransomware from goodware. (3) Generate and make public a dynamic features dataset that includes these selected parameters for samples of different artifacts. (4) Apply the dynamic feature dataset to obtain models with machine learning algorithms. Five platforms, 20 ransomware, and 20 goodware artifacts were evaluated. The final feature dataset is composed of 2000 registers of 50 characteristics each. This dataset allows for a machine learning detection with a 10-fold cross-evaluation with an average accuracy superior to 0.99 for gradient boosted regression trees, random forest, and neural networks.
引用
收藏
页数:24
相关论文
共 50 条
  • [1] Ransomware detection using machine learning algorithms
    Bae, Seong Il
    Lee, Gyu Bin
    Im, Eul Gyu
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2020, 32 (18):
  • [2] Machine Learning Algorithms and Frameworks in Ransomware Detection
    Smith, Daryle
    Khorsandroo, Sajad
    Roy, Kaushik
    [J]. IEEE ACCESS, 2022, 10 : 117597 - 117610
  • [3] Ransomware Classification and Detection With Machine Learning Algorithms
    Masum, Mohammad
    Faruk, Md Jobair Hossain
    Shahriar, Hossain
    Qian, Kai
    Lo, Dan
    Adnan, Muhaiminul Islam
    [J]. 2022 IEEE 12TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE (CCWC), 2022, : 316 - 322
  • [4] Classifying Ransomware Using Machine Learning Algorithms
    Egunjobi, Samuel
    Parkinson, Simon
    Crampton, Andrew
    [J]. INTELLIGENT DATA ENGINEERING AND AUTOMATED LEARNING (IDEAL 2019), PT II, 2019, 11872 : 45 - 52
  • [5] The Effect of the Ransomware Dataset Age on the Detection Accuracy of Machine Learning Models
    Yaseen, Qussai M.
    [J]. INFORMATION, 2023, 14 (03)
  • [6] Ransomware Detection Using Machine Learning: A Survey
    Alraizza, Amjad
    Algarni, Abdulmohsen
    [J]. BIG DATA AND COGNITIVE COMPUTING, 2023, 7 (03)
  • [7] Ransomware Detection Using the Dynamic Analysis and Machine Learning: A Survey and Research Directions
    Urooj, Umara
    Al-rimy, Bander Ali Saleh
    Zainal, Anazida
    Ghaleb, Fuad A.
    Rassam, Murad A.
    [J]. APPLIED SCIENCES-BASEL, 2022, 12 (01):
  • [8] Snow and glacial feature identification using Hyperion dataset and machine learning algorithms
    Haq M.A.
    Alshehri M.
    Rahaman G.
    Ghosh A.
    Baral P.
    Shekhar C.
    [J]. Arabian Journal of Geosciences, 2021, 14 (15)
  • [9] AN EXPERIMENTAL STUDY TO EVALUATE THE PERFORMANCE OF MACHINE LEARNING ALGORITHMS IN RANSOMWARE DETECTION
    Dion, Yap L.
    Brohi, Sarfraz N.
    [J]. JOURNAL OF ENGINEERING SCIENCE AND TECHNOLOGY, 2020, 15 (02): : 967 - 981
  • [10] Ransomware Detection using Machine and Deep Learning Approaches
    Alsaidi, Ramadhan A. M.
    Yafooz, Wael M. S.
    Alolofi, Hashem
    Taufiq-Hail, Ghilan Al-Madhagy
    Emara, Abdel-Hamid M.
    Abdel-Wahab, Ahmed
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (11) : 112 - 119