Enhancing File Entropy Analysis to Improve Machine Learning Detection Rate of Ransomware

被引:11
|
作者
Hsu, Chia-Ming [1 ]
Yang, Chia-Cheng [1 ]
Cheng, Han-Hsuan [1 ]
Setiasabda, Paul E. [1 ]
Leu, Jenq-Shiou [1 ]
机构
[1] Natl Taiwan Univ Sci & Technol, Dept Elect & Comp Engn, Taipei 10607, Taiwan
关键词
Ransomware; Cryptography; Feature extraction; Entropy; Support vector machines; Encryption; Analytical models; Machine learning; ransomware; entropy; security;
D O I
10.1109/ACCESS.2021.3114148
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybersecurity is the biggest threat in the world. More and more people are used to storing personal data on a computer and transmitting it through the Internet. Cybersecurity will be an important issue that everyone continues to pay attention to. One of the most serious problems recently is the prevalence of ransomware, especially crypto-ransomware. Unlike ordinary attacks, crypto-ransomware does not control the victim's computer and steal important data. It focuses on encrypting all data and asking victims to provide ransom to decrypt the data. Currently, many studies focus on various aspects of ransomware, including file-based, behavior-based, and network-based ransomware detection method, and use machine learning to build detection models. In addition to the above research, we found that attackers have begun to develop a new method to encrypt data. It will not only increase the speed of data encryption but also reduce the detection rate in the existing detection system. In any case, we are still facing ransomware dangers, as it is hard to recognize and forestall ransomware executing obscure malicious programs. In other words, user data will be sabotaged as soon as the computer cannot detect the ransomware. To solve the problem, detecting files instead of detecting the executable program might be helpful to establish the backup system immediately before ransomware encrypts all of the user files. We analyze the 22 formats of the encrypted files, extract the specific features and use the Support Vector Machine to distinguish between encrypted and unencrypted files. Conducted analysis results confirm that our method has better performance and a higher detection rate, reaching 85.17%. (Where the detection rate of SVM kernel Trick (Poly) exceeds 92%).
引用
收藏
页码:138345 / 138351
页数:7
相关论文
共 50 条
  • [1] Machine Learning Based File Entropy Analysis for Ransomware Detection in Backup Systems
    Lee, Kyungroul
    Lee, Sun-Young
    Yim, Kangbin
    IEEE ACCESS, 2019, 7 : 110205 - 110215
  • [2] Enhancing Android Ransomware Detection Using an Ensemble Machine Learning Classifier
    Vali, Nasser
    Portillo-Dominguez, A. Omar
    Ayala-Rivera, Vanessa
    PROGRAMMING AND COMPUTER SOFTWARE, 2024, 50 (08) : 562 - 576
  • [3] Enhancing Machine Learning Approach Based on Nilsimsa Fingerprinting for Ransomware Detection in IoMT
    Lucia Hernandez-Jaimes, Mireya
    Martinez-Cruz, Alfonso
    Alejandra Ramirez-Gutierrez, Kelsey
    Guevara-Martinez, Elizabeth
    IEEE ACCESS, 2024, 12 : 153886 - 153897
  • [4] Detecting Ransomware Encryption with File Signatures and Machine Learning Models
    Duignan, Michael
    Schukat, Michael
    Barrett, Enda
    2023 34TH IRISH SIGNALS AND SYSTEMS CONFERENCE, ISSC, 2023,
  • [5] Ransomware early detection by the analysis of file sharing traffic
    Morato, Daniel
    Berrueta, Eduardo
    Magana, Eduardo
    Izal, Mikel
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2018, 124 : 14 - 32
  • [6] Authentic Learning of Machine Learning to Ransomware Detection and Prevention
    Faruk, Md Jobair Hossain
    Masum, Mohammad
    Shahriar, Hossain
    Qian, Kai
    Lo, Dan
    2022 IEEE 46TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE (COMPSAC 2022), 2022, : 442 - 443
  • [7] Machine Learning Algorithms and Frameworks in Ransomware Detection
    Smith, Daryle
    Khorsandroo, Sajad
    Roy, Kaushik
    IEEE ACCESS, 2022, 10 : 117597 - 117610
  • [8] Multilayer ransomware detection using grouped registry key operations, file entropy and file signature monitoring
    Jethva, Brijesh
    Traore, Issa
    Ghaleb, Asem
    Ganame, Karim
    Ahmed, Sherif
    JOURNAL OF COMPUTER SECURITY, 2020, 28 (03) : 337 - 373
  • [9] Ransomware detection using machine learning algorithms
    Bae, Seong Il
    Lee, Gyu Bin
    Im, Eul Gyu
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2020, 32 (18):
  • [10] Ransomware Classification and Detection With Machine Learning Algorithms
    Masum, Mohammad
    Faruk, Md Jobair Hossain
    Shahriar, Hossain
    Qian, Kai
    Lo, Dan
    Adnan, Muhaiminul Islam
    2022 IEEE 12TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE (CCWC), 2022, : 316 - 322