Enhancing File Entropy Analysis to Improve Machine Learning Detection Rate of Ransomware

被引:11
|
作者
Hsu, Chia-Ming [1 ]
Yang, Chia-Cheng [1 ]
Cheng, Han-Hsuan [1 ]
Setiasabda, Paul E. [1 ]
Leu, Jenq-Shiou [1 ]
机构
[1] Natl Taiwan Univ Sci & Technol, Dept Elect & Comp Engn, Taipei 10607, Taiwan
关键词
Ransomware; Cryptography; Feature extraction; Entropy; Support vector machines; Encryption; Analytical models; Machine learning; ransomware; entropy; security;
D O I
10.1109/ACCESS.2021.3114148
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybersecurity is the biggest threat in the world. More and more people are used to storing personal data on a computer and transmitting it through the Internet. Cybersecurity will be an important issue that everyone continues to pay attention to. One of the most serious problems recently is the prevalence of ransomware, especially crypto-ransomware. Unlike ordinary attacks, crypto-ransomware does not control the victim's computer and steal important data. It focuses on encrypting all data and asking victims to provide ransom to decrypt the data. Currently, many studies focus on various aspects of ransomware, including file-based, behavior-based, and network-based ransomware detection method, and use machine learning to build detection models. In addition to the above research, we found that attackers have begun to develop a new method to encrypt data. It will not only increase the speed of data encryption but also reduce the detection rate in the existing detection system. In any case, we are still facing ransomware dangers, as it is hard to recognize and forestall ransomware executing obscure malicious programs. In other words, user data will be sabotaged as soon as the computer cannot detect the ransomware. To solve the problem, detecting files instead of detecting the executable program might be helpful to establish the backup system immediately before ransomware encrypts all of the user files. We analyze the 22 formats of the encrypted files, extract the specific features and use the Support Vector Machine to distinguish between encrypted and unencrypted files. Conducted analysis results confirm that our method has better performance and a higher detection rate, reaching 85.17%. (Where the detection rate of SVM kernel Trick (Poly) exceeds 92%).
引用
收藏
页码:138345 / 138351
页数:7
相关论文
共 50 条
  • [31] Machine Learning-Based Detection of Ransomware Using SDN
    Cusack, Greg
    Michel, Oliver
    Keller, Eric
    PROCEEDINGS OF THE 2018 ACM INTERNATIONAL WORKSHOP ON SECURITY IN SOFTWARE DEFINED NETWORKS & NETWORK FUNCTION VIRTUALIZATION (SDN-NFVSEC'18), 2018, : 1 - 6
  • [32] Edge Computing Ransomware Detection in IoT using Machine Learning
    Radhakrishna, Tejesh
    Majd, Nahid Ebrahimi
    2024 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS, ICNC, 2024, : 244 - 248
  • [33] Ransomware detection based on machine learning using memory features
    Aljabri, Malak
    Alhaidari, Fahd
    Albuainain, Aminah
    Alrashidi, Samiyah
    Alansari, Jana
    Alqahtani, Wasmiyah
    Alshaya, Jana
    EGYPTIAN INFORMATICS JOURNAL, 2024, 25
  • [34] A Study on the Evolution of Ransomware Detection Using Machine Learning and Deep Learning Techniques
    Fernando, Damien Warren
    Komninos, Nikos
    Chen, Thomas
    IOT, 2020, 1 (02): : 551 - 604
  • [35] Differential area analysis for ransomware attack detection within mixed file datasets
    Davies, Simon R.
    Macfarlane, Richard
    Buchanan, William J.
    COMPUTERS & SECURITY, 2021, 108
  • [36] The Effect of the Ransomware Dataset Age on the Detection Accuracy of Machine Learning Models
    Yaseen, Qussai M.
    INFORMATION, 2023, 14 (03)
  • [37] A Digital DNA Sequencing Engine for Ransomware Detection Using Machine Learning
    Khan, Firoz
    Ncube, Cornelius
    Ramasamy, Lakshmana Kumar
    Kadry, Seifedine
    Nam, Yunyoung
    IEEE ACCESS, 2020, 8 : 119710 - 119719
  • [38] Behavioral based detection of android ransomware using machine learning techniques
    Kirubavathi, G.
    Anne, W. Regis
    INTERNATIONAL JOURNAL OF SYSTEM ASSURANCE ENGINEERING AND MANAGEMENT, 2024, 15 (09) : 4404 - 4425
  • [39] AN EXPERIMENTAL STUDY TO EVALUATE THE PERFORMANCE OF MACHINE LEARNING ALGORITHMS IN RANSOMWARE DETECTION
    Dion, Yap L.
    Brohi, Sarfraz N.
    JOURNAL OF ENGINEERING SCIENCE AND TECHNOLOGY, 2020, 15 (02): : 967 - 981
  • [40] Ransomware Attack Detection on the Internet of Things Using Machine Learning Algorithm
    Zewdie, Temechu Girma
    Girma, Anteneh
    Cotae, Paul
    HCI INTERNATIONAL 2022 - LATE BREAKING PAPERS: INTERACTING WITH EXTENDED REALITY AND ARTIFICIAL INTELLIGENCE, 2022, 13518 : 598 - 613