Enhancing File Entropy Analysis to Improve Machine Learning Detection Rate of Ransomware

被引:11
|
作者
Hsu, Chia-Ming [1 ]
Yang, Chia-Cheng [1 ]
Cheng, Han-Hsuan [1 ]
Setiasabda, Paul E. [1 ]
Leu, Jenq-Shiou [1 ]
机构
[1] Natl Taiwan Univ Sci & Technol, Dept Elect & Comp Engn, Taipei 10607, Taiwan
关键词
Ransomware; Cryptography; Feature extraction; Entropy; Support vector machines; Encryption; Analytical models; Machine learning; ransomware; entropy; security;
D O I
10.1109/ACCESS.2021.3114148
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybersecurity is the biggest threat in the world. More and more people are used to storing personal data on a computer and transmitting it through the Internet. Cybersecurity will be an important issue that everyone continues to pay attention to. One of the most serious problems recently is the prevalence of ransomware, especially crypto-ransomware. Unlike ordinary attacks, crypto-ransomware does not control the victim's computer and steal important data. It focuses on encrypting all data and asking victims to provide ransom to decrypt the data. Currently, many studies focus on various aspects of ransomware, including file-based, behavior-based, and network-based ransomware detection method, and use machine learning to build detection models. In addition to the above research, we found that attackers have begun to develop a new method to encrypt data. It will not only increase the speed of data encryption but also reduce the detection rate in the existing detection system. In any case, we are still facing ransomware dangers, as it is hard to recognize and forestall ransomware executing obscure malicious programs. In other words, user data will be sabotaged as soon as the computer cannot detect the ransomware. To solve the problem, detecting files instead of detecting the executable program might be helpful to establish the backup system immediately before ransomware encrypts all of the user files. We analyze the 22 formats of the encrypted files, extract the specific features and use the Support Vector Machine to distinguish between encrypted and unencrypted files. Conducted analysis results confirm that our method has better performance and a higher detection rate, reaching 85.17%. (Where the detection rate of SVM kernel Trick (Poly) exceeds 92%).
引用
收藏
页码:138345 / 138351
页数:7
相关论文
共 50 条
  • [41] Dynamic Feature Dataset for Ransomware Detection Using Machine Learning Algorithms
    Herrera-Silva, Juan A.
    Hernandez-alvarez, Myriam
    SENSORS, 2023, 23 (03)
  • [42] Ransomware Detection: Ensemble Machine Learning Models using Disjoint Data
    da Silva, Charles M. R.
    de Castro, Paulo Andre L.
    Cesar, Cecilia de A. C.
    2024 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR, 2024, : 166 - 179
  • [43] Evaluation metric for crypto-ransomware detection using machine learning
    Kok, S. H.
    Azween, A.
    Jhanjhi, N. Z.
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2020, 55
  • [44] Ransomware detection method based on context-aware entropy analysis
    Sangmoon Jung
    Yoojae Won
    Soft Computing, 2018, 22 : 6731 - 6740
  • [45] Ransomware detection method based on context-aware entropy analysis
    Jung, Sangmoon
    Won, Yoojae
    SOFT COMPUTING, 2018, 22 (20) : 6731 - 6740
  • [46] Enhancing machine learning multi-class fault detection in electric motors through entropy-based analysis
    Palaiologou, Ilias
    Falekas, Georgios
    Antonino-Daviu, Jose A.
    Karlis, Athanasios
    MEASUREMENT SCIENCE AND TECHNOLOGY, 2025, 36 (01)
  • [47] FeSAD ransomware detection framework with machine learning using adaption to concept drift
    Fernando, Damien Warren
    Komninos, Nikos
    COMPUTERS & SECURITY, 2024, 137
  • [48] Ransomware Detection Using Machine Learning: A Review, Research Limitations and Future Directions
    Ispahany, Jamil
    Islam, Md. Rafiqul
    Islam, Md. Zahidul
    Khan, M. Arif
    IEEE ACCESS, 2024, 12 : 68785 - 68813
  • [49] Reducing False Negatives in Ransomware Detection: A Critical Evaluation of Machine Learning Algorithms
    Bold, Robert
    Al-Khateeb, Haider
    Ersotelos, Nikolaos
    APPLIED SCIENCES-BASEL, 2022, 12 (24):
  • [50] A Proposal for Privacy- preserving Ransomware Detection by means of Federated Machine Learning
    Ciaramella, Giovanni
    Martinelli, Fabio
    Mercaldo, Francesco
    ERCIM NEWS, 2024, (139):