FeSA: Feature selection architecture for ransomware detection under concept drift

被引:11
|
作者
Fernando, Damien Warren [1 ]
Komninos, Nikos [1 ]
机构
[1] City Univ London, Sch Math Comp Sci & Engn, Dept Comp Sci, London, England
关键词
Ransomware; Concept-drift; Detection; Learning-algorithms; Features;
D O I
10.1016/j.cose.2022.102659
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper investigates how different genetic and nature-inspired feature selection algorithms operate in systems where the prediction model changes over time in unforeseen ways. As a result, this study proposes a feature section architecture, namely FeSA, independent of the underlying classification algorithm and aims to find a set of features that will improve the longevity of the machine learning classifier. The feature set produced by FeSA is evaluated by creating scenarios in which concept drift is presented to our trained model. Based on our results, the generated feature set remains robust and maintains high detection rates of ransomware malware. Throughout this paper, we will refer to the true-positive rate of ransomware as detection; this is to clearly define what we focus on, as the high true positive rate for ransomware is the main priority. Our architecture is compared to other nature-inspired feature selection algorithms such as evolutionary search, genetic search, harmony search, best-first search and the greedy stepwise feature selection algorithm. Our results show that FeSA displays the least degradation on average when exposed to concept drift. FeSA is evaluated based on ransomware detection rate, recall, false positives and precision. The FeSA architecture provides a feature set that shows competitive recall, false positives and precision under concept drift while maintaining the highest detection rate from the algorithms it has been compared to.Crown Copyright (c) 2022 Published by Elsevier Ltd. All rights reserved.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] Improving the Prediction Accuracy with Feature Selection for Ransomware Detection
    Gao, Chulan
    Shahriar, Hossain
    Lo, Dan
    Shi, Yong
    Qian, Kai
    [J]. 2022 IEEE 46TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE (COMPSAC 2022), 2022, : 424 - 425
  • [2] Towards Online Concept Drift Detection with Feature Selection for Data Stream Classification
    Hammoodi, Mahmood
    Stahl, Frederic
    Tennant, Mark
    [J]. ECAI 2016: 22ND EUROPEAN CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2016, 285 : 1549 - 1550
  • [3] FeSAD ransomware detection framework with machine learning using adaption to concept drift
    Fernando, Damien Warren
    Komninos, Nikos
    [J]. COMPUTERS & SECURITY, 2024, 137
  • [4] Feature Selection for Handling Concept Drift in the Data Stream Classification
    Turkov, Pavel
    Krasotkina, Olga
    Mottl, Vadim
    Sychugov, Alexey
    [J]. MACHINE LEARNING AND DATA MINING IN PATTERN RECOGNITION (MLDM 2016), 2016, 9729 : 614 - 629
  • [5] A Genetic Programming Approach to Feature Selection and Construction for Ransomware, Phishing and Spam Detection
    Al-Sahaf, Harith
    Welch, Ian
    [J]. PROCEEDINGS OF THE 2019 GENETIC AND EVOLUTIONARY COMPUTATION CONFERENCE COMPANION (GECCCO'19 COMPANION), 2019, : 332 - 333
  • [6] Android ransomware detection using a novel hamming distance based feature selection
    Rahima Manzil, Hashida Haidros
    Naik, S. Manohar
    [J]. JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2024, 20 (01) : 71 - 93
  • [7] Feature-Selection-Based Ransomware Detection with Machine Learning of Data Analysis
    Wan, Yu-Lun
    Chang, Jen-Chun
    Chen, Rong-Jaye
    Wang, Shiuh-Jeng
    [J]. PROCEEDINGS OF 2018 3RD INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION SYSTEMS (ICCCS), 2018, : 85 - 88
  • [8] Android ransomware detection using a novel hamming distance based feature selection
    Hashida Haidros Rahima Manzil
    S. Manohar Naik
    [J]. Journal of Computer Virology and Hacking Techniques, 2024, 20 : 71 - 93
  • [9] Android Ransomware Detection From Traffic Analysis Using Metaheuristic Feature Selection
    Hossain, Md. Sakir
    Hasan, Naim
    Samad, Md. Abdus
    Shakhawat, Hossain M. D.
    Karmoker, Joydeep
    Ahmed, Foysol
    Fuad, K. F. M. Nafiz
    Choi, Kwonhue
    [J]. IEEE ACCESS, 2022, 10 : 128754 - 128763
  • [10] Android Ransomware Detection from Traffic Analysis Using Metaheuristic Feature Selection
    Hossain, Md. Sakir
    Hasan, Naim
    Samad, Md. Abdus
    Shakhawat, Hossain Md.
    Karmoker, Joydeep
    Ahmed, Foysol
    Nafiz Fuad, K.F.M.N.
    Choi, Kwonhue
    [J]. IEEE Access, 2022, 10 : 128754 - 128763