FeSA: Feature selection architecture for ransomware detection under concept drift

被引:11
|
作者
Fernando, Damien Warren [1 ]
Komninos, Nikos [1 ]
机构
[1] City Univ London, Sch Math Comp Sci & Engn, Dept Comp Sci, London, England
关键词
Ransomware; Concept-drift; Detection; Learning-algorithms; Features;
D O I
10.1016/j.cose.2022.102659
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper investigates how different genetic and nature-inspired feature selection algorithms operate in systems where the prediction model changes over time in unforeseen ways. As a result, this study proposes a feature section architecture, namely FeSA, independent of the underlying classification algorithm and aims to find a set of features that will improve the longevity of the machine learning classifier. The feature set produced by FeSA is evaluated by creating scenarios in which concept drift is presented to our trained model. Based on our results, the generated feature set remains robust and maintains high detection rates of ransomware malware. Throughout this paper, we will refer to the true-positive rate of ransomware as detection; this is to clearly define what we focus on, as the high true positive rate for ransomware is the main priority. Our architecture is compared to other nature-inspired feature selection algorithms such as evolutionary search, genetic search, harmony search, best-first search and the greedy stepwise feature selection algorithm. Our results show that FeSA displays the least degradation on average when exposed to concept drift. FeSA is evaluated based on ransomware detection rate, recall, false positives and precision. The FeSA architecture provides a feature set that shows competitive recall, false positives and precision under concept drift while maintaining the highest detection rate from the algorithms it has been compared to.Crown Copyright (c) 2022 Published by Elsevier Ltd. All rights reserved.
引用
下载
收藏
页数:13
相关论文
共 50 条
  • [41] Regional Concept Drift Detection and Density Synchronized Drift Adaptation
    Liu, Anjin
    Song, Yiliao
    Zhang, Guangquan
    Lu, Jie
    PROCEEDINGS OF THE TWENTY-SIXTH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2017, : 2280 - 2286
  • [42] Dynamic Feature Dataset for Ransomware Detection Using Machine Learning Algorithms
    Herrera-Silva, Juan A.
    Hernandez-alvarez, Myriam
    SENSORS, 2023, 23 (03)
  • [43] Active feature acquisition on data streams under feature drift
    Beyer, Christian
    Buettner, Maik
    Unnikrishnan, Vishnu
    Schleicher, Miro
    Ntoutsi, Eirini
    Spiliopoulou, Myra
    ANNALS OF TELECOMMUNICATIONS, 2020, 75 (9-10) : 597 - 611
  • [44] Is iterative feature selection technique efficient enough? A comparative performance analysis of RFECV feature selection technique in ransomware classification using SHAP
    Mowri R.A.
    Siddula M.
    Roy K.
    Discover Internet of Things, 2023, 3 (01):
  • [45] Active feature acquisition on data streams under feature drift
    Christian Beyer
    Maik Büttner
    Vishnu Unnikrishnan
    Miro Schleicher
    Eirini Ntoutsi
    Myra Spiliopoulou
    Annals of Telecommunications, 2020, 75 : 597 - 611
  • [46] Adaptive Supervised Learning Model for Training set Selection under Concept Drift Data Streams
    Patil, Pramod D.
    Kulkarni, Parag
    2013 INTERNATIONAL CONFERENCE ON CLOUD & UBIQUITOUS COMPUTING & EMERGING TECHNOLOGIES (CUBE 2013), 2013, : 36 - +
  • [47] Construction of the concept drift detection model based on the information entropy of feature distribution and dynamic weighting algorithm
    Sun, Xue
    Li, Kun-Lun
    Han, Lei
    Bai, Xiao-Liang
    Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2015, 43 (07): : 1356 - 1361
  • [48] Adversarial concept drift detection under poisoning attacks for robust data stream mining
    Łukasz Korycki
    Bartosz Krawczyk
    Machine Learning, 2023, 112 : 4013 - 4048
  • [49] Concept Drift Detection for Graph-structured Classifiers under Scarcity of True Labels
    Sriwatanasakdi, Noppayut
    Numao, Masayuki
    Fukui, Ken-ichi
    2017 IEEE 29TH INTERNATIONAL CONFERENCE ON TOOLS WITH ARTIFICIAL INTELLIGENCE (ICTAI 2017), 2017, : 461 - 468
  • [50] Adversarial concept drift detection under poisoning attacks for robust data stream mining
    Korycki, Lukasz
    Krawczyk, Bartosz
    MACHINE LEARNING, 2023, 112 (10) : 4013 - 4048