Two-Stage Ransomware Detection Using Dynamic Analysis and Machine Learning Techniques

被引:52
|
作者
Hwang, Jinsoo [1 ]
Kim, Jeankyung [1 ]
Lee, Seunghwan [1 ]
Kim, Kichang [2 ]
机构
[1] Inha Univ, Dept Stat, Incheon, South Korea
[2] Inha Univ, Sch Informat & Commun Engn, Incheon, South Korea
基金
新加坡国家研究基金会;
关键词
Ransomware; Normalware; Markov chain; Random Forest; Machine learning;
D O I
10.1007/s11277-020-07166-9
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Detecting ransomware is harder than general malware because of the ever-increasing number of ransomwares with different signatures, which makes traditional signature-based detection technique powerless against ransomware. Current ransomware detection techniques usually build a complex model that incorporates various behavioral traits. The traits include suspicious file activities, API call pattern or frequency, registry keys, file extensions, etc. In this paper, we build a two-stage mixed ransomware detection model, Markov model and Random Forest model. First we focus on Windows API call sequence pattern and build a Markov model to capture the characteristics of ransomware. Next we build Random Forest machine learning model to the remaining data in order to control both false positive (FPR) and false negative (FNR) error rates. As a result of our two-stage mixed detection method we can achieve overall accuracy 97.3% with 4.8% FPR and 1.5% FNR.
引用
收藏
页码:2597 / 2609
页数:13
相关论文
共 50 条
  • [1] Two-Stage Ransomware Detection Using Dynamic Analysis and Machine Learning Techniques
    Jinsoo Hwang
    Jeankyung Kim
    Seunghwan Lee
    Kichang Kim
    [J]. Wireless Personal Communications, 2020, 112 : 2597 - 2609
  • [2] Ransomware Detection Service: Execution and Analysis Using Machine Learning Techniques
    Badrinath, Suriya
    Dodhi, Roshni
    Muthalagu, Raja
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2023, 133 (02) : 995 - 1009
  • [3] Ransomware Detection Service: Execution and Analysis Using Machine Learning Techniques
    Suriya Badrinath
    Roshni Dodhi
    Raja Muthalagu
    [J]. Wireless Personal Communications, 2023, 133 : 995 - 1009
  • [4] Ransomware Detection Using the Dynamic Analysis and Machine Learning: A Survey and Research Directions
    Urooj, Umara
    Al-rimy, Bander Ali Saleh
    Zainal, Anazida
    Ghaleb, Fuad A.
    Rassam, Murad A.
    [J]. APPLIED SCIENCES-BASEL, 2022, 12 (01):
  • [5] Predicting Stock Price Using Two-Stage Machine Learning Techniques
    Zhang, Jun
    Li, Lan
    Chen, Wei
    [J]. COMPUTATIONAL ECONOMICS, 2021, 57 (04) : 1237 - 1261
  • [6] Two-stage credit rating prediction using machine learning techniques
    Wu, Hsu-Che
    Hu, Ya-Han
    Huang, Yen-Hao
    [J]. KYBERNETES, 2014, 43 (07) : 1098 - 1113
  • [7] Predicting Stock Price Using Two-Stage Machine Learning Techniques
    Jun Zhang
    Lan Li
    Wei Chen
    [J]. Computational Economics, 2021, 57 : 1237 - 1261
  • [8] Android Ransomware Detection Using Supervised Machine Learning Techniques Based on Traffic Analysis
    Albin Ahmed, Amnah
    Shaahid, Afrah
    Alnasser, Fatima
    Alfaddagh, Shahad
    Binagag, Shadha
    Alqahtani, Deemah
    [J]. SENSORS, 2024, 24 (01)
  • [9] Android Ransomware Detection using Machine Learning Techniques: A Comparative Analysis on GPU and CPU
    Sharma, Shweta
    Krishna, C. Rama
    Kumar, Rakesh
    [J]. 2020 21ST INTERNATIONAL ARAB CONFERENCE ON INFORMATION TECHNOLOGY (ACIT), 2020,
  • [10] A Study on the Evolution of Ransomware Detection Using Machine Learning and Deep Learning Techniques
    Fernando, Damien Warren
    Komninos, Nikos
    Chen, Thomas
    [J]. IOT, 2020, 1 (02): : 551 - 604