Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

Early Detection of Windows Cryptographic Ransomware Based on Pre-Attack API Calls Features and Machine Learning

View through CrossRef
Ransomware attacks are currently one of cybersecurity's greatest and most alluring threats. Antivirus software is frequently ineffective against zero-day malware and ransomware attacks; consequently, significant network infections could result in substantial data loss. Such attacks are also becoming more dynamic and capable of altering their signatures, resulting in a race to the bottom regarding weaponry. Cryptographic ransomware exploits crypto-viral extortion techniques. The malware encrypts the victim's data and demands payment in exchange. The attacker would release the data decryption key after accepting payment. After data encryption, the user has two options: pay the ransom or lose the data. Cryptographic ransomware causes damage that is nearly impossible to undo. Detection at an early stage of a ransomware attack's lifecycle is vital for preventing unintended consequences for the victim. Most ransomware detection technologies concentrate on detection during encryption and post-attack stages. Due to the absence of early behaviour signs, it is challenging to detect ransomware before it begins the unwanted process of mass file encryption. This study examines the relationship between API calls pattern and their nature to determine whether it is ransomware early behaviour. The purpose of this paper is to determine whether this technique can be used to early detect the presence of ransomware activity on a Windows endpoint. 582 ransomware samples that consist of ten ransomware families and 942 benign software samples were analysed. This study proposed RENTAKA, a novel framework for the early detection of cryptographic ransomware. It makes use of characteristics acquired from ransomware behaviour and machine learning. This study presented an algorithm to generate a ransomware pre-encryption dataset. This study, which includes six machine-learning models, gives satisfactory results in detecting cryptographic ransomware. The features used in this research were among the 232 features identified in Windows API calls. Five standard machine learning classifiers were employed in this experiment: Naive Bayes, k-nearest neighbours (kNN), Support Vector Machines (SVM), Random Forest, and J48. In our tests, SVM fared the best, with an accuracy rate of 93.8% and an area under the curve (AUC) of 0.979, respectively. The results indicate that we can distinguish ransomware from benign applications with low false-positive and false-negative rates.
Title: Early Detection of Windows Cryptographic Ransomware Based on Pre-Attack API Calls Features and Machine Learning
Description:
Ransomware attacks are currently one of cybersecurity's greatest and most alluring threats.
Antivirus software is frequently ineffective against zero-day malware and ransomware attacks; consequently, significant network infections could result in substantial data loss.
Such attacks are also becoming more dynamic and capable of altering their signatures, resulting in a race to the bottom regarding weaponry.
Cryptographic ransomware exploits crypto-viral extortion techniques.
The malware encrypts the victim's data and demands payment in exchange.
The attacker would release the data decryption key after accepting payment.
After data encryption, the user has two options: pay the ransom or lose the data.
Cryptographic ransomware causes damage that is nearly impossible to undo.
Detection at an early stage of a ransomware attack's lifecycle is vital for preventing unintended consequences for the victim.
Most ransomware detection technologies concentrate on detection during encryption and post-attack stages.
Due to the absence of early behaviour signs, it is challenging to detect ransomware before it begins the unwanted process of mass file encryption.
This study examines the relationship between API calls pattern and their nature to determine whether it is ransomware early behaviour.
The purpose of this paper is to determine whether this technique can be used to early detect the presence of ransomware activity on a Windows endpoint.
582 ransomware samples that consist of ten ransomware families and 942 benign software samples were analysed.
This study proposed RENTAKA, a novel framework for the early detection of cryptographic ransomware.
It makes use of characteristics acquired from ransomware behaviour and machine learning.
This study presented an algorithm to generate a ransomware pre-encryption dataset.
This study, which includes six machine-learning models, gives satisfactory results in detecting cryptographic ransomware.
The features used in this research were among the 232 features identified in Windows API calls.
Five standard machine learning classifiers were employed in this experiment: Naive Bayes, k-nearest neighbours (kNN), Support Vector Machines (SVM), Random Forest, and J48.
In our tests, SVM fared the best, with an accuracy rate of 93.
8% and an area under the curve (AUC) of 0.
979, respectively.
The results indicate that we can distinguish ransomware from benign applications with low false-positive and false-negative rates.

Related Results

Ransomware Classification with Deep Neural Network and Bi-LSTM
Ransomware Classification with Deep Neural Network and Bi-LSTM
Malicious attacks, malware, and ransomware families present essential risks to cybersecurity and may result in significant harm to computer systems, data clusters, networks, and mo...
Enhancing Ransomware Detection: A Windows API Min Max Relevance Refinement Approach
Enhancing Ransomware Detection: A Windows API Min Max Relevance Refinement Approach
Ransomware constitutes a distinctive category of pernicious software that sequesters a user's digital assets by encryption, holding them hostage until a sum is extorted from the vi...
KRDroid: Ransomware-Oriented Detector for Mobile Devices Based on Behaviors
KRDroid: Ransomware-Oriented Detector for Mobile Devices Based on Behaviors
Ransomware has become a serious threat on Android and new cases of ransomware are continuously growing. Most existing ransomware detectors use sensitive text or APIs to detect rans...
Ransomware Early Detection using Machine Learning Approach and Pre-Encryption Boundary Identification
Ransomware Early Detection using Machine Learning Approach and Pre-Encryption Boundary Identification
The escalating ransomware threat has catalysed the formation of a sophisticated network of cybercriminal enterprises. Addressing this issue, our research provides a detailed explor...
Malware and Windows APIs: A Dangerous Duo
Malware and Windows APIs: A Dangerous Duo
This paper introduces its interaction with malware and Windows APIs (application programming interface). The first section describes malware and investigates various types such as ...
Selection of Injectable Drug Product Composition using Machine Learning Models (Preprint)
Selection of Injectable Drug Product Composition using Machine Learning Models (Preprint)
BACKGROUND As of July 2020, a Web of Science search of “machine learning (ML)” nested within the search of “pharmacokinetics or pharmacodynamics” yielded over 100...
API Offshore Structure Standards: 2006 And Beyond
API Offshore Structure Standards: 2006 And Beyond
Abstract The future of the API offshore structure standards appears to be at a crossroad. The short term plans are clearly laid out, with the projected publicatio...
CREATING LEARNING MEDIA IN TEACHING ENGLISH AT SMP MUHAMMADIYAH 2 PAGELARAN ACADEMIC YEAR 2020/2021
CREATING LEARNING MEDIA IN TEACHING ENGLISH AT SMP MUHAMMADIYAH 2 PAGELARAN ACADEMIC YEAR 2020/2021
The pandemic Covid-19 currently demands teachers to be able to use technology in teaching and learning process. But in reality there are still many teachers who have not been able ...

Back to Top