Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

Ransomware Early Detection using Machine Learning Approach and Pre-Encryption Boundary Identification

View through CrossRef
The escalating ransomware threat has catalysed the formation of a sophisticated network of cybercriminal enterprises. Addressing this issue, our research provides a detailed exploration of the ransomware menace and an evaluation of contemporary detection methodologies. A successful ransomware attack leverages many factors: robust encryption methods that defy decryption, the anonymity of cyber currencies, and the widespread availability of ransomware kits that enable even inexperienced actors to launch attacks. Such dynamics have cultivated a niche for cybercriminal specialists in the digital underworld. In response to these challenges, our study proposes a detection framework based on machine learning, a domain where regression algorithms have gained popularity without yielding a definitive protective model. We employ API call analysis as the foundation to assess various machine learning classifiers' efficiency in identifying ransomware. The evaluation demonstrates that the Naive Bayes classifier underperforms due to suboptimal accuracy, making it unsuitable for this application. Conversely, Logistic Regression, with an AUC of 0.951, minimal training time, and substantial efficacy gains, emerges as a strong contender. The Decision Tree and Random Forest classifiers exhibit comparable proficiency; however, the Decision Tree's interpretability and Random Forest's computational swiftness present unique advantages. Superior still, SVM and Gradient Boosted Trees command the highest AUC and gains, albeit at the cost of increased training duration. Our findings affirm the pivotal role of API call analysis in ransomware detection and the potency of machine learning approaches in learning from extensive datasets to identify novel malware strains. Given the continual evolution of malware, detection methodologies must adapt correspondingly. This study's comparative analysis elucidates the trade-offs between accuracy, computational speed, and training time, guiding the selection of the optimal machine learning algorithm for robust ransomware detection.
Title: Ransomware Early Detection using Machine Learning Approach and Pre-Encryption Boundary Identification
Description:
The escalating ransomware threat has catalysed the formation of a sophisticated network of cybercriminal enterprises.
Addressing this issue, our research provides a detailed exploration of the ransomware menace and an evaluation of contemporary detection methodologies.
A successful ransomware attack leverages many factors: robust encryption methods that defy decryption, the anonymity of cyber currencies, and the widespread availability of ransomware kits that enable even inexperienced actors to launch attacks.
Such dynamics have cultivated a niche for cybercriminal specialists in the digital underworld.
In response to these challenges, our study proposes a detection framework based on machine learning, a domain where regression algorithms have gained popularity without yielding a definitive protective model.
We employ API call analysis as the foundation to assess various machine learning classifiers' efficiency in identifying ransomware.
The evaluation demonstrates that the Naive Bayes classifier underperforms due to suboptimal accuracy, making it unsuitable for this application.
Conversely, Logistic Regression, with an AUC of 0.
951, minimal training time, and substantial efficacy gains, emerges as a strong contender.
The Decision Tree and Random Forest classifiers exhibit comparable proficiency; however, the Decision Tree's interpretability and Random Forest's computational swiftness present unique advantages.
Superior still, SVM and Gradient Boosted Trees command the highest AUC and gains, albeit at the cost of increased training duration.
Our findings affirm the pivotal role of API call analysis in ransomware detection and the potency of machine learning approaches in learning from extensive datasets to identify novel malware strains.
Given the continual evolution of malware, detection methodologies must adapt correspondingly.
This study's comparative analysis elucidates the trade-offs between accuracy, computational speed, and training time, guiding the selection of the optimal machine learning algorithm for robust ransomware detection.

Related Results

Early Detection of Windows Cryptographic Ransomware Based on Pre-Attack API Calls Features and Machine Learning
Early Detection of Windows Cryptographic Ransomware Based on Pre-Attack API Calls Features and Machine Learning
Ransomware attacks are currently one of cybersecurity's greatest and most alluring threats. Antivirus software is frequently ineffective against zero-day malware and ransomware att...
RANSOWARE: A COMPREHENSIVE INVESTIGATION Authors
RANSOWARE: A COMPREHENSIVE INVESTIGATION Authors
Ransomware has rapidly become one of the most pervasive and damaging cyber threats in the digital age. This form of malicious software, which encrypts a victim's data and demands a...
Ransomware prediction and detection in healthcare Networking using AI
Ransomware prediction and detection in healthcare Networking using AI
The healthcare industry's reliance on interconnected digital systems, electronic health records (EHR), and real-time patient data management makes them a prime target for ransomwar...
Ransomware Classification with Deep Neural Network and Bi-LSTM
Ransomware Classification with Deep Neural Network and Bi-LSTM
Malicious attacks, malware, and ransomware families present essential risks to cybersecurity and may result in significant harm to computer systems, data clusters, networks, and mo...
KRDroid: Ransomware-Oriented Detector for Mobile Devices Based on Behaviors
KRDroid: Ransomware-Oriented Detector for Mobile Devices Based on Behaviors
Ransomware has become a serious threat on Android and new cases of ransomware are continuously growing. Most existing ransomware detectors use sensitive text or APIs to detect rans...
A Framework for Real-Time Ransomware Detection Using Convergent Behavioural Signal Mapping
A Framework for Real-Time Ransomware Detection Using Convergent Behavioural Signal Mapping
Traditional signature-based detection systems often fail to identify novel ransomware strains due to their reliance on known patterns, leaving systems vulnerable to emerging threat...
Effects of Ransomware: Analysis, Challenges and Future Perspective
Effects of Ransomware: Analysis, Challenges and Future Perspective
This review paper highlights the challenges and best practices in malware analysis, specifically focusing on the age of ransomware. It provides an overview of malware and its impac...
URL-Based Classification Features in Preventing Ransomware Cyber-Attacks
URL-Based Classification Features in Preventing Ransomware Cyber-Attacks
During pandemic COVID-19 outbreaks, the number of ransomware cyber-attacks has increased tremendously. Ransomware often spreads through malicious links or compromised URLS. Such li...

Back to Top