Ransomware detection using machine learning algorithms

Author: Bae, Seong Il; Lee, Gyu Bin; Im, Eul Gyu

Description: The number of ransomware variants has increased rapidly every year, and ransomware needs to be distinguished from the other types of malware to protect users’ machines from ransomware-based attacks. Ransomware is similar to other types of malware in some aspects, but other characteristics are clearly different. For example, ransomware generally conducts a large number of file-related operations in a short period of time to lock or to encrypt files of a victim’s machine. The signature-based malware detection methods, which have difficulties to detect zero-day ransomware, are not suitable to protect users’ files against the attacks caused by risky unknown ransomware. Therefore, a new protection mechanism specialized for ransomware is needed, and the mechanism should focus on ransomware-specific operations to distinguish ransomware from other types of malware as well as benign files. This paper proposes a ransomware detection method that can distinguish between ransomware and benign files as well as between ransomware and malware. The experimental results show that our proposed method can detect ransomware among malware and benign files.

Subject headings: Machine learning; Malware analysis; Malware detection; Network security; Ransomware detection

Publication year: 2020

Journal or book title: Concurrency and Computation: Practice and Experience

Volume: 32

Issue: 18

Pages: e5422

Find the full text: https://onlinelibrary.wiley.com/doi/abs/10.1002/cpe.5422

Find more like this one (cited by): https://scholar.google.com/scholar?cites=10274587148523036911&as_sdt=400005&sciodt=0,14&hl=en

Serial number: 3427

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.