Analysis of Machine Learning Techniques for Ransomware Detection
Title | Analysis of Machine Learning Techniques for Ransomware Detection |
Publication Type | Conference Paper |
Year of Publication | 2019 |
Authors | Noorbehbahani, Fakhroddin, Rasouli, Farzaneh, Saberi, Mohammad |
Conference Name | 2019 16th International ISC (Iranian Society of Cryptology) Conference on Information Security and Cryptology (ISCISC) |
Date Published | aug |
Keywords | CICAndMal2017 dataset, classification methods, composability, computer networks, cryptology, Human Behavior, invasive software, learning (artificial intelligence), machine learning, machine learning-based ransomware detection, malware detection, Metrics, pattern classification, policy-based governance, pubcrawl, Random Forest, ransomware, ransomware families, Resiliency, Scalability |
Abstract | In parallel with the increasing growth of the Internet and computer networks, the number of malwares has been increasing every day. Today, one of the newest attacks and the biggest threats in cybersecurity is ransomware. The effectiveness of applying machine learning techniques for malware detection has been explored in much scientific research, however, there is few studies focused on machine learning-based ransomware detection. In this paper, the effectiveness of ransomware detection using machine learning methods applied to CICAndMal2017 dataset is examined in two experiments. First, the classifiers are trained on a single dataset containing different types of ransomware. Second, different classifiers are trained on datasets of 10 ransomware families distinctly. Our findings imply that in both experiments random forest outperforms other tested classifiers and the performance of the classifiers are not changed significantly when they are trained on each family distinctly. Therefore, the random forest classification method is very effective in ransomware detection. |
DOI | 10.1109/ISCISC48546.2019.8985139 |
Citation Key | noorbehbahani_analysis_2019 |
- malware detection
- Resiliency
- ransomware families
- Ransomware
- Random Forest
- Scalability
- pubcrawl
- policy-based governance
- pattern classification
- Metrics
- CICAndMal2017 dataset
- machine learning-based ransomware detection
- machine learning
- learning (artificial intelligence)
- invasive software
- Human behavior
- cryptology
- computer networks
- composability
- classification methods