AI-Powered Ransomware Detection Framework
Title | AI-Powered Ransomware Detection Framework |
Publication Type | Conference Paper |
Year of Publication | 2020 |
Authors | Poudyal, Subash, Dasgupta, Dipankar |
Conference Name | 2020 IEEE Symposium Series on Computational Intelligence (SSCI) |
Date Published | Dec. 2020 |
Publisher | IEEE |
ISBN Number | 978-1-7281-2547-3 |
Keywords | AI Tool, artificial intelligence, Collaboration, collaboration agreements, composability, compositionality, cryptography, dynamic binary instrumentation, Encryption, feature extraction, FP-Growth, Instruments, NLP, policy-based governance, pubcrawl, ransomware, ransomware detection, Resiliency, reverse engineering, Sandboxing, Scalability, Tools |
Abstract | Ransomware attacks are taking advantage of the ongoing pandemics and attacking the vulnerable systems in business, health sector, education, insurance, bank, and government sectors. Various approaches have been proposed to combat ransomware, but the dynamic nature of malware writers often bypasses the security checkpoints. There are commercial tools available in the market for ransomware analysis and detection, but their performance is questionable. This paper aims at proposing an AI-based ransomware detection framework and designing a detection tool (AIRaD) using a combination of both static and dynamic malware analysis techniques. Dynamic binary instrumentation is done using PIN tool, function call trace is analyzed leveraging Cuckoo sandbox and Ghidra. Features extracted at DLL, function call, and assembly level are processed with NLP, association rule mining techniques and fed to different machine learning classifiers. Support vector machine and Adaboost with J48 algorithms achieved the highest accuracy of 99.54% with 0.005 false-positive rates for a multi-level combined term frequency approach. |
URL | https://ieeexplore.ieee.org/document/9308387 |
DOI | 10.1109/SSCI47803.2020.9308387 |
Citation Key | poudyal_ai-powered_2020 |
- feature extraction
- tools
- Scalability
- sandboxing
- reverse engineering
- ransomware detection
- pubcrawl
- policy-based governance
- NLP
- Instruments
- FP-Growth
- Ransomware
- encryption
- dynamic binary instrumentation
- Cryptography
- composability
- collaboration agreements
- collaboration
- Artificial Intelligence
- AI Tool
- Compositionality
- Resiliency