arrow
返回

BigRC-EML: big-data based ransomware classification using ensemble machine learning

delete2022-03-15
delete18
PRE
AI
S
Sana Aurangzeb
H
Haris Anwar
M
M. Asif Naeem
M
Muhammad Aleem *
DOI:10.1007/s10586-022-03569-4delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Ransomware is a subcategory of malware whose specific goal is to hold the victim's data by using encryption techniques until a ransom is paid. With mainstream usage of the Windows platform, Windows-based ransomware has become a great threat. With the rise of new malware categories and the huge volume of big data emerging, it has now become difficult to identify ransomware from benign applications. At the same time, ransomware detection and classification play a crucial role in computer security. Therefore, it is essential to analyze the behavior of ransomware samples to know their malicious nature that differs from clean applications. Due to the shortcomings of static analysis, we propose BigRC-EML for ransomware detection and classification based on several static and dynamic features. We use ensemble machine learning methods on big data to enhance the accuracy of the ransomware detection. Although, many machine learning models have been used in the detection of ransomware, yet, the evaluation of ensemble methods has not been investigated. Moreover, a new feature selection approach based on Principle Component Analysis (PCA) is presented to decrease the dimensions of the features. The datasets employed in the study comprised of two types: the first one is dynamic that comprises of 582 ransomware and 942 clean applications while the second one is hybrid that comprises of 500 applications. The classification models used are SVM, Random Forests, KNN, XGBoost, and Neural Network. Our experimental results show that Neural Network outperforms the other models and that BigRC-EML achieves an accuracy of 98% as well as can work under all types of data i.e. balanced, imbalanced, static, and dynamic. The experimental results successfully validate the effectiveness of the proposed approach by improving the classification accuracy of new ransomware.
Keyword:
Ransomware
Big data security
Classification
Stream
Malware analysis
Machine learning

期刊

C
Cluster Computing-The Journal of Networks Software Tools and Applications
IF:
4.1
论文数:
5.1K
被引数:
7.5K

机构

暂无机构信息
引用论文

引用论文

A Survey on Ensemble Learning for Data Stream Classification面向数据流分类的集成学习研究综述
err2017-03-27
err378
PREAI
errGomes, Heitor Murilo; Barddal, Jean Paul; Enembreck, Fabricio; Bifet, Albert
err分享
err收藏
Image-Based malware classification using ensemble of CNN architectures (IMCEC)
err2020-05-01
err239
PREAI
errVasan, Danish; Alazab, Mamoun; Wassan, Sobia; Safaei, Babak; Zheng, Qin
err分享
err收藏
err分享
err收藏
Malware Dynamic Analysis Evasion Techniques: A Survey恶意软件动态分析规避技术综述
err2019-11-14
err90
PREAI
errAfianian, Amir; Niksefat, Salman; Sadeghiyan, Babak; Baptiste, David
err分享
err收藏
err分享
err收藏
<p>Metformin Inhibits Propofol-Induced Apoptosis of Mouse Hippocampal Neurons HT-22 Through Downregulating Cav-1</p>
err2020-04-01
err0
errOAAI
errJianyun Ge; Yulin Huang; Yi Zhang; Lin Liu; Tianyu Gu; Xu Liu; Lei Yao; Mengmeng Cai; Jiafeng Sun; Jie Song
err分享
err收藏
err分享
err收藏
Evaluation of machine learning classifiers for mobile malware detection
err2014-11-09
err263
PREAI
errNarudin, Fairuz Amalina; Feizollah, Ali; Anuar, Nor Badrul; Gani, Abdullah
err分享
err收藏
Mangrove Management, Assessment and Monitoring
err2015-05-14
err0
PREAI
errKlaus Schmitt; Norman C. Duke
err分享
err收藏
学者 查看更多内容