返回
MIRAD: A Method for Interpretable Ransomware Attack Detection
DOI:10.1109/ACCESS.2024.3461322.png)
摘要
En 中文
In the face of escalating crypto-ransomware attacks, we introduce MIRAD, a novel dynamic detection method. MIRAD leverages machine learning to continuously monitor API calls and registry entries, detecting ransomware at all stages of infection while maintaining system performance. What sets MIRAD apart is its strong focus on interpretability. This feature allows for quick, informed adaptation to the dynamically changing threat landscape and enables the detection and elimination of errors and biases that plague black-box models. In preliminary tests on data generated in a simulated user environment, our method demonstrates a high ROC AUC, outperforming standard interpretable models such as Gaussian Naive Bayes, KNN, and Decision Trees. Importantly, MIRAD achieves a low false positive rate, addressing a common issue in dynamic ransomware detection. Our contributions also include a Python library for easy implementation of MIRAD and a comprehensive, publicly available ransomware detection dataset, facilitating broader research and implementation in ransomware defense.
Keyword:
Ransomware
Training
Heuristic algorithms
Radio frequency
Medical services
Long short term memory
Binary sequences
Explainable AI
Binary classification
ransomware detection
explainable artificial intelligence
期刊
IF:
3.6
论文数:
9.8W
被引数:
29.4W
机构
引用论文
Bismuth(III) coordination compounds. Synthesis, characterization, and X-ray structures of [Bi(Cl)(μ-Cl)2(THF)2]∞, Bi(O2CMe)3(Solv)x (Solv = py, x = 2 or MeIm, x = 4) [1], and [Bi(μ-OCH2CMe3)(OCH2CMe3)2(Solv)]2 (Solv = HOCH2CMe3 or py)
Polyhedron
IF0

