arrow
返回

MIRAD: A Method for Interpretable Ransomware Attack Detection

delete2024-01-01
delete1
delete
OA
AI
B
Bartosz Marcinkowski
M
Maja Goschorska *
N
Natalia Wileńska
J
Jakub Siuta
T
Tomasz Kajdanowicz
DOI:10.1109/ACCESS.2024.3461322delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
In the face of escalating crypto-ransomware attacks, we introduce MIRAD, a novel dynamic detection method. MIRAD leverages machine learning to continuously monitor API calls and registry entries, detecting ransomware at all stages of infection while maintaining system performance. What sets MIRAD apart is its strong focus on interpretability. This feature allows for quick, informed adaptation to the dynamically changing threat landscape and enables the detection and elimination of errors and biases that plague black-box models. In preliminary tests on data generated in a simulated user environment, our method demonstrates a high ROC AUC, outperforming standard interpretable models such as Gaussian Naive Bayes, KNN, and Decision Trees. Importantly, MIRAD achieves a low false positive rate, addressing a common issue in dynamic ransomware detection. Our contributions also include a Python library for easy implementation of MIRAD and a comprehensive, publicly available ransomware detection dataset, facilitating broader research and implementation in ransomware defense.
Keyword:
Ransomware
Training
Heuristic algorithms
Radio frequency
Medical services
Long short term memory
Binary sequences
Explainable AI
Binary classification
ransomware detection
explainable artificial intelligence

期刊

IEEE Access 封面图
IEEE Access
IF:
3.6
论文数:
9.8W
被引数:
29.4W

机构

L
Lodz University of Technology
学者数:
4.7K
论文数: 4.5K
被引数: 4.2K
W
wroclaw university of science & technology
学者数:
7.4K
论文数: 7.1K
被引数: 2
引用论文

引用论文

Ransomware detection based on machine learning using memory features
err2024-03-01
err4
errOAAI
errAljabri, Malak; Alhaidari, Fahd; Albuainain, Aminah; Alrashidi, Samiyah; Alansari, Jana; Alqahtani, Wasmiyah; Alshaya, Jana
err分享
err收藏
err分享
err收藏
Analysis of Crypto-Ransomware Using ML-Based Multi-Level Profiling
err2021-01-01
err20
errOAAI
errPoudyal, Subash; Dasgupta, Dipankar
err分享
err收藏
Know Abnormal, Find Evil: Frequent Pattern Mining for Ransomware Threat Hunting and Intelligence
err2020-04-01
err97
errOAAI
errHomayoun, Sajad; Dehghantanha, Ali; Ahmadzadeh, Marzieh; Hashemi, Sattar; Khayami, Raouf
err分享
err收藏
The Age of Ransomware: A Survey on the Evolution, Taxonomy, and Research Directions
err2023-01-01
err38
errOAAI
errRazaulla, Salwa; Fachkha, Claude; Markarian, Christine; Gawanmeh, Amjad; Mansoor, Wathiq; Fung, Benjamin C. M.; Assi, Chadi
err分享
err收藏
学者 查看更多内容