arrow
返回

RanVisStat: a statistical feature engineering approach for ransomware binary and multiclass classification using machine learning

delete2026-01-23
delete0
PRE
AI
S
Syed Shakir Hameed Shah
N
Norziana Jamil *
L
Lariyah Mohd Sidek
A
Atta ur Rehman Khan
E
Ezedin Baraka
DOI:10.1007/s00521-025-11810-5delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Ransomware attackers have expanded their targets beyond corporate entities, leveraging vulnerabilities in web security and exploiting non-technical users through phishing campaigns. Recent studies have investigated the application of entropy-based feature extraction from binary files, integrated with deep learning models, to detect malicious activity. This approach quantifies the degree of randomness or disorder within a binary file to identify potential threats. However, a critical limitation of this method is its reliance on entropy alone, which lacks sufficient contextual analysis. As a result, high-entropy segments may not reliably indicate the true malicious intent or functional behavior of ransomware. To mitigate this limitation, the present study proposes a novel statistical methodology that enhances feature extraction by incorporating both entropy measurements and contextual insights, thereby improving the accuracy and robustness of ransomware detection. The ‘ISOT Ransomware Detection Dataset’, a publicly available dataset, is utilized for this purpose. These extracted features are then fed into various machine learning classifiers to evaluate their effectiveness. Among all the classifiers tested, the Extra Trees classifier demonstrated superior performance, surpassing the others with remarkable accuracy metrics. For the multiclassification problem, it achieved an accuracy, precision, recall, and F1-score of 99.49%, 99.49%, 99.53%, and 99.51%, respectively. In the binary problem scenario, its accuracy, precision, recall, and F1-score are even higher, reaching 99.59%, 99.60%, 99.59%, and 99.59%, respectively. To the best of our knowledge, the application of statistical features extracted from visual images for classification of ransomware has not been previously explored. By utilizing a small set of statistical features, we are able to accurately describe and analyze the data, leading to highly effective ransomware detection and classification outcomes.
Keyword:
Ransomware classification
Artificial intelligence
Entropy
Contextual
Malware classification

期刊

Neural Computing and Applications 封面图
Neural Computing and Applications
IF:
4.5
论文数:
886
被引数:
3.2W

机构

I
Institute of Energy Infrastructure
学者数:
18
论文数: 16
被引数: 0
C
college of engineering and it
学者数:
3
论文数: 3
被引数: 0
C
College of Information Technology
学者数:
81
论文数: 41
被引数: 0
学者 查看更多机构
引用论文

引用论文

err分享
err收藏
A Fuzzy-Based Duo-Secure Multi-Modal Framework for IoMT Anomaly Detection
err2023-01-01
err0
errOAAI
errShiraz Ali Wagan; Jahwan Koo; Isma Farah Siddiqui; Nawab Muhammad Faseeh Qureshi; Muhammad Attique; Dong Ryeol Shin
err分享
err收藏
Mal-Detect: An intelligent visualization approach for malware detection
err2022-05-01
err0
errOAAI
errOlorunjube James Falana; Adesina Simon Sodiya; Saidat Adebukola Onashoga; Biodun Surajudeen Badmus
err分享
err收藏
Mitigating adversarial evasion attacks of ransomware using ensemble learning
err2022-05-01
err32
errOAAI
errAhmed, Usman; Lin, Jerry Chun-Wei; Srivastava, Gautam
err分享
err收藏
err分享
err收藏
err分享
err收藏
学者 查看更多内容