An Empirical Analysis of Machine Learning Efficacy in Anti-Ransomware Tools
摘要
Researchers attempt to develop more competent anti-ransomware tools that assisted by machine learning classifiers to mitigate the threats of ransomware, protect the privacy of cyber users, and survive the security of cyberspace. However, their achievements remain insufficient in their efficacy against zero-day variants and/or imperviously detected families of ransomware during real-time practice. This is due to their partial characterizing sets of traits, limited analysis of static and dynamic actions, lacking the semi-realistic testbeds, heavy use of computer footprints, indecisive classification margins, and unavailability of representative datasets, inactive learning mechanisms. To emphasize the causality between their contributions and shortages, this paper analyzes the applied machine learning classifier in the existing anti-ransomware tools empirically. Also, it qualifies their attributes and shortages to affirm their efficacy and sufficiency for real-time ransomware detection. Empirical outcomes yield notable facets to study in the future work that will boost up the current achievements in the anti-ransomware domain.