错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Generic Framework for Ransomware Prediction and Classification with Artificial Neural Networks

  • Saaman Nadeem,
  • Tahir Mehmood,
  • Muhammad Yaqoob

摘要

With the increase in the development of technology, the threat of “Ransomware” has also increased especially towards organizations. Ransomware is a malicious software that encrypts all the user’s data or system and demands a ransom payment for decryption. Despite various machine learning approaches proposed for ransomware detection, they often fail to identify those threats accurately in time, thus leading to data loss and victimization. This research introduces a novel framework, primarily based on static analysis of ransomware and predicting the presence of ransomware on users’ systems by monitoring a defined set of ransomware activities. In this study, we used the Resilient Information Systems Security (RISS) ransomware dataset, encompassing 582 ransomware samples from 11 distinct families and 982 instances of goodware. We proposed a generic neural network framework for the identification of ransomware and compared the performance of artificial neural networks (ANN) and deep neural networks (DNN) in terms of accurately classifying ransomware and goodware. The suggested framework secured an accuracy of 98.56% with ANNs, and achieved a slightly better performance (99.06%) when ANN was replaced with DNN. Our results showed that a basic ANN can achieve performance comparable to that of a DNN for ransomware detection. In future work, we plan to evaluate the performance of the proposed framework in a real-time setting.