Ransomware attacks pose a formidable challenge to healthcare organizations, disrupting critical operations and demanding ransom for compromised server access. In response, the paper introduces an innovative model focused on static analysis for efficient detection and proactive prevention of such attacks. The approach diverges from the traditional reliance on time-consuming dynamic analysis, offering a streamlined yet robust defense mechanism. AIIMS Delhi’s firsthand encounter with daily disruptions and ransom demands underscores the urgency for effective solutions. Our model not only identifies ransomware attacks but also actively works to impede and thwart illegal activities, contributing to heightened cyber security resilience in the healthcare sector. The research represents a crucial step toward fortifying healthcare systems against the evolving landscape of cyber threats. The unique aspect of the proposed method lies in it's avoidance of the disassembly step. This innovation is achieved by directly extracting features from raw byte data using pattern extraction through regular occurrence, thus eliminating the need for disassembly. The approach simplifies the process and also results in a remarkable acceleration of the detection speed. The examination employed a Random Forest classifier to methodically assess how altering the quantities of trees and seeds affects the efficiency of ransomware detection. The results indicated that the optimal blend for achieving a balance between time efficiency and accuracy was found with 100 trees using a seed number 1. Through experimental evaluation, it was evident that the proposed method excelled, achieving a robust detection accuracy of 98.32% in identifying ransomware.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Ransomware Detection in Healthcare Organizations Using Supervised Learning Models: Random Forest Technique

  • Rimpa Dutta,
  • Sandip Karmakar

摘要

Ransomware attacks pose a formidable challenge to healthcare organizations, disrupting critical operations and demanding ransom for compromised server access. In response, the paper introduces an innovative model focused on static analysis for efficient detection and proactive prevention of such attacks. The approach diverges from the traditional reliance on time-consuming dynamic analysis, offering a streamlined yet robust defense mechanism. AIIMS Delhi’s firsthand encounter with daily disruptions and ransom demands underscores the urgency for effective solutions. Our model not only identifies ransomware attacks but also actively works to impede and thwart illegal activities, contributing to heightened cyber security resilience in the healthcare sector. The research represents a crucial step toward fortifying healthcare systems against the evolving landscape of cyber threats. The unique aspect of the proposed method lies in it's avoidance of the disassembly step. This innovation is achieved by directly extracting features from raw byte data using pattern extraction through regular occurrence, thus eliminating the need for disassembly. The approach simplifies the process and also results in a remarkable acceleration of the detection speed. The examination employed a Random Forest classifier to methodically assess how altering the quantities of trees and seeds affects the efficiency of ransomware detection. The results indicated that the optimal blend for achieving a balance between time efficiency and accuracy was found with 100 trees using a seed number 1. Through experimental evaluation, it was evident that the proposed method excelled, achieving a robust detection accuracy of 98.32% in identifying ransomware.