Dynamic ransomware detection for windows platform using machine learning classifiers

In this world of growing technological advancements, ransomware attacks are also on the rise. This threat often affects the finance of individuals, organizations, and financial sectors. In order to effectively detect and block these ransomware threats, the dynamic analysis strategy was proposed and...

Full description

Saved in:
Bibliographic Details
Main Authors: Jaya, M. Izham, Ab Razak, Mohd Faizal
Format: Article
Language:English
Published: Department of Information Technology - Politeknik Negeri Padang 2022
Subjects:
Online Access:http://umpir.ump.edu.my/id/eprint/35386/1/Dynamic%20ransomware%20detection%20for%20Windows%20platform.pdf
http://umpir.ump.edu.my/id/eprint/35386/
http://dx.doi.org/10.30630/joiv.6.2-2.1093
http://dx.doi.org/10.30630/joiv.6.2-2.1093
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: Universiti Malaysia Pahang
Language: English
id my.ump.umpir.35386
record_format eprints
spelling my.ump.umpir.353862022-10-11T02:29:17Z http://umpir.ump.edu.my/id/eprint/35386/ Dynamic ransomware detection for windows platform using machine learning classifiers Jaya, M. Izham Ab Razak, Mohd Faizal QA76 Computer software In this world of growing technological advancements, ransomware attacks are also on the rise. This threat often affects the finance of individuals, organizations, and financial sectors. In order to effectively detect and block these ransomware threats, the dynamic analysis strategy was proposed and carried out as the approach of this research. This paper aims to detect ransomware attacks with dynamic analysis and classify the attacks using various machine learning classifiers namely: Random Forest, Naïve Bayes, J48, Decision Table and Hoeffding Tree. The TON IoT Datasets from the University of New South Wales' (UNSW) were used to capture ransomware attack features on Windows 7. During the experiment, a testbed was configured with numerous virtual Windows 7 machines and a single attacker host to carry out the ransomware attack. A total of 77 classification features are selected based on the changes before and after the attack. Random Forest and J48 classifiers outperformed other classifiers with the highest accuracy results of 99.74%. The confusion matrix highlights that both Random Forest and J48 classifiers are able to accurately classify the ransomware attacks with the AUC value of 0.997 respectively. Our experimental result also suggests that dynamic analysis with machine learning classifier is an effective solution to detect ransomware with the accuracy percentage exceeds 98%. Department of Information Technology - Politeknik Negeri Padang 2022 Article PeerReviewed pdf en cc_by_sa_4 http://umpir.ump.edu.my/id/eprint/35386/1/Dynamic%20ransomware%20detection%20for%20Windows%20platform.pdf Jaya, M. Izham and Ab Razak, Mohd Faizal (2022) Dynamic ransomware detection for windows platform using machine learning classifiers. JOIV: International Journal on Informatics Visualization, 6 (2). 469 -474. ISSN 2549-9904 http://dx.doi.org/10.30630/joiv.6.2-2.1093 http://dx.doi.org/10.30630/joiv.6.2-2.1093
institution Universiti Malaysia Pahang
building UMP Library
collection Institutional Repository
continent Asia
country Malaysia
content_provider Universiti Malaysia Pahang
content_source UMP Institutional Repository
url_provider http://umpir.ump.edu.my/
language English
topic QA76 Computer software
spellingShingle QA76 Computer software
Jaya, M. Izham
Ab Razak, Mohd Faizal
Dynamic ransomware detection for windows platform using machine learning classifiers
description In this world of growing technological advancements, ransomware attacks are also on the rise. This threat often affects the finance of individuals, organizations, and financial sectors. In order to effectively detect and block these ransomware threats, the dynamic analysis strategy was proposed and carried out as the approach of this research. This paper aims to detect ransomware attacks with dynamic analysis and classify the attacks using various machine learning classifiers namely: Random Forest, Naïve Bayes, J48, Decision Table and Hoeffding Tree. The TON IoT Datasets from the University of New South Wales' (UNSW) were used to capture ransomware attack features on Windows 7. During the experiment, a testbed was configured with numerous virtual Windows 7 machines and a single attacker host to carry out the ransomware attack. A total of 77 classification features are selected based on the changes before and after the attack. Random Forest and J48 classifiers outperformed other classifiers with the highest accuracy results of 99.74%. The confusion matrix highlights that both Random Forest and J48 classifiers are able to accurately classify the ransomware attacks with the AUC value of 0.997 respectively. Our experimental result also suggests that dynamic analysis with machine learning classifier is an effective solution to detect ransomware with the accuracy percentage exceeds 98%.
format Article
author Jaya, M. Izham
Ab Razak, Mohd Faizal
author_facet Jaya, M. Izham
Ab Razak, Mohd Faizal
author_sort Jaya, M. Izham
title Dynamic ransomware detection for windows platform using machine learning classifiers
title_short Dynamic ransomware detection for windows platform using machine learning classifiers
title_full Dynamic ransomware detection for windows platform using machine learning classifiers
title_fullStr Dynamic ransomware detection for windows platform using machine learning classifiers
title_full_unstemmed Dynamic ransomware detection for windows platform using machine learning classifiers
title_sort dynamic ransomware detection for windows platform using machine learning classifiers
publisher Department of Information Technology - Politeknik Negeri Padang
publishDate 2022
url http://umpir.ump.edu.my/id/eprint/35386/1/Dynamic%20ransomware%20detection%20for%20Windows%20platform.pdf
http://umpir.ump.edu.my/id/eprint/35386/
http://dx.doi.org/10.30630/joiv.6.2-2.1093
http://dx.doi.org/10.30630/joiv.6.2-2.1093
_version_ 1748180695837048832