Ransomware Detection Model Based on Adaptive Graph Neural Network Learning

被引:0
作者
Li, Jun [1 ,2 ]
Yang, Gengyu [1 ,2 ]
Shao, Yanhua [3 ]
机构
[1] Beijing Informat Sci & Technol Univ, Artificial Intelligence Secur Innovat Res, Beijing 100192, Peoples R China
[2] Beijing Informat Sci & Technol Univ, Sch Informat Management, Beijing 100192, Peoples R China
[3] Natl Comp Syst Engn Res Inst China, Beijing 100083, Peoples R China
来源
APPLIED SCIENCES-BASEL | 2024年 / 14卷 / 11期
关键词
adaptive diffusion convolution; deep learning; graph convolutional network; network intrusion detection; ransomware detection; MALWARE DETECTION;
D O I
10.3390/app14114579
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Ransomware is a type of malicious software that encrypts or locks user files and demands a high ransom. It has become a major threat to cyberspace security, especially as it continues to be developed and updated at exponential rates. Ransomware detection technology has become a focus of research on information security risk detection methods. However, current ransomware detection techniques have high false positive and false negative rates, and traditional methods ignore global word co-occurrence and correlation information between key node steps in the entire process. This poses a significant challenge for accurately identifying and detecting ransomware. We propose a ransomware detection model based on co-occurrence information adaptive diffusion learning using a Text Graph Convolutional Network (ADC-TextGCN). Specifically, ADC-TextGCN first assign self-weights to word nodes based on sensitive API call functions and preserve co-occurrence information using Point Mutual Information Theory (COIR-PMI); then our model automatically learn the optimal neighborhood through an Adaptive Diffusion Convolution (ADC) strategy, thereby improving the ability to aggregate long-distance node information across layers and enhancing the network's ability to represent ransomware behavior. Experimental results show that our method achieves an accuracy of over 96.6% in ransomware detection, proving its effectiveness and superiority compared to traditional methods based on CNN and RNN in ransomware detection.
引用
收藏
页数:22
相关论文
共 50 条
  • [41] Anomaly detection based on a deep graph convolutional neural network for reliability improvement
    Xu, Gang
    Hu, Jie
    Qie, Xin
    Rong, Jingguo
    FRONTIERS IN ENERGY RESEARCH, 2024, 12
  • [42] An Android Malware Detection Method Based on Metapath Aggregated Graph Neural Network
    Li, Qingru
    Zhang, Yufei
    Wang, Fangwei
    Wang, Changguang
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2023, PT III, 2024, 14489 : 344 - 357
  • [43] Graph Neural Network based Netlist Operator Detection under Circuit Rewriting
    Zhao, Guangwei
    Shamsi, Kaveh
    PROCEEDINGS OF THE 32ND GREAT LAKES SYMPOSIUM ON VLSI 2022, GLSVLSI 2022, 2022, : 53 - 58
  • [44] Intelligent malware detection based on graph convolutional network
    Li, Shanxi
    Zhou, Qingguo
    Zhou, Rui
    Lv, Qingquan
    JOURNAL OF SUPERCOMPUTING, 2022, 78 (03) : 4182 - 4198
  • [45] Intelligent malware detection based on graph convolutional network
    Shanxi Li
    Qingguo Zhou
    Rui Zhou
    Qingquan Lv
    The Journal of Supercomputing, 2022, 78 : 4182 - 4198
  • [46] Overview and Case Study for Ransomware Classification Using Deep Neural Network
    Nurnoby, M. Faisal
    El-Alfy, El-Sayed M.
    2019 2ND IEEE MIDDLE EAST AND NORTH AFRICA COMMUNICATIONS CONFERENCE (IEEEMENACOMM'19), 2019, : 273 - 278
  • [47] FLDetect: An API-Based Ransomware Detection Using Federated Learning
    Petros, Tomas
    Ghirmay, Henos
    Otoum, Safa
    Salem, Reem
    Debbah, Merouane
    IEEE CONFERENCE ON GLOBAL COMMUNICATIONS, GLOBECOM, 2023, : 4449 - 4454
  • [48] Behavioral based detection of android ransomware using machine learning techniques
    Kirubavathi, G.
    Anne, W. Regis
    INTERNATIONAL JOURNAL OF SYSTEM ASSURANCE ENGINEERING AND MANAGEMENT, 2024, 15 (09) : 4404 - 4425
  • [49] A few-shot meta-learning based siamese neural network using entropy features for ransomware classification
    Zhu, Jinting
    Jang-Jaccard, Julian
    Singh, Amardeep
    Welch, Ian
    Al-Sahaf, Harith
    Camtepe, Seyit
    COMPUTERS & SECURITY, 2022, 117
  • [50] Modification of Architecture Learning Convolutional Neural Network for Graph
    Rukmanda, T. D.
    Sugeng, K. A.
    Murfi, H.
    PROCEEDINGS OF THE 3RD INTERNATIONAL SYMPOSIUM ON CURRENT PROGRESS IN MATHEMATICS AND SCIENCES 2017 (ISCPMS2017), 2018, 2023