Behavioral based detection of android ransomware using machine learning techniques

被引:4
作者
Kirubavathi, G. [1 ]
Anne, W. Regis [2 ]
机构
[1] Amrita Vishwa Vidyapeetham, Amrita Sch Phys Sci, Dept Math, Coimbatore, Tamilnadu, India
[2] PSG Coll Technol, Coimbatore, Tamilnadu, India
关键词
Android ransomware; Decision tree classifier; Light gradient boosting machine and random forest tree classifiers; Performance metrics; MALWARE DETECTION; BOTNETS;
D O I
10.1007/s13198-024-02439-z
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
After the pandemic, the whole world is transforming digital, due to the increased usage of handheld devices like smartphones and due to the evolution of the internet. All the transactions are becoming online. The security at end devices is an important issue to everyone. We believe that the data in transit is more secure, but in reality this is not true. The data are in the hands of bad actors for malicious activities. Android ransomware is one of the most widely distributed assaults throughout the world. It is a type of virus that prevents users from accessing the operating system and encrypts the essential data saved on their device. This work focuses on thorough assessment and detection of android ransomware application using machine learning methods. After a thorough analysis of existing mechanisms of android ransomware detection, we found that the combination of static behaviour with machine learning techniques can detect android ransomware with good accuracy. We have analysed 3572 samples of ransomware applications and 3628 samples of benign applications of various family. For classification, the decision tree, random forest, extra tree classifier, light gradient boosting machine methods are selected from the pool of classifier. The dataset was obtained from Kaggle, which is an open source dataset repository. The suggested model outperforms with a detection accuracy of 98.05%. Based on its best performance, we believe our suggested approach will be useful in ransomware and forensic investigation.
引用
收藏
页码:4404 / 4425
页数:22
相关论文
共 41 条
[1]   Android Ransomware Detection Based on Dynamic Obtained Features [J].
Abdullah, Zubaile ;
Muhadi, Farah Waheeda ;
Saudi, Madihah Mohd ;
Hamid, Isredza Rahmi A. ;
Foozy, Cik Feresa Mohd .
RECENT ADVANCES ON SOFT COMPUTING AND DATA MINING (SCDM 2020), 2020, 978 :121-129
[2]   Crypto-ransomware early detection model using novel incremental bagging with enhanced semi-random subspace selection [J].
Al-rimy, Bander Ali Saleh ;
Maarof, Mohd Aizaini ;
Shaid, Syed Zainudeen Mohd .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2019, 101 :476-491
[3]   Artificial Intelligence Algorithms for Malware Detection in Android-Operated Mobile Devices [J].
Alkahtani, Hasan ;
Aldhyani, Theyazn H. H. .
SENSORS, 2022, 22 (06)
[4]   Android Ransomware Detection Based on a Hybrid Evolutionary Approach in the Context of Highly Imbalanced Data [J].
Almomani, Iman ;
Qaddoura, Raneeem ;
Habib, Maria ;
Alsoghyer, Samah ;
Al Khayer, Alaa ;
Aljarah, Ibrahim ;
Faris, Hossam .
IEEE ACCESS, 2021, 9 :57674-57691
[5]  
Alsoghyer Samah, 2020, 2020 6th Conference on Data Science and Machine Learning Applications (CDMA), P94, DOI 10.1109/CDMA47397.2020.00022
[6]   Ransomware Detection System for Android Applications [J].
Alsoghyer, Samah ;
Almomani, Iman .
ELECTRONICS, 2019, 8 (08)
[7]   An Intelligent Behavior-Based Ransomware Detection System For Android Platform [J].
Alzahrani, Abdulrahman ;
Alshahrani, Hani ;
Alshehri, Ali ;
Fu, Huirong .
2019 FIRST IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2019), 2019, :28-35
[8]  
Alzahrani A, 2018, INT CONF ELECTRO INF, P892, DOI 10.1109/EIT.2018.8500161
[9]   A Review on Android Ransomware Detection Using Deep Learning Techniques [J].
Alzahrani, Nisreen ;
Alghazzawi, Daniyal .
11TH INTERNATIONAL CONFERENCE ON MANAGEMENT OF DIGITAL ECOSYSTEMS (MEDES), 2019, :330-335
[10]  
Anwar S, 2018, PERTANIKA J SCI TECH, V26, P37