Enhancing Machine Learning Approach Based on Nilsimsa Fingerprinting for Ransomware Detection in IoMT

被引:1
|
作者
Lucia Hernandez-Jaimes, Mireya [1 ]
Martinez-Cruz, Alfonso [1 ,2 ]
Alejandra Ramirez-Gutierrez, Kelsey [1 ,2 ]
Guevara-Martinez, Elizabeth [3 ]
机构
[1] Inst Nacl Astrofis Opt & Elect INAOE, Comp Sci Dept, Puebla 72840, Mexico
[2] Consejo Nacl Human Ciencia & Tecnol CONAHCYT, Mexico City 03940, Mexico
[3] Univ Anahuac Mexico, Engn Dept, Huixquilucan De Degollado 52786, Mexico
来源
IEEE ACCESS | 2024年 / 12卷
关键词
Artificial intelligence; attack detection; Internet of Medical Things; machine learning; Nilsimsa fingerprinting; ransomware; security; HEALTH-CARE-SYSTEMS;
D O I
10.1109/ACCESS.2024.3480889
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The heterogeneous data generated within IoMT environments have presented significant challenges in ML-based attack detection approaches, where the lack of standardized features creates a barrier. Current ML-based attack detection methods rely on feature extraction techniques, often requiring specialized security expertise to analyze and identify the most relevant features for modeling ML algorithms, hindering widespread adoption in IoMT. This study presents a new approach for detecting ransomware-spreading behavior based on Nilsimsa fingerprinting and Machine Learning to represent network traffic and detect infected network flows. The performance of our proposal was evaluated using two IoMT datasets, ICE and CICIoMT2024. Our approach demonstrated better performance than current ML-based attack detection methods using network traffic features in terms of precision, F1-score, and training efficiency across both datasets. The Random Forest algorithm modeled with Nilsimsa fingerprints on the ICE dataset achieved 100% precision and 98.72% F1-score. Similarly, on the CICIoMT2024 dataset, our approach exhibited 99.44% precision and 98.59% F1-score.
引用
收藏
页码:153886 / 153897
页数:12
相关论文
共 50 条
  • [1] Enhancing File Entropy Analysis to Improve Machine Learning Detection Rate of Ransomware
    Hsu, Chia-Ming
    Yang, Chia-Cheng
    Cheng, Han-Hsuan
    Setiasabda, Paul E.
    Leu, Jenq-Shiou
    IEEE ACCESS, 2021, 9 : 138345 - 138351
  • [2] Proposed Ransomware Detection Model Based on Machine Learning
    Gonza, Karen
    Torres, Juan
    Curioso, Mars
    Ticona, Wilfredo
    CYBERNETICS AND CONTROL THEORY IN SYSTEMS, VOL 2, CSOC 2024, 2024, 1119 : 287 - 299
  • [3] Machine Learning Based File Entropy Analysis for Ransomware Detection in Backup Systems
    Lee, Kyungroul
    Lee, Sun-Young
    Yim, Kangbin
    IEEE ACCESS, 2019, 7 : 110205 - 110215
  • [4] Ransomware detection based on machine learning using memory features
    Aljabri, Malak
    Alhaidari, Fahd
    Albuainain, Aminah
    Alrashidi, Samiyah
    Alansari, Jana
    Alqahtani, Wasmiyah
    Alshaya, Jana
    EGYPTIAN INFORMATICS JOURNAL, 2024, 25
  • [5] Machine Learning-Based Detection of Ransomware Using SDN
    Cusack, Greg
    Michel, Oliver
    Keller, Eric
    PROCEEDINGS OF THE 2018 ACM INTERNATIONAL WORKSHOP ON SECURITY IN SOFTWARE DEFINED NETWORKS & NETWORK FUNCTION VIRTUALIZATION (SDN-NFVSEC'18), 2018, : 1 - 6
  • [6] Ransomware Detection and Classification Using Machine Learning and Deep Learning
    Ouerdi, Noura
    Mejjout, Brahim
    Laaroussi, Khadija
    Kasmi, Mohammed Amine
    ADVANCES IN SMART MEDICAL, IOT & ARTIFICIAL INTELLIGENCE, VOL 1, ICSMAI 2024, 2024, 11 : 194 - 201
  • [7] Ransomware Detection in Executable Files Using Machine Learning
    Ganta, Venkata Gopi
    Harish, G. Venkata
    Kumar, V. Prem
    Rao, G. Rama Koteswar
    2020 5TH IEEE INTERNATIONAL CONFERENCE ON RECENT TRENDS ON ELECTRONICS, INFORMATION, COMMUNICATION & TECHNOLOGY (RTEICT-2020), 2020, : 282 - 286
  • [8] Ransomware Detection using Machine and Deep Learning Approaches
    Alsaidi, Ramadhan A. M.
    Yafooz, Wael M. S.
    Alolofi, Hashem
    Taufiq-Hail, Ghilan Al-Madhagy
    Emara, Abdel-Hamid M.
    Abdel-Wahab, Ahmed
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (11) : 112 - 119
  • [9] An overview of machine learning methods in enabling IoMT-based epileptic seizure detection
    Alaa Lateef Noor Al-hajjar
    Ali Kadhum M. Al-Qurabat
    The Journal of Supercomputing, 2023, 79 : 16017 - 16064
  • [10] An overview of machine learning methods in enabling IoMT-based epileptic seizure detection
    Al-hajjar, Alaa Lateef Noor
    Al-Qurabat, Ali Kadhum M.
    JOURNAL OF SUPERCOMPUTING, 2023, 79 (14) : 16017 - 16064