XRan: Explainable deep learning-based ransomware detection using dynamic analysis

被引:12
作者
Gulmez, Sibel [1 ]
Kakisim, Arzu Gorgulu [2 ]
Sogukpinar, Ibrahim [1 ]
机构
[1] Gebze Tech Univ, Comp Engn Dept, Kocaeli, Turkiye
[2] Istanbul Medeniyet Univ, Comp Engn Dept, Istanbul, Turkiye
关键词
Ransomware detection; Dynamic analysis; Deep learning; XAI; API calls; DLLs; Mutual exclusions;
D O I
10.1016/j.cose.2024.103703
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, the frequency and complexity of ransomware attacks have been increasing steadily, posing significant threats to individuals and organizations alike. While traditional signature -based antiransomware systems are effective in the detection of known threats, they struggle to identify new ransomware samples. To address this limitation, many researchers have focused on analyzing the behavior and actions of executables. During this dynamic analysis process, various dynamic -based features emerge, offering different perspectives on the executable's behavior, including Application Program Interface (API) call sequences, dynamic link libraries (DLLs), and mutual exclusions. Existing methods mostly perform machine or deep learning models for feature engineering and detection. These methods usually perform learning according to a single perspective or by combining data from different perspectives into the frequency domain. In this case, they may ignore the information from the other aspects or the sequence relationship between the features. In addition, learning models used in these solutions are mostly incomprehensible to humans, which could be an obstacle in terms of having an insight through the model's mentality and also ransomware's way of work. In this study, we provide XRan (eXplainable deep learning -based RANsomware detection using dynamic analysis), an Explainable Artificial Intelligence (XAI) supported ransomware detection system that combines different dynamic analysisbased sequences, each representing a different view of the executable, in order to enrich the feature space. XRan employs a Convolutional Neural Network (CNN) architecture to detect ransomware and two XAI models as Interpretable Model -Agnostic Explanations (LIME), and SHapley Additive exPlanations (SHAP) to provide local and global explanations for detection. Experimental results demonstrate that XRan provides up to 99.4% True Positive Rate (TPR), and outperforms the state-of-the-art methods.
引用
收藏
页数:18
相关论文
共 50 条
  • [21] Distributed system anomaly detection using deep learning-based log analysis
    Han, Pengfei
    Li, Huakang
    Xue, Gang
    Zhang, Chao
    COMPUTATIONAL INTELLIGENCE, 2023, 39 (03) : 433 - 455
  • [22] Explainable Deep Learning-Based Approach for Multilabel Classification of Electrocardiogram
    Ganeshkumar, M.
    Ravi, Vinayakumar
    Sowmya, V.
    Gopalakrishnan, E. A.
    Soman, K. P.
    IEEE TRANSACTIONS ON ENGINEERING MANAGEMENT, 2023, 70 (08) : 2787 - 2799
  • [23] Making Deep Learning-Based Predictions for Credit Scoring Explainable
    Dastile, Xolani
    Celik, Turgay
    IEEE ACCESS, 2021, 9 : 50426 - 50440
  • [24] Quantitative evaluation of Saliency-Based Explainable artificial intelligence (XAI) methods in Deep Learning-Based mammogram analysis
    Cerekci, Esma
    Alis, Deniz
    Denizoglu, Nurper
    Camurdan, Ozden
    Seker, Mustafa Ege
    Ozer, Caner
    Hansu, Muhammed Yusuf
    Tanyel, Toygar
    Oksuz, Ilkay
    Karaarslan, Ercan
    EUROPEAN JOURNAL OF RADIOLOGY, 2024, 173
  • [25] Deep learning-based object detection for dynamic construction site management
    Xu, Jiayi
    Pan, Wei
    AUTOMATION IN CONSTRUCTION, 2024, 165
  • [26] Deep learning-based crack detection in a concrete tunnel structure using multispectral dynamic imaging
    Ali, Rahmat
    Zeng, Jiangyu
    Cha, Young-Jin
    SMART STRUCTURES AND NDE FOR INDUSTRY 4.0, SMART CITIES, AND ENERGY SYSTEMS, 2020, 11382
  • [27] Deep Learning-Based Melanoma Detection using Attention Maps
    Andleeb, Ifrah
    Elzein, Almiqdad
    Patel, Vaibhav Anilkumar
    Alginahi, Yasser M.
    2024 IEEE 3RD INTERNATIONAL CONFERENCE ON COMPUTING AND MACHINE INTELLIGENCE, ICMI 2024, 2024,
  • [28] JMCD Dataset for Brain Tumor Detection and Analysis Using Explainable Deep Learning
    Verma A.
    Gupta N.
    Bhatele P.
    Khanna P.
    SN Computer Science, 4 (6)
  • [29] Deep learning-based fall detection
    Chiang, Jason Wei Hoe
    Zhang, Li
    DEVELOPMENTS OF ARTIFICIAL INTELLIGENCE TECHNOLOGIES IN COMPUTATION AND ROBOTICS, 2020, 12 : 891 - 898
  • [30] Object detection and recognition using deep learning-based techniques
    Sharma, Preksha
    Gupta, Surbhi
    Vyas, Sonali
    Shabaz, Mohammad
    IET COMMUNICATIONS, 2023, 17 (13) : 1589 - 1599