XRan: Explainable deep learning-based ransomware detection using dynamic analysis

被引:11
|
作者
Gulmez, Sibel [1 ]
Kakisim, Arzu Gorgulu [2 ]
Sogukpinar, Ibrahim [1 ]
机构
[1] Gebze Tech Univ, Comp Engn Dept, Kocaeli, Turkiye
[2] Istanbul Medeniyet Univ, Comp Engn Dept, Istanbul, Turkiye
关键词
Ransomware detection; Dynamic analysis; Deep learning; XAI; API calls; DLLs; Mutual exclusions;
D O I
10.1016/j.cose.2024.103703
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, the frequency and complexity of ransomware attacks have been increasing steadily, posing significant threats to individuals and organizations alike. While traditional signature -based antiransomware systems are effective in the detection of known threats, they struggle to identify new ransomware samples. To address this limitation, many researchers have focused on analyzing the behavior and actions of executables. During this dynamic analysis process, various dynamic -based features emerge, offering different perspectives on the executable's behavior, including Application Program Interface (API) call sequences, dynamic link libraries (DLLs), and mutual exclusions. Existing methods mostly perform machine or deep learning models for feature engineering and detection. These methods usually perform learning according to a single perspective or by combining data from different perspectives into the frequency domain. In this case, they may ignore the information from the other aspects or the sequence relationship between the features. In addition, learning models used in these solutions are mostly incomprehensible to humans, which could be an obstacle in terms of having an insight through the model's mentality and also ransomware's way of work. In this study, we provide XRan (eXplainable deep learning -based RANsomware detection using dynamic analysis), an Explainable Artificial Intelligence (XAI) supported ransomware detection system that combines different dynamic analysisbased sequences, each representing a different view of the executable, in order to enrich the feature space. XRan employs a Convolutional Neural Network (CNN) architecture to detect ransomware and two XAI models as Interpretable Model -Agnostic Explanations (LIME), and SHapley Additive exPlanations (SHAP) to provide local and global explanations for detection. Experimental results demonstrate that XRan provides up to 99.4% True Positive Rate (TPR), and outperforms the state-of-the-art methods.
引用
收藏
页数:18
相关论文
共 50 条
  • [31] Two-Stage Ransomware Detection Using Dynamic Analysis and Machine Learning Techniques
    Jinsoo Hwang
    Jeankyung Kim
    Seunghwan Lee
    Kichang Kim
    Wireless Personal Communications, 2020, 112 : 2597 - 2609
  • [32] Deep learning-based object detection for dynamic construction site management
    Xu, Jiayi
    Pan, Wei
    AUTOMATION IN CONSTRUCTION, 2024, 165
  • [33] Integrating Ebola optimization search algorithm for enhanced deep learning-based ransomware detection in Internet of Things security
    Alzahrani, Ibrahim R.
    Allafi, Randa
    AIMS MATHEMATICS, 2024, 9 (03): : 6784 - 6802
  • [34] Deep learning-based crack detection in a concrete tunnel structure using multispectral dynamic imaging
    Ali, Rahmat
    Zeng, Jiangyu
    Cha, Young-Jin
    SMART STRUCTURES AND NDE FOR INDUSTRY 4.0, SMART CITIES, AND ENERGY SYSTEMS, 2020, 11382
  • [35] Improvement of Deep Learning-based Human Detection using Dynamic Thresholding for Intelligent Surveillance System
    Wahyono
    Wibowo, Moh Edi
    Ashari, Ahmad
    Putra, Muhammad Pajar Kharisma
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (10) : 472 - 477
  • [36] A Study on the Evolution of Ransomware Detection Using Machine Learning and Deep Learning Techniques
    Fernando, Damien Warren
    Komninos, Nikos
    Chen, Thomas
    IOT, 2020, 1 (02): : 551 - 604
  • [37] Natural disasters detection using explainable deep learning
    Mustafa, Ahmad M.
    Agha, Rand
    Ghazalat, Lujain
    Sha'ban, Tariq
    INTELLIGENT SYSTEMS WITH APPLICATIONS, 2024, 23
  • [38] Glaucoma Detection Using Explainable AI and Deep Learning
    Afreen N.
    Aluvalu R.
    EAI Endorsed Transactions on Pervasive Health and Technology, 2024, 10
  • [39] Deep learning-based fall detection
    Chiang, Jason Wei Hoe
    Zhang, Li
    DEVELOPMENTS OF ARTIFICIAL INTELLIGENCE TECHNOLOGIES IN COMPUTATION AND ROBOTICS, 2020, 12 : 891 - 898
  • [40] JMCD Dataset for Brain Tumor Detection and Analysis Using Explainable Deep Learning
    Verma A.
    Gupta N.
    Bhatele P.
    Khanna P.
    SN Computer Science, 4 (6)