Revolutionizing ransomware detection and criticality assessment: Multiclass hybrid machine learning and semantic similarity-based end2end solution

被引:0
作者
Chaithanya B N
Brahmananda S H
机构
[1] Gitam School of Technology,Department of Computer Science and Engineering
来源
Multimedia Tools and Applications | 2024年 / 83卷
关键词
Ransomware; Malicious files; Machine learning; Hybridization; Data processing; Infection identification system; Criticality identification; Semantic algorithms;
D O I
暂无
中图分类号
学科分类号
摘要
In the digital environment, a ransomware detection and protection solution is crucial. Because it makes it possible for companies to combat the rising threat of ransomware attacks, prevent financial losses, preserve crucial systems, and satisfy legal requirements. The primary issue is that current ransomware detection and mitigation methods could be more effective due to its dynamic nature and an insufficient up-to-date understanding of its variants. To create more effective defenses and narrow the cybersecurity knowledge gap, interdisciplinary research that examines ransomware's coding, behavior, and goals is required. This paper seeks to improve methods of ransomware defense by analyzing the code, behavior, and goals of numerous ransomware variants. The study proposes using semantic similarity algorithms to estimate the severity of attacks and identify connections between existing attacks to enhance detection and mitigation measures. The objectives of this paper include developing an improved, all-inclusive multiclass ransomware detection and response generation model with automatic or semi-automatic response capabilities. The method combines artificial intelligence with semantic similarity detection techniques to automatically identify and classify ransomware attacks using predefined classifiers. Single machine learning techniques were initially trained on a dataset of ransomware samples; however, the accuracy was poor, ranging from 11% with the LGBM classifier to a maximum of 51% with the decision tree classifier. A hybridization of ML algorithms increases accuracy, leading to a notable improvement in classifier accuracy, with a Hybrid 3 obtaining 91% accuracy. Semantic algorithms periodically retrain the model to keep it current with new ransomware variations. These algorithms also provide the severity of the attack. If the criticality is low, the model notifies the administrator for additional analysis; if it is medium, sensitive data-related operations are stopped with automatic backups; and if it is high, all processes are controlled to prevent further harm. The key advantages of this model are its ability to identify 21 different ransomware classes, enhance training with new variants, and provide criticality recommendations for optimal decision-making during a ransomware assault.
引用
收藏
页码:39135 / 39168
页数:33
相关论文
共 59 条
[1]  
Jiang JX(2019)Types of information compromised in breaches of protected health information Ann Intern Med 172 159-28
[2]  
Bai G(2023)BSFR-SH: Blockchain-enabled security framework against ransomware attacks for smart healthcare IEEE Trans Consum Electron 69 18-210
[3]  
Wazid M(2015)Understanding DDoS attack & its effect in cloud environment Proc Comput Sci 49 202-9
[4]  
Kumar Das A(2016)Ransomware attacks: detection, prevention, and cure Netw Secur 2016 5-797
[5]  
Shetty S(2021)Digital hostages: Leveraging ransomware attacks in cyberspace Bus Horiz 64 787-117
[6]  
Deshmukh RV(2022)A crypto-steganography approach for hiding ransomware within HEVC streams in android IoT devices Sensors 22 2281-181
[7]  
Devadkar KK(2022)The rise of ransomware: Forensic analysis for windows-based ransomware attacks Expert Syst Appl 190 116198-12
[8]  
Brewer R(2021)Internet of things and ransomware: Evolution, mitigation and prevention Egypt Inf J 22 105-107
[9]  
Wade M(2020)The ransomware-as-a-service economy within the darknet Comput Secur 92 101762-8
[10]  
Almomani I(2019)Economics of ransomware attacks SSRN Electron J 138 113400-632