4.7 Article

Behavior-based ransomware classification: A particle swarm optimization wrapper-based approach for feature selection

期刊

APPLIED SOFT COMPUTING
卷 121, 期 -, 页码 -

出版社

ELSEVIER
DOI: 10.1016/j.asoc.2022.108744

关键词

Evolutionary computation; Ransomware detection; Feature selection; Particle swarm optimization

资金

  1. Cyber Security Research Programme ``AI for Automating Response to Threats'' Ministry of Business, Innovation, and Employment (MBIE), New Zealand
  2. Catalyst Strategy Funds [MAUX1912]

向作者/读者索取更多资源

Ransomware is a type of malware that encrypts data and demands ransom. Behavior-based ransomware detection is challenging due to a large number of system calls in the analysis output. This study presents an automated feature selection method using particle swarm optimization for behavior-based ransomware detection and classification.
Ransomware is malware that encrypts the victim's data and demands a ransom for a decryption key. The increasing number of ransomware families and their variants renders the existing signature-based anti-ransomware techniques useless; thus, behavior-based detection techniques have gained popularity. A difficulty in behavior-based ransomware detection is that hundreds of thousands of system calls are obtained as analysis output, making the manual investigation and selection of ransomware-specific features infeasible. Moreover, manual investigation of the analysis output requires domain experts, who are expensive to hire and unavailable in some cases. Machine learning methods have shown success in a wide range of scientific domains to automate and address the problem of feature selection and extraction from noisy and high-dimensional data. However, automated feature selection is under-explored in malware detection. This study proposes an automated feature selection method that utilizes particle swarm optimization for behavior-based ransomware detection and classification. The proposed method considers the significance of various feature groups of the data in ransomware detection and classification and performs feature selection based on groups' significance. The experimental results show that, in most cases, the proposed method achieves comparable or significantly better performance than other state-of-the-art methods used in this study for benchmarking. In addition, this article presents an in-depth analysis of the significance of various features groups and the features selected by the proposed method in ransomware detection and classification. (c) 2022 Elsevier B.V. All rights reserved.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.7
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据