Analysis of the Dynamic Features on Ransomware Detection Using Deep Learning-based Methods

dc.contributor.authorGulmez, Sibel
dc.contributor.authorKakisim, Arzu Gorgulu
dc.contributor.authorSogukpinar, Ibrahim
dc.date.accessioned2025-05-10T15:23:57Z
dc.date.issued2023
dc.departmentİstanbul Medeniyet Üniversitesi
dc.description11th International Symposium on Digital Forensics and Security, ISDFS 2023 -- 11 May 2023 through 12 May 2023 -- TN -- 189042
dc.descriptionIEEE; IEEE Education Society's
dc.description.abstractRecently, the number and complexity of ran-somware attacks have been increasing day by day, threatening more individuals and organizations, both financially and reputationally, by denying users access to their files or devices and then demanding payment to restore access. Traditional anti-ransomware systems help detect known ransomware threats, but they are ineffective to identify zero-day ransomware. Therefore, many researchers use dynamic analysis approaches to provide detection by analyzing behavior and actions during execution to determine if the executable is malware. However, during dynamic analysis, many dynamic-based features can emerge, such as Application Program Interface (API) call sequences, dynamic-link libraries (DLLs), enumerated directories, mutual exclusions, and registry key operations, which can be called different views belonging to an executable. In this paper, we aim to analyze the effects of such dynamic analysis-based features obtained from the different views on ransomware detection using Convolutional Neural Network (CNN) and Long-Short-Term Memory (LSTM). To provide detailed comparison results, we use three different ransomware datasets, one malware dataset, and benign samples. The results show that true positive rate (TPR) reaches 100% for ransomware and malware datasets if the API call sequences are used as input for deep learning models, but the false positive rate (FPR) is significantly high. When we use DLLs, enumerated directories, and other features it is observed that the models achieve higher accuracy for ransomware detection, but obtain relatively lower TPR. © 2023 IEEE.
dc.description.sponsorshipGebze Technical University, (2022-A-113-03)
dc.identifier.doi10.1109/ISDFS58141.2023.10131862
dc.identifier.isbn979-835033698-6
dc.identifier.scopus2-s2.0-85163088994
dc.identifier.scopusqualityN/A
dc.identifier.urihttps://doi.org/10.1109/ISDFS58141.2023.10131862
dc.identifier.urihttps://hdl.handle.net/20.500.14730/6547
dc.indekslendigikaynakScopus
dc.language.isoen
dc.publisherInstitute of Electrical and Electronics Engineers Inc.
dc.relation.ispartofISDFS 2023 - 11th International Symposium on Digital Forensics and Security
dc.relation.publicationcategoryKonferans Öğesi - Uluslararası - Kurum Öğretim Elemanı
dc.rightsinfo:eu-repo/semantics/closedAccess
dc.snmzKA_Scopus_20250302
dc.subjectAPI calls; deep learning; dynamic analysis; malware; ransomware detection
dc.titleAnalysis of the Dynamic Features on Ransomware Detection Using Deep Learning-based Methods
dc.typeConference Object

Dosyalar

Orijinal paket

Listeleniyor 1 - 1 / 1
Yükleniyor...
Küçük Resim
İsim:
6547
Boyut:
1.12 MB
Biçim:
Adobe Portable Document Format