XRan: Explainable deep learning-based ransomware detection using dynamic analysis

dc.authorid0000-0001-6169-3486
dc.contributor.authorGulmez, Sibel
dc.contributor.authorKakisim, Arzu Gorgulu
dc.contributor.authorSogukpinar, Ibrahim
dc.date.accessioned2025-05-10T19:49:06Z
dc.date.issued2024
dc.departmentİstanbul Medeniyet Üniversitesi
dc.description.abstractRecently, the frequency and complexity of ransomware attacks have been increasing steadily, posing significant threats to individuals and organizations alike. While traditional signature -based antiransomware systems are effective in the detection of known threats, they struggle to identify new ransomware samples. To address this limitation, many researchers have focused on analyzing the behavior and actions of executables. During this dynamic analysis process, various dynamic -based features emerge, offering different perspectives on the executable's behavior, including Application Program Interface (API) call sequences, dynamic link libraries (DLLs), and mutual exclusions. Existing methods mostly perform machine or deep learning models for feature engineering and detection. These methods usually perform learning according to a single perspective or by combining data from different perspectives into the frequency domain. In this case, they may ignore the information from the other aspects or the sequence relationship between the features. In addition, learning models used in these solutions are mostly incomprehensible to humans, which could be an obstacle in terms of having an insight through the model's mentality and also ransomware's way of work. In this study, we provide XRan (eXplainable deep learning -based RANsomware detection using dynamic analysis), an Explainable Artificial Intelligence (XAI) supported ransomware detection system that combines different dynamic analysisbased sequences, each representing a different view of the executable, in order to enrich the feature space. XRan employs a Convolutional Neural Network (CNN) architecture to detect ransomware and two XAI models as Interpretable Model -Agnostic Explanations (LIME), and SHapley Additive exPlanations (SHAP) to provide local and global explanations for detection. Experimental results demonstrate that XRan provides up to 99.4% True Positive Rate (TPR), and outperforms the state-of-the-art methods.
dc.description.sponsorshipScientific Research Projects of Gebze Technical University [2022-A-113-03]
dc.description.sponsorshipAcknowledgements This work was supported by Scientific Research Projects of Gebze Technical University, Grant No: 2022-A-113-03.
dc.identifier.doi10.1016/j.cose.2024.103703
dc.identifier.issn0167-4048
dc.identifier.issn1872-6208
dc.identifier.scopus2-s2.0-85181979529
dc.identifier.scopusqualityQ1
dc.identifier.urihttps://doi.org/10.1016/j.cose.2024.103703
dc.identifier.urihttps://hdl.handle.net/20.500.14730/11916
dc.identifier.volume139
dc.identifier.wosWOS:001156448700001
dc.identifier.wosqualityQ1
dc.indekslendigikaynakWeb of Science
dc.indekslendigikaynakScopus
dc.language.isoen
dc.publisherElsevier Advanced Technology
dc.relation.ispartofComputers & Security
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı
dc.rightsinfo:eu-repo/semantics/closedAccess
dc.snmzKA_WOS_20250302
dc.subjectRansomware detection
dc.subjectDynamic analysis
dc.subjectDeep learning
dc.subjectXAI
dc.subjectAPI calls
dc.subjectDLLs
dc.subjectMutual exclusions
dc.titleXRan: Explainable deep learning-based ransomware detection using dynamic analysis
dc.typeArticle

Dosyalar