<p>Due to the epidemic, many industries have become increasingly reliant on computers to perform essential tasks. However, ransomware attacks pose a significant threat, with potentially devastating consequences. To mitigate these risks, many researchers have proposed large number of methods to distinguish between benign programs and ransomware, but ransomware continues to evolve, rendering these methods gradually ineffective and leaving the virus attacks unresolved. In this study, we collected 1200 samples of ransomware from 80 different families, including packed, encrypted, and variant forms, to enhance the models’ ability to detect ransomware variant. Using features such as DLLs, subsystem information, subsystem versions, and N-grams, we made three deep learning models capable of handling variable input sizes. After experiments, our best-performing model achieved an accuracy of 99.77%, a recall of 99.72%, and a precision of 99.81%. Additionally, we designed a program that integrates these trained models, allowing users to scan their computers and proactively protect themselves against ransomware threats.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Ransomware detection with CNN and deep learning based on multiple features of portable executable files

  • Chia-Cheng Yang,
  • Jia-Ming Hsu,
  • Jenq-Shiou Leu,
  • Wen-Bin Hsieh

摘要

Due to the epidemic, many industries have become increasingly reliant on computers to perform essential tasks. However, ransomware attacks pose a significant threat, with potentially devastating consequences. To mitigate these risks, many researchers have proposed large number of methods to distinguish between benign programs and ransomware, but ransomware continues to evolve, rendering these methods gradually ineffective and leaving the virus attacks unresolved. In this study, we collected 1200 samples of ransomware from 80 different families, including packed, encrypted, and variant forms, to enhance the models’ ability to detect ransomware variant. Using features such as DLLs, subsystem information, subsystem versions, and N-grams, we made three deep learning models capable of handling variable input sizes. After experiments, our best-performing model achieved an accuracy of 99.77%, a recall of 99.72%, and a precision of 99.81%. Additionally, we designed a program that integrates these trained models, allowing users to scan their computers and proactively protect themselves against ransomware threats.