In response to the increasing ransomware threat, this study presents a novel detection system that combines parallel Convolutional Neural Networks (CNNs) and Long Short-Term Memory (LSTM) networks. By leveraging Sysmon logs, the system enables real-time analysis on Windows-based endpoints. Our approach overcomes the limitations of traditional models by employing batch-based incremental learning, allowing the system to continuously adapt to new ransomware variants without requiring full retraining. The proposed model achieved an impressive average F2 score of 99.57%, with low false positive and false negative rates of 0.16% and 4.89%, respectively, within a highly imbalanced dataset, demonstrating exceptional accuracy in detecting malicious behaviour. The dynamic detection capabilities of Sysmon enhance the model’s effectiveness by providing a continuous stream of security events, reducing the vulnerabilities associated with static detection methods. Additionally, the parallel processing of LSTM and CNN modules, along with attention mechanisms, enables our system to achieve the highest F2 score and the lowest false negative rate compared to other popular deep learning algorithms for ransomware detection, making it highly suitable for real-world applications. These results underscore the potential of our iCNN-LSTM framework as a robust solution for real-time ransomware detection, ensuring adaptability and resilience against evolving cyber threats.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

iCNN-LSTM: An Incremental CNN-LSTM Based Ransomware Detection System

  • Jamil Ispahany,
  • MD Rafiqul Islam,
  • M. Arif Khan,
  • MD Zahidul Islam

摘要

In response to the increasing ransomware threat, this study presents a novel detection system that combines parallel Convolutional Neural Networks (CNNs) and Long Short-Term Memory (LSTM) networks. By leveraging Sysmon logs, the system enables real-time analysis on Windows-based endpoints. Our approach overcomes the limitations of traditional models by employing batch-based incremental learning, allowing the system to continuously adapt to new ransomware variants without requiring full retraining. The proposed model achieved an impressive average F2 score of 99.57%, with low false positive and false negative rates of 0.16% and 4.89%, respectively, within a highly imbalanced dataset, demonstrating exceptional accuracy in detecting malicious behaviour. The dynamic detection capabilities of Sysmon enhance the model’s effectiveness by providing a continuous stream of security events, reducing the vulnerabilities associated with static detection methods. Additionally, the parallel processing of LSTM and CNN modules, along with attention mechanisms, enables our system to achieve the highest F2 score and the lowest false negative rate compared to other popular deep learning algorithms for ransomware detection, making it highly suitable for real-world applications. These results underscore the potential of our iCNN-LSTM framework as a robust solution for real-time ransomware detection, ensuring adaptability and resilience against evolving cyber threats.