Modified Decision Tree Technique for Ransomware Detection at Runtime through API Calls

المؤلفون المشاركون

Shah, Dilawar
Salam, Abdu
Javaid, Qaisar
Ahmad, Masood
Sarwar, Nadeem
Ullah, Faizan
Abrar, Muhammad

المصدر

Scientific Programming

العدد

المجلد 2020، العدد 2020 (31 ديسمبر/كانون الأول 2020)، ص ص. 1-10، 10ص.

الناشر

Hindawi Publishing Corporation

تاريخ النشر

2020-08-01

دولة النشر

مصر

عدد الصفحات

10

التخصصات الرئيسية

الرياضيات

الملخص EN

Ransomware (RW) is a distinctive variety of malware that encrypts the files or locks the user’s system by keeping and taking their files hostage, which leads to huge financial losses to users.

In this article, we propose a new model that extracts the novel features from the RW dataset and performs classification of the RW and benign files.

The proposed model can detect a large number of RW from various families at runtime and scan the network, registry activities, and file system throughout the execution.

API-call series was reutilized to represent the behavior-based features of RW.

The technique extracts fourteen-feature vector at runtime and analyzes it by applying online machine learning algorithms to predict the RW.

To validate the effectiveness and scalability, we test 78550 recent malign and benign RW and compare with the random forest and AdaBoost, and the testing accuracy is extended at 99.56%.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

Ullah, Faizan& Javaid, Qaisar& Salam, Abdu& Ahmad, Masood& Sarwar, Nadeem& Shah, Dilawar…[et al.]. 2020. Modified Decision Tree Technique for Ransomware Detection at Runtime through API Calls. Scientific Programming،Vol. 2020, no. 2020, pp.1-10.
https://search.emarefa.net/detail/BIM-1209198

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

Ullah, Faizan…[et al.]. Modified Decision Tree Technique for Ransomware Detection at Runtime through API Calls. Scientific Programming No. 2020 (2020), pp.1-10.
https://search.emarefa.net/detail/BIM-1209198

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

Ullah, Faizan& Javaid, Qaisar& Salam, Abdu& Ahmad, Masood& Sarwar, Nadeem& Shah, Dilawar…[et al.]. Modified Decision Tree Technique for Ransomware Detection at Runtime through API Calls. Scientific Programming. 2020. Vol. 2020, no. 2020, pp.1-10.
https://search.emarefa.net/detail/BIM-1209198

نوع البيانات

مقالات

لغة النص

الإنجليزية

الملاحظات

Includes bibliographical references

رقم السجل

BIM-1209198