Towards a Resilient Machine Learning Classifier – a Case Study of Ransomware Detection

03/13/2020
by   Chih-Yuan Yang, et al.
0

The damage caused by crypto-ransomware, due to encryption, is difficult to revert and cause data losses. In this paper, a machine learning (ML) classifier was built to early detect ransomware (called crypto-ransomware) that uses cryptography by program behavior. If a signature-based detection was missed, a behavior-based detector can be the last line of defense to detect and contain the damages. We find that input/output activities of ransomware and the file-content entropy are unique traits to detect crypto-ransomware. A deep-learning (DL) classifier can detect ransomware with a high accuracy and a low false positive rate. We conduct an adversarial research against the models generated. We use simulated ransomware programs to launch a gray-box analysis to probe the weakness of ML classifiers and to improve model robustness. In addition to accuracy and resiliency, trustworthiness is the other key criteria for a quality detector. Making sure that the correct information was used for inference is important for a security application. The Integrated Gradient method was used to explain the deep learning model and also to reveal why false negatives evade the detection. The approaches to build and to evaluate a real-world detector were demonstrated and discussed.

READ FULL TEXT

page 2

page 3

page 6

research
12/21/2018

Towards resilient machine learning for ransomware detection

There has been a surge of interest in using machine learning (ML) to aut...
research
09/24/2021

The More, the Better? A Study on Collaborative Machine Learning for DGA Detection

Domain generation algorithms (DGAs) prevent the connection between a bot...
research
07/08/2020

A Critical Evaluation of Open-World Machine Learning

Open-world machine learning (ML) combines closed-world models trained on...
research
05/28/2020

Detection of Lying Electrical Vehicles in Charging Coordination Application Using Deep Learning

The simultaneous charging of many electric vehicles (EVs) stresses the d...
research
12/04/2017

Learning Fast and Slow: PROPEDEUTICA for Real-time Malware Detection

In this paper, we introduce and evaluate PROPEDEUTICA, a novel methodolo...
research
11/08/2017

Towards Developing Network forensic mechanism for Botnet Activities in the IoT based on Machine Learning Techniques

The IoT is a network of interconnected everyday objects called things th...
research
07/17/2019

Improving Outbreak Detection with Stacking of Statistical Surveillance Methods

Epidemiologists use a variety of statistical algorithms for the early de...

Please sign up or login with your details

Forgot password? Click here to reset