A new wrapper feature selection approach for binary ransomware detection

Chaieb Omar, Kannouf Nabil, Mohammed Benabdellah

Abstract


Concerns about ransomware attacks have heightened in recent years for both individuals and organizations. Detecting these malicious attacks poses considerable challenges for cybersecurity professionals, particularly due to their ever-evolving nature. Although behavior-based detection methods show promise in recognizing new ransomware variants, they face significant hurdles, especially in managing the massive volumes of data generated from real-time malware behavior monitoring, leading to high dimensionality. This paper introduces a new feature selection approach specifically for binary ransomware detection. Our method emphasizes assessing the impact of feature categories on the effectiveness and speed of detection algorithms. It involves two stages: the first stage selects the most relevant groups (categories) of features, while the second ranks and identifies the important features within those categories. Experimental results indicate that our approach surpasses similar studies regarding accuracy and ability to minimize the original features set. Moreover, both computation speed and accuracy are notably enhanced when using the selected subset compared to the original features.

Keywords


Anomaly detection; Behavior analysis; Feature selection; Machine learning; Ransomware

Full Text:

PDF


DOI: http://doi.org/10.11591/ijai.v14.i3.pp2104-2112

Refbacks

  • There are currently no refbacks.


Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

IAES International Journal of Artificial Intelligence (IJ-AI)
ISSN/e-ISSN 2089-4872/2252-8938 
This journal is published by the Institute of Advanced Engineering and Science (IAES).

View IJAI Stats