Ransomware Detection: Leveraging Sandbox, Text Mining Techiques and Machine Learning

Augusto Parisot,Raphael C. S. Machado,L. Bento
DOI: https://doi.org/10.1109/MetroInd4.0IoT61288.2024.10584155
2024-05-29
Abstract:With the significant rise in ransomware attacks in recent years, these malwares have emerged as one of the top threats to global cybersecurity. This article introduces a dynamic methodology for ransomware classification, leveraging the advanced analysis capabilities of the Cuckoo Sandbox combined with widely used machine learning techniques. We constructed three novel datasets focusing on API calls, network interactions, and string information extracted from malware samples, applying the TF-IDF technique for essential feature extraction. The efficacy of six machine learning (ML) classification algorithms is evaluated, with the Random Forest and Support Vector Machine models standing out for their exceptional robustness and adaptability across various preprocessing scenarios.
Computer Science
What problem does this paper attempt to address?