An Incremental Mutual Information-Selection Technique for Early Ransomware Detection
-
Published:2024-03-31
Issue:4
Volume:15
Page:194
-
ISSN:2078-2489
-
Container-title:Information
-
language:en
-
Short-container-title:Information
Author:
Gazzan Mazen12, Sheldon Frederick T.1ORCID
Affiliation:
1. Department of Computer Science, College of Engineering, University of Idaho, Moscow, ID 83844, USA 2. Department of Information Systems, College of Computer Science & Information Systems, Najran University, Najran 11001, Saudi Arabia
Abstract
Ransomware attacks have emerged as a significant threat to critical data and systems, extending beyond traditional computers to mobile and IoT/Cyber–Physical Systems. This study addresses the need to detect early ransomware behavior when only limited data are available. A major step for training such a detection model is choosing a set of relevant and non-redundant features, which is challenging when data are scarce. Therefore, this paper proposes an incremental mutual information-selection technique as a method for selecting the relevant features at the early stages of ransomware attacks. It introduces an adaptive feature-selection technique that processes data in smaller, manageable batches. This approach lessens the computational load and enhances the system’s ability to quickly adapt to new data arrival, making it particularly suitable for ongoing attacks during the initial phases of the attack. The experimental results emphasize the importance of the proposed technique in estimating feature significance in limited data scenarios. Such results underscore the significance of the incremental approach as a proactive measure in addressing the escalating challenges posed by ransomware.
Reference64 articles.
1. Neprash, H.T., McGlave, C.C., Cross, D.A., Virnig, B.A., Puskarich, M.A., Huling, J.D., Rozenshtein, A.Z., and Nikpay, S.S. (2022). Trends in Ransomware Attacks on US Hospitals, Clinics, and Other Health Care Delivery Organizations, 2016–2021. JAMA Health Forum, 3. 2. Automatically Traceback RDP-Based Targeted Ransomware Attacks;Wang;Wirel. Commun. Mob. Comput.,2018 3. Aboaoja, F.A., Zainal, A., Ghaleb, F.A., and Al-rimy, B.A.S. (2021). Proceeding of the 2021 International Conference on Data Science and Its Applications (ICoDSA), Bandung, Indonesia, 6–7 October 2021, IEEE. 4. A Survey on Ransomware: Evolution, Taxonomy, and Defense Solutions;Oz;ACM Comput. Surv.,2022 5. The Age of Ransomware: A Survey on the Evolution, Taxonomy, and Research Directions;Razaulla;IEEE Access,2023
|
|