首页    期刊浏览 2024年11月30日 星期六
登录注册

文章基本信息

  • 标题:RANSOMWARE DETECTION USING CLASSIFICATION METHOD AGAINST REGISTRY DATA
  • 本地全文:下载
  • 作者:ASHMIN AZMAN ; WARUSIA YASSIN ; OTHMAN MOHD
  • 期刊名称:Journal of Theoretical and Applied Information Technology
  • 印刷版ISSN:1992-8645
  • 电子版ISSN:1817-3195
  • 出版年度:2019
  • 卷号:97
  • 期号:22
  • 页码:3366-3376
  • 出版社:Journal of Theoretical and Applied
  • 摘要:An intrusion detection system (IDS) is used to detect numerous kinds of malware attacks, and many classification methods have been introduced by the researcher to detect malware behavior. However, even though various classification method has been proposed, the detection of malware behavior remains a challenging task as the detection method focusing more on traffic data classification. Consequently, there is a lack of classification approach employed to classify Windows Registry data for malware detection. Such a situation could cause more damages if the ransomware activity intended to affect registry besides traffic. Henceforward, the objective of this paper is to study the malware behavior which targeted registry and analyzing a series of machine learning algorithm as well as identify the most accurate algorithm in the detection of malware. Thus, this paper proposes a framework for ransomware detection by using registry data as features through a number of a machine learning algorithm. Based on conducted literature, Support Vector Machine, Decision Tree, Random Forest, Jrip, and Na�ve widely applied as a classification method for malware detection. The experiments have been carried out via the algorithm mentioned above against registry data that been affected by ransomware. The algorithm is capable of classifying registry data to detect ransomware activity precisely. The main contribution of this research illustrates that registry data could be examined via the proposed framework �Malware Registry Detection Framework (MRDF)� specifically for malware detection. The findings of this experiment is the capability of the proposed method to identify ransomware activity and classify which machine learning algorithm come with the highest detection rate.
  • 关键词:Ransomware; Malware Detection; Machine Learning; Registry; Classification
国家哲学社会科学文献中心版权所有