A Behaviour based Ransomware Detection using Neural Network Models
Eleni Ketzaki, Petros Toupas, Konstantinos M. Giannoutakis, Anastasios Drosou, Dimitrios K. Tzovaras · 2020
This study proposes a behaviour based methodology for ransomware detection. Ransomware is the type of malware that restricts access to files or blocks an infected device asking victims to pay fees in order to remove the restriction. The proposed detection procedure is based on the usage of neural network methodologies for the ransomware detection assuming features that related only with the utilization of the device resources. In the first part of the study, the System Monitor Service is proposed, that records the utilisation of the workstations' resources and extracts the corresponding features that describe their behaviour. The above tool monitors in real time the CPU, the memory, the disk space, the rate of reads and writes, the number of changed, created and deleted files. The second part of the methodology concerns the development of a neural network model that detects ransomware. Based on real data that arose from the System Monitor service, a model that fulfils the modern needs regarding the performance of the agents has been developed. The proposed methodology is ideal for Small and Medium Enterprises (SMEs) that constitute a particular target of the ransomwares for financial reasons.