Application of Improved Random Forest Method and C4.5 Algorithm as Classifier to Ransomware Detection Based on the Frequency Appearance of API Calls

Dwi Kuswanto, Husni Husni, M. Rozin Anjad · 2021

The signature base technique cannot recognize new types of Ransomware without first analyzing it. For that, we need a method to detect Ransomware using machine learning. This study aims to apply the improved Random Forest method to detect Ransomware in a random. The Forest used the feature evaluator and filter instances to increase the accuracy of the regular Random Forest. This study will use the improved Random Forest method with the C4.5 algorithm as a classifier to detect Ransomware. In this study, several stages were done to detect Malware using an improved Random Forest, namely extracting API calls, then selecting features based on the occurrence ratio of Malware, performing evaluator, resampling features, and then classifying them. The feature used API calls in the Malware based on the frequency that appears the most. Implementation of Ransomware detection using the improved Random Forest method obtained an accuracy value of 96% with an API call ratio value of 0.02 with 188 features. The results show that the Ransomware detection software is ineffective for all conditions. Because some Ransomware has not had the same API call, which affected failed the detection.

Read the paper · More papers on PaperTik