Real-Time Ransomware Detection by Using eBPF and Natural Language Processing and Machine Learning
Danyil Zhuravchak, Valeriy Dudykevych · 2023
This paper introduces a novel real-time ransomware detection system integrating Extended Berkeley Packet Filter (eBPF), Machine Learning (ML), and Natural Language Processing (NLP). The system architecture leverages eBPF for efficient data collection, ML for anomaly detection, and NLP for textual analysis, achieving a high detection accuracy of 94.7% with significantly reduced false positives. Evaluation on mixed datasets demonstrates the system's rapid response (average 2.3 seconds) and adaptability to new ransomware variants. Despite its effectiveness, challenges in scalability under high-volume conditions suggest areas for future enhancement. This research marks a significant step forward in proactive cybersecurity measures against evolving ransomware threats.