Using Graph Neural Network to Ransomware Detection for Cyber Threats

Hsiao-Chung Lin, Ping Wang, Wen‐Hui Lin, Yu-Hsiang Lin, Yi-Sian Yu, Jing-Huei Dai · 2024

The prevalence of malicious software (Malware) in recent years has led to many major information security incidents. Tens of millions of computers around the world are infected by malware and cause significant losses to individuals and businesses. RaaS (Ransomware-as-a-Service) is a new type of cybercrime model. Ransomware has caused losses exceeding billions of dollars every year, making it a major threat to network security. Due to the diversity of ransomware, it is difficult to extract features from ransomware, which make ransomware detection not conductive to the application of AI technology. Ransomware detection can get help from graph neural network (GNN) to learn the characteristics of ransomware. In this research, the graph convolutional network (GCN) and graph attention network (GAT) are employed for malware detection, and compare their performance with each other. Cuckoo Sandbox is deployed to log malicious behaviors generated by ransomware, and the JSON report generated by Cuckoo Sandbox is employed to extract API call sequences for ransomware detection. To evaluate the effectiveness of GCN-based and GAT-based model, the modes are evaluated with ransomware samples downloaded from Malware Bazaar Database and examined with accuracy, precision, recall and ROC curve. Experimental results show that the GCN-based and GAT-based models can detect ransomware effectively. The GCN-based model reaches better results than the GAT-based model.

Read the paper · More papers on PaperTik