Edge Computing Ransomware Detection in IoT Using Machine Learning
Tejesh Radhakrishna, Nahid Ebrahimi Majd · 2024
The resurgence of ransomware has emerged as a pressing security threat in computer networks and Internet connected machines and IoT devices. To address this challenge, accurate ransomware detectors are required to automatically detect and block the malicious traffic. Most ransomware detectors only detect whether the traffic is benign or ransomware. However, detecting the family of ransomware would be greatly useful to promptly eliminate or mitigate its destructive effects. To tackle this issue, we propose machine learning models that accurately detect each ransomware family. Our models aim to detect the ransomware network traffic and thwart it at the network edge before it enters the network. Considering that ransomwares directly work with the memory dump and file system, the information extracted from the operating system's functions on the memory dump is very useful to detect a ransomware attack. However, that information could be collected only when the ransomware has already infected the device and is actively disrupting the file system. In our research, we propose a framework that blocks the ransomware at the network edge. This restricts our research to using a dataset that extracts network traffic features with no access to the device's operating system's functionalities. An edge computing intrusion detection system is also beneficial for resource contained network devices, such as IoT, which have limited computational resources and cannot dynamically analyze the network traffic and run a strong intrusion detection system. We worked on CICAndMal2017 dataset and proposed a feature selection-based framework along with different machine learning models. We also applied a data augmentation technique to the training set to strengthen the data used to build our models. We extensively studied our proposed framework. Our experimental results demonstrated that chi-square feature selection with Random Forest and XGBoost models surpass other models and the state of the art in detecting ransomware classes.