Ransomware Defense Empowered: Deep Learning for Real-Time Family Identification with a Proprietary Dataset
Hassan Jalil Hadi, Yue Cao, Naveed Ahmad, Mohammed Ali Alshara · 2024
Ransomware, employing encryption techniques, presents a significant threat by rendering data inaccessible. The emergence of diverse ransomware families has inflicted substantial harm on governments, corporations, and individual users. Despite the proliferation of cyber threats, current solutions often delay in real-time detection and identifying ransomware families at early stages. In response, we introduce FCG-RFD, a benchmark dataset with extensive Function Call Graphs (FCG) for ransomware family detection. The continuous evolution of malware poses challenges to antivirus scanners, necessitating recent and updated datasets. This paper presents a dataset comprising 8,095 samples collected from VirusSamples, Virusshare, VirusSign, the Zoo, MalwareBazaar, along with 8,020 normal files collected from MS Store and Softonic. Benchmark results, utilizing LSTM models on this dataset, demonstrate competitive Fl-Scores of 99.24% aligning with State-of-the-art (SOTA) techniques. The dataset is publicly available11Dataset Link: https://figshare.com/s/b2da6a26f927627c6c4f, empowering the research community to test diverse methods for enhanced ran-somware detection capabilities.