Ransomware Detection Using Network Traffic Analysis and Generative Adversarial Networks
A Wiles, F. Colombo, Rhyanna Mascorro · 2024
Ransomware is a significant threat to cybersecurity, causing severe financial and operational disruptions through the encryption of critical data and demanding ransoms for decryption. Employing Generative Adversarial Networks (GANs) for ransomware detection introduces an innovative approach that offers enhanced adaptability and precision compared to traditional signature and anomaly-based detection methods. The GAN-based model presented in this research was designed to analyze network traffic patterns, learning to distinguish between normal and ransomware-induced anomalies through an adversarial process. Experimental results indicated high accuracy, precision, recall, and F1 scores, showing the model's capability to identify subtle variations in network behavior associated with ransomware activities. The implementation demonstrated robustness in realtime scenarios, maintaining consistent detection performance over various time intervals while managing resource utilization efficiently. This research contributes to the field of cybersecurity through the development of a dynamic and adaptive detection mechanism, potentially offering a more effective defense against increasingly sophisticated ransomware attacks.