Automated Detection of Ransomware in Windows Active Directory Domain Services Using Log Analysis and Machine Learning

Benjamin Keyogeg, Michael Thompson, Graham Dawson, Daniel Wägner, Gabriel Johnson, Barnaby Elliott · 2024

Ransomware continues to pose one of the most severe cybersecurity challenges, particularly in enterprise environments that rely on Active Directory Domain Services (AD DS) for managing network resources and permissions. The detection of ransomware in AD environments has remained complex due to the sophisticated tactics used by modern ransomware, such as privilege escalation and lateral movement, making traditional security measures insufficient. A novel machine learning-based detection model is proposed, designed to autonomously identify ransomware activity in real time through the analysis of process creation, file access patterns, and network traffic behaviors. The model, leveraging Random Forests, demonstrates high accuracy in detecting ransomware at early stages by learning from features that reflect typical ransomware behaviors without relying solely on signature-based methods. Results show that the model performs effectively across various ransomware families, enabling rapid detection before substantial damage is done, while minimizing false positives from legitimate administrative tasks. The study also demonstrates the importance of feature engineering in enhancing detection accuracy, as well as the potential for future integration of the model into real-time monitoring systems in enterprise environments. The controlled experimental setup provided consistency in testing, but future work could explore the model's scalability and adaptability to more dynamic network conditions.

Read the paper · More papers on PaperTik