Detecting Ransomware through Network Traffic Patterns using Random Forest Machine Learning
Daniel Fyford, Edward Anderson, Richard Thomas, Matthew Garcia · 2024
The cyber attacks by ransomware rapidly increased in frequency and sophistication, causing significant disruptions to critical infrastructure, businesses, and individuals. A novel approach is introduced through the analysis of network traffic patterns combined with machine learning techniques, enabling the early detection of ransomware activity prior to file encryption or data exfiltration. The Random Forest algorithm, utilized in this study, effectively handles high-dimensional datasets and offers accurate classification by leveraging important network traffic features such as flow duration, packet sizes, and byte transmission rates. Experimental results demonstrate the model's ability to detect ransomware traffic with high accuracy across various datasets while maintaining computational efficiency. The proposed methodology highlights the potential of machine learningbased network traffic analysis as a scalable and proactive solution for ransomware detection, providing an adaptable framework for future cybersecurity applications.