Context-Aware Anomaly-based Detection for Ransomware using Multivariate Feature
Millati Pratiwi, Yoon-Ho Choi · 2024
In this research, we introduce a context-aware anomaly detection-based method for ransomware detection. We extracted the ransomware installation and communication stage as the context and engineered dynamic features including packet length, time delta, changes in source and destination ports, file downloads, DNS queries, protocol usage, encrypted traffic, and bytes per second (bps). Our method, evaluated using deep learning models like LSTM and Bidirectional LSTM networks, demonstrated superior performance in managing complex network traffic data. Experimental results revealed a detection accuracy of 99.37% and a precision of 100%, significantly reducing false positives compared to existing methods. Additionally, our context-aware detection achieved a stage classification accuracy of 98.99%, with a precision of 97.94%, recall of 95.77%, and an F1 score of 96.79%. These results validate the robustness of our context-aware anomaly detection framework, underscoring its potential for enhancing practical ransomware detection systems.