Deep Learning Approaches for Ransomware Detection: Assessing CNN and CNN-LSTM Models using Class Imbalance Methods
H Shwetha, Nandhini Vineeth, G. R. Asha · 2024
Ransomware continues to provide a serious risk to smartphone users by restricting access to data until a ransom is paid. Traditional malware detection methods, such as statistical-based approaches, often fall short against the evolving nature of Ransomware, leading to high false positive rates. In response to this problem, an evolutionary-based machine learning methodology is proposed for Ransomware detection. The PE malware dataset, comprising 96,725 benign samples and 41,328 malware samples, is utilized. Feature selection is conducted using the Extra Trees classifier, reducing the dataset to 14 key features. Models of CNN-LSTM and Convolutional Neural Networks (CNN) are applied, leveraging the method of Synthetic Minority Oversampling (SMOTE) and NearMiss for class balancing. Comparative Analysis reveals that the CNN model with SMOTE achieves the highest performance, attaining 98.90% accuracy. The CNN-LSTM models exhibit varied results, with NearMiss outperforming SMOTE (87.05% vs. 70.63%). This approach demonstrates significant potential in enhancing Ransomware detection compared to traditional methods.