Malware Traffic and Ransomware Anomaly Detection Based on Wavelet Time-Frequency Analysis and Deep Learning
Weiyu Chen, Tsang-Long Pao, Yu‐Cheng Kao · Advances in Artificial Intelligence and Machine Learning · 2025
This study proposes a method for detecting malicious software traffic using wavelet timefrequency analysis combined with machine learning. The public CICIDS2017 intrusion detection dataset was utilized to extract network flow data, on which wavelet transforms were applied to obtain spectral features (such as multi-scale energy distributions and entropy). These features were used to train classification models including Support Vector Machine (SVM), Random Forest (RF), and a deep neural network. Experimental results show that wavelet-derived features significantly improve anomaly detection performance. In particular, the neural network model achieved over 97% detection accuracy, outperforming the traditional classifiers. The wavelet analysis enabled the models to accurately distinguish normal versus ransomware-like malicious traffic, even for attacks with subtle or evolving patterns. These findings demonstrate that wavelet time-frequency analysis can enhance the detection of malware traffic and provide robust recognition capability against unknown attacks.