Ransomware Detection Using Distributed Neural Decoding Networks
Paulin Odsvetov, Veronica Balmoral, Georgina Steinbruckner, Hugo Alighieri, Xavier Nightingale · 2024
Identifying malicious activities with high accuracy demands innovative solutions capable of addressing the challenges posed by evolving cyber threats. Distributed Neural Decoding Networks (DNDN) introduce a decentralized framework that leverages modular neural architectures to detect sophisticated ransomware attacks. The system integrates federated learning to preserve data privacy while enabling collaborative training across distributed nodes, reducing vulnerabilities associated with centralised detection mechanisms. The incorporation of attention mechanisms enhances the precision of detection by directing analytical focus toward critical data points. Experimental evaluations demonstrated the framework's adaptability to diverse ransomware variants, maintaining robust detection rates across varying operational contexts. Performance metrics revealed consistent improvements in accuracy, precision, and recall, highlighting the framework's ability to outperform traditional approaches. An analysis of detection latency indicated timely identification of ransomware activities, critical for mitigating potential damage in high-stakes environments. Further insights were derived from scalability tests, showing that the architecture can handle significant increases in concurrent attack volumes without substantial degradation in performance. Temporal analyses captured fluctuations in detection efficacy linked to the emergence of novel threats, while regional variations illuminated the importance of tailored configurations for diverse environments. The framework’s ability to detect anomalies associated with encryption behavior, lateral movement, and memory-based threats highlights its comprehensive applicability. By combining advanced neural processing techniques with decentralized learning strategies, the DNDN model not only enhances detection capabilities but also sets a foundation for more resilient and adaptive cybersecurity systems.