Skip to main navigation Skip to search Skip to main content

On the classification of Microsoft-Windows ransomware using hardware profile

  • Sana Aurangzeb
  • , Rao Naveed Bin Rais
  • , Muhammad Aleem
  • , Muhammad Arshad Islam
  • , Muhammad Azhar Iqbal
  • National University of Modern Languages
  • National University of Computer and Emerging Science
  • Southwest Jiaotong University

Research output: Contribution to journalArticlepeer-review

28 Scopus citations

Abstract

Due to the expeditious inclination of online services usage, the incidents of ransomware proliferation being reported are on the rise. Ransomware is a more hazardous threat than other malware as the victim of ransomware cannot regain access to the hijacked device until some form of compensation is paid. In the literature, several dynamic analysis techniques have been employed for the detection of malware including ransomware; however, to the best of our knowledge, hardware execution profile for ransomware analysis has not been investigated for this purpose, as of today. In this study, we show that the true execution picture obtained via a hardware execution profile is beneficial to identify the obfuscated ransomware too. We evaluate the features obtained from hardware performance counters to classify malicious applications into ransomware and non-ransomware categories using several machine learning algorithms such as Random Forest, Decision Tree, Gradient Boosting, and Extreme Gradient Boosting. The employed data set comprises 80 ransomware and 80 non-ransomware applications, which are collected using the VirusShare platform. The results revealed that extracted hardware features play a substantial part in the identification and detection of ransomware with F-measure score of 0.97 achieved by Random Forest and Extreme Gradient Boosting.

Original languageEnglish
Pages (from-to)1-24
Number of pages24
JournalPeerJ Computer Science
Volume7
DOIs
StatePublished - 2021

Keywords

  • Classification
  • Machine learning
  • Malware
  • Performance counters
  • Ransomware

Fingerprint

Dive into the research topics of 'On the classification of Microsoft-Windows ransomware using hardware profile'. Together they form a unique fingerprint.

Cite this