Network Level Detection of Ransomware Attacks using Ensemble Learning

preprint OA: closed
View at publisher

Abstract

Today internet plays a major role in every individual’s life. It is seen that the usage of the internet and information technology applications had a huge increase during the recent covid-19 epidemic. This led to an increase in the number of cyber attacks. Malware is software that affects computer systems and causes damage to the system. One kind of malware is ransomware which encrypts the files or data of the victim in his system and prohibits access to the data. Access to the data is regained after a ransom amount is paid by the victim. Several approaches were proposed for the detection of ransomware attacks, which mostly were static, dynamic, and hybrid approaches. Here an approach is proposed which detects ransomware attacks by utilizing the network traffic information. After ransomware infection, the victim machine communicates with a C&C server controlled by the attacker to obtain the public key for encryption of victim data. This network traffic information is utilized to detect ransomware attacks and prevent encryption of victim data. An Ensemble Learning-based classifier is developed in which the network traffic dataset is trained and tested. The proposed classifier is compared with various other machine learning algorithms basedon the performance.

My notes (saved in your browser only)

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. The paper's references may be in our DB but unresolved to ``paper_id`` (resolution happens at ingest when the cited DOI matches a row we already have). Run the cross-source citation reconcile pass to retry.

Source provenance

europepmc
last seen: 2026-05-19T01:45:01.086888+00:00