NEXT-GENERATION RANSOMWARE DEFENSE: HIGH-PERFORMANCE COMPUTING STRATEGIES FOR MONITORING DISK I/O AND CPU PERFORMANCE
Keywords:
Deep learning, disk statistics, hardware performance counters, machine learning, ransomware, virtual machinesAbstract
Ransomware frequently bypasses antivirus tools, encrypting files and making data inaccessible. Traditional detection methods, which involve monitoring processes, system calls, and file activities, have high overhead and can be disrupted by sophisticated ransomware. This Researchintroduces a method for detecting ransomware on a virtual machine by collecting specific processor and disk I/O event data from the host machine and using a machine learning classifier. The random forest model excelled among seven classifiers, achieving 0.98 accuracy within 400 milliseconds across various user loads and 22 ransomware types.
Downloads
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.