Ransomware Detection Using Federated Learning with Imbalanced Datasets

التفاصيل البيبلوغرافية
العنوان: Ransomware Detection Using Federated Learning with Imbalanced Datasets
المؤلفون: Vehabovic, Aldin, Zanddizari, Hadi, Ghani, Nasir, Javidi, G., Uluagac, S., Rahouti, M., Bou-Harb, E., Pour, M. Safaei
سنة النشر: 2023
المجموعة: Computer Science
مصطلحات موضوعية: Computer Science - Cryptography and Security
الوصف: Ransomware is a type of malware which encrypts user data and extorts payments in return for the decryption keys. This cyberthreat is one of the most serious challenges facing organizations today and has already caused immense financial damage. As a result, many researchers have been developing techniques to counter ransomware. Recently, the federated learning (FL) approach has also been applied for ransomware analysis, allowing corporations to achieve scalable, effective detection and attribution without having to share their private data. However, in reality there is much variation in the quantity and composition of ransomware data collected across multiple FL client sites/regions. This imbalance will inevitably degrade the effectiveness of any defense mechanisms. To address this concern, a modified FL scheme is proposed using a weighted cross-entropy loss function approach to mitigate dataset imbalance. A detailed performance evaluation study is then presented for the case of static analysis using the latest Windows-based ransomware families. The findings confirm improved ML classifier performance for a highly imbalanced dataset.
Comment: 6 pages, 4 figures, 3 tables
نوع الوثيقة: Working Paper
URL الوصول: http://arxiv.org/abs/2311.07760
رقم الأكسشن: edsarx.2311.07760
قاعدة البيانات: arXiv