遇见数据集

A DATA DRIVEN APPROACH TO RANSOMWARE DETECTION WITH MACHINE LEARNING

收藏
Zenodo2026-04-18 更新2026-05-26 收录
官方服务:

资源简介:

Ransomware attacks represent a growing cybersecurity threat, affecting individuals and organizations by compromising data integrity, causing financial losses, and damaging reputations [1]. Early and accurate detection of ransomware is essential to mitigate these risks. This study presents a data-driven machine learning approach for ransomware detection using a dataset of 138,047 executable file records. The proposed system extracts critical Portable Executable (PE) header features — including ImageBase, SectionsMaxEntropy, and Version In formation Size — and applies a Random Forest classifier to distinguish between legitimate and malicious files [4]. To address class imbalance, SMOTE-TOMEK resampling is applied before model training. The LIME (Local Interpretable Model-agnostic Explanations) framework is integrated to provide transparency in model predictions. The system achieves an accuracy of 99.38%, precision of 98.83%, recall of 99.13%, F1-score of 98.98%, and an AUC of 99.95%, demonstrating highly reliable ransomware identification with minimal false positives

勒索软件攻击已成为日益严峻的网络安全威胁,通过破坏数据完整性、造成经济损失以及损害声誉,对个人与组织造成负面影响[1]。及早且精准地检测勒索软件,是缓解此类风险的关键所在。本研究提出了一种基于数据驱动的机器学习勒索软件检测方法,所用数据集包含138047条可执行文件记录。所提出的系统会提取关键的可移植可执行文件(Portable Executable,PE)头特征,其中包括ImageBase、SectionsMaxEntropy以及Version Information Size,并通过随机森林分类器对合法与恶意文件进行区分[4]。为解决类别不平衡问题,本研究在模型训练前采用了SMOTE-TOMEK重采样方法。本研究集成了局部可解释模型无关解释(Local Interpretable Model-agnostic Explanations,LIME)框架,以提升模型预测结果的可解释性。该系统的检测准确率达99.38%、精确率为98.83%、召回率为99.13%、F1值为98.98%,AUC值为99.95%,展现出极高的勒索软件识别可靠性,且误报率极低。

提供机构:
Zenodo
创建时间:
2026-04-18
二维码
社区交流群
二维码
科研交流群
商业服务