Enhanced detection of android ransomware families using machine learning and network traffic analysis
Manmeet Mahinderjit Singh, Kalaivani Selvaraj, Zhao Wei
Abstract
Ransomware attacks on Android devices often go undetected until damage occurs, as prevention strategies are limited by inconsistent threat detection and classification. This paper presents a framework for evaluating machine learning models to detect and classify Android ransomware families through network behavioral analysis. The framework extracts discriminative features from network traffic data and segregates them into four optimal clusters using the k-means clustering method. A total of 84 critical network traffic features are identified, including source IP, destination IP, source port, destination port, traffic duration, and the total number of forward and reverse packets. These optimal features are effectively utilized to train well-known machine learning models, including decision trees (DT), random forest (RF), K-nearest neighbors (KNN), support vector machines (SVM), and bagging, to evaluate their accuracy in classifying ransomware families. Simulation results demonstrate that RF achieves the best performance with an accuracy of 95.18%, precision of 95.21%, recall of 95.27%, and F1-score of 95.19%. This framework, focused on network behavioral analysis rather than static or dynamic analysis, provides deeper insights into the behavior and characteristics of ransomware.
Keywords
Android ransomware; Classification; Detection; Dimensionality reduction; Machine learning models; Network behavioral analysis; Ransomware families
DOI:
https://doi.org/10.11591/eei.v14i4.9485
Refbacks
There are currently no refbacks.
This work is licensed under a
Creative Commons Attribution-ShareAlike 4.0 International License .
<div class="statcounter"><a title="hit counter" href="http://statcounter.com/free-hit-counter/" target="_blank"><img class="statcounter" src="http://c.statcounter.com/10241695/0/5a758c6a/0/" alt="hit counter"></a></div>
Bulletin of EEI Stats
Bulletin of Electrical Engineering and Informatics (BEEI) ISSN: 2089-3191 , e-ISSN: 2302-9285 This journal is published by the Institute of Advanced Engineering and Science (IAES) in collaboration with Intelektual Pustaka Media Utama (IPMU) .