Machine learning and deep learning for ransomware detection via feature decontamination
Sriyanto Sriyanto, Chairani Fauzi, Mohd Faizal Abdollah, Zuriati Zuriati
Abstract
The continuous escalation of ransomware attacks poses a severe risk to network infrastructure and data integrity, highlighting the urgent requirement for dependable detection systems. This paper presents a comparative analysis of deep learning (DL) and machine learning (ML) techniques for identifying ransomware traffic using the UNSW-NB15 dataset. A significant obstacle in many intrusion detection investigations is feature contamination, where specific attributes inadvertently leak label data or reflect post-incident statistics, resulting in inflated and overly optimistic performance evaluations. To mitigate this concern, a feature decontamination protocol is implemented to isolate 29 reliable attributes, followed by the application of the synthetic minority over-sampling technique (SMOTE) to address the issue of class imbalance. Empirical results demonstrate that the random forest (RF) model achieves superior performance, reaching an accuracy of 0.9027 and a recall of 0.9507. Among the DL candidates, the multi-layer perceptron (MLP) delivers the most competitive outcomes with an accuracy of 0.8859 and an F1-score of 0.8996. These results suggest that ensemble-based ML frameworks offer more effective and computationally efficient ransomware detection when applied to decontaminated tabular datasets.
Keywords
cybersecurity; feature decontamination; intrusion detection; network traffic analysis; ransomware; synthetic minority over sampling technique;
DOI:
http://doi.org/10.12928/telkomnika.v24i3.27833
Refbacks
There are currently no refbacks.
This work is licensed under a
Creative Commons Attribution-ShareAlike 4.0 International License .
TELKOMNIKA Telecommunication, Computing, Electronics and Control ISSN: 1693-6930 , e-ISSN: 2302-9293 Universitas Ahmad Dahlan , 4th Campus Jl. Ringroad Selatan, Kragilan, Tamanan, Banguntapan, Bantul, Yogyakarta, Indonesia 55191 Phone: +62 (274) 563515, 511830, 379418, 371120 Fax: +62 274 564604
<div class="statcounter"><a title="Web Analytics" href="http://statcounter.com/" target="_blank"><img class="statcounter" src="//c.statcounter.com/10241713/0/0b6069be/0/" alt="Web Analytics"></a></div> View TELKOMNIKA Stats