Master'sOpen Access

Detection of ransomware using machine learning algorithms

2021
0 views
0 downloads
Advisor: Prof. Dr. Murat Gök

Abstract (EN)

Ransomware is malware that encrypts computer files, preventing user access. It demands a financial fee (ransom) from people in order to open the systems it has infected. If this request fails, the victim will not be able to access encrypted files. Sometimes, even if the computer is formatted, malicious software can remain active. The victim must fulfill the request and pay the ransom in order to gain access to his files. The ransom payment is mostly requested over cryptocurrencies due to the difficulty of financial tracking. The amount of ransom required varies according to the damage inflicted. The bigger the damage, the higher the ransom demanded. The aim of this thesis is to identify ransomware with machine learning methods. The ransomware data set we use consists of 1,524 samples and 30,967 features. Multiple classification studies can be performed on this data set. In this study, firstly, ransomware classification on our dataset using Naive Bayes, Bayesian Network, k-Nearest Neighborhood (k-EYK), Random Forest, Multi-Layer Sensor Network (MCCA), Support Vector Machines (SVM) and Bagging methods. works have been carried out. In the second stage, the classification algorithms specified by the feature selection methods (Linear Forward Selection Method, Genetic Algorithm and Particle Swarm Optimization) were tested in order to increase the ransomware prediction performance. In the third stage, a new feature selection method called C-XOR has been developed. Random Forest Algorithm together with C-XOR method in multi classification gave the best result with an accuracy value of % 59.15.

Author

Dr. Volkan Okur

How to Cite

Volkan Okur (Master Thesis). Detection of ransomware using machine learning algorithms, 2021, Yalova University.

Keywords

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Yalova University