Ir directamente a la navegación principal Ir directamente a la búsqueda Ir directamente al contenido principal

Ransomware Detection Using Executable Header Features and Machine Learning Techniques

Producción científica: Capítulo del libro/informe/acta de congresoArticulo (Contribución a conferencia)revisión exhaustiva

Resumen

This study presents a machine learning-based approach for ransomware detection through the header feature of executable files. A dataset was constructed consisting of 2,497 samples, including 962 benign files and 1,535 ransomware samples belonging to 19 active families identified since 2020. The samples were collected from specialized sources and processed within a controlled virtual environment, ensuring safe conditions throughout the analysis. Various internal features were extracted from the samples and subsequently subjected to preparation, cleaning, and balancing procedures to ensure proper interpretation by the predictive models. Four widely used classification algorithms were trained: LightGBM, XGBoost, Random Forest, and MLP. After hyperparameter tuning and stratified cross-validation, each model's performance was evaluated using standard metrics such as precision, recall, and F1-score. The results showed outstanding performance from Random Forest and XGBoost, both achieving an F1-score close to 97.68%, followed closely by LightGBM. The MLP model yielded slightly lower, yet acceptable, performance. These findings confirm that static analysis, combined with machine learning techniques, is an effective alternative for detecting ransomware, enabling the accurate identification of malicious files without executing them.

Idioma originalInglés
Título de la publicación alojadaProceedings of 8th International Conference on Systems Engineering - Cybersecurity and AI
Subtítulo de la publicación alojadaBuilding a reliable digital future, CIIS 2025
EditorialAssociation for Computing Machinery, Inc
Páginas87-97
Número de páginas11
ISBN (versión digital)9798400718809
DOI
EstadoPublicada - 22 nov. 2025
Evento8th International Conference on Systems Engineering, CIIS 2025 - Hybrid, Lima, Perú
Duración: 1 oct. 20253 oct. 2025

Serie de la publicación

NombreProceedings of 8th International Conference on Systems Engineering - Cybersecurity and AI: Building a reliable digital future, CIIS 2025

Conferencia

Conferencia8th International Conference on Systems Engineering, CIIS 2025
País/TerritorioPerú
CiudadHybrid, Lima
Período1/10/253/10/25

Huella

Profundice en los temas de investigación de 'Ransomware Detection Using Executable Header Features and Machine Learning Techniques'. En conjunto forman una huella única.

Citar esto