FLDetect: An API-Based Ransomware Detection Using Federated Learning

Tomas Petros, Henos Ghirmay, Safa Otoum, Reem Salem, Mérouane Debbah

    Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

    Abstract

    Ransomware, a malicious piece of software responsible for several high-profile attacks in recent years, poses a significant threat to organizations of all sizes. Such attacks can cause significant operational and financial harm, including system interruptions and compromises of system integrity. By developing the ability to detect and prevent ransomware attacks, we can contribute to the creation of a more secure and safe digital ecosystem. In this research, we propose FLDetect, a unique Federated Learning (FL)-based method for identifying ransomware on Windows machines. Windows machines, integral to Internet of Things (loT) networks, can act as brokers to other sensor nodes, rendering them susceptible to such attacks. Our approach utilizes distributed computing to train a Machine Learning (ML) model using data from various devices without relying on centralized data storage. The API-call-pattern-based detection method is the preferred approach for detecting ransomware in this paper. We made use of an open-source dataset, known as ransomwaredataset2016, for a comparable objective. The global model's accuracy was 93.1% after we trained it with twenty different devices. Our results demonstrate that our method is effective in identifying ransomware while maintaining the privacy and security of the training data by utilizing FL.

    Original languageBritish English
    Title of host publicationGLOBECOM 2023 - 2023 IEEE Global Communications Conference
    PublisherInstitute of Electrical and Electronics Engineers Inc.
    Pages4449-4454
    Number of pages6
    ISBN (Electronic)9798350310900
    DOIs
    StatePublished - 2023
    Event2023 IEEE Global Communications Conference, GLOBECOM 2023 - Kuala Lumpur, Malaysia
    Duration: 4 Dec 20238 Dec 2023

    Publication series

    NameProceedings - IEEE Global Communications Conference, GLOBECOM
    ISSN (Print)2334-0983
    ISSN (Electronic)2576-6813

    Conference

    Conference2023 IEEE Global Communications Conference, GLOBECOM 2023
    Country/TerritoryMalaysia
    CityKuala Lumpur
    Period4/12/238/12/23

    Keywords

    • API
    • Federated Learning (FL)
    • Ransomware Detection
    • Windows Security

    Fingerprint

    Dive into the research topics of 'FLDetect: An API-Based Ransomware Detection Using Federated Learning'. Together they form a unique fingerprint.

    Cite this