Journal / Conference2021

Ransomware Detection Based On Opcode Behavior Using K-Nearest Neighbors Algorithm

Authors

Deris Stiawan, Ahmad Heryanto, Nurul Afifah, Somame Morianus Daely, Mohd. Yazid Idris, Rahmat Budiarto

Published in

Information Technology and Control

Abstract

Ransomware is a malware that represents a serious threat to a user’s information privacy. By investigating how ransomware works, we may be able to recognise its atomic behaviour. In return, we will be able to detect the ransomware at an earlier stage with better accuracy. In this paper, we propose Control Flow Graph (CFG) as an extracting opcode behaviour technique, combined with 4-gram (sequence of 4 “words”) to extract opcode sequence to be incorporated into Trojan Ransomware detection method using K-Nearest Neighbors (K-NN) algorithm. The opcode CFG 4-gram can fully represent the detailed behavioural characteristics of Trojan Ransomware. The proposed ransomware detection method considers the closest distance to a previously identified ransomware pattern. Experimental results show that the proposed technique using K-NN, obtains the best accuracy of 98.86% for 1-gram opcode and using 1-NN classifier.

Author Team

1

Deris Stiawan

Universitas Sriwijaya

2

Ahmad Heryanto

Universitas Sriwijaya

3

Nurul Afifah

Universitas Sriwijaya

4

Somame Morianus Daely

5

Mohd. Yazid Idris

Universitas Sriwijaya

6

Rahmat Budiarto

Universitas Sriwijaya

Cite

Deris Stiawan, Ahmad Heryanto, Nurul Afifah, Somame Morianus Daely, Mohd. Yazid Idris, Rahmat Budiarto (2021). Ransomware Detection Based On Opcode Behavior Using K-Nearest Neighbors Algorithm. Information Technology and Control.