Ransomware Detection Using AES-Simulated Infections and Machine Learning Techniques
Ransomware compromises system integrity by encrypting files to demand payment, resulting in significant operational and financial losses. While machine learning methods using Format-Preserving Encryption (FPE) have been proposed for detection, their real-world applicability is limited as threat actors typically employ stronger encryption techniques. This research addresses this gap by developing a machine learning-based algorithm trained on files subjected to simulated ransomware attacks using AES-128 encryption. The model identifies ransomware by analyzing features from files encrypted with Intermittent AES128. To evaluate performance, three datasets with distinct feature combinations were created and tested across several machine learning algorithms, with hyperparameter tuning applied using GridSearchCV. The inclusion of features such as compression ratio, byte frequency distribution, and the chi-square test improved detection accuracy, with the Random Forest model demonstrating the best results and fewer false negatives. This approach serves as a functional prototype for practical ransomware detection.