The rise of ransomware attacks has necessitated the development of effective strategies for identifying and mitigating these threats. This research investigates the utilization of a feature selection algorithm for distinguishing ransomware-related and benign transactions in both Bitcoin (BTC) and United States Dollar (USD). Leveraging the UGRansome dataset, a comprehensive repository of ransomware related BTC and USD transactions, we propose a set of novel features designed to capture the distinct characteristics of ransomware activity within the cryptocurrency ecosystem. These features encompass transaction metadata, ransom analysis, and behavioral patterns, offering a multifaceted view of ransomware-related financial transactions. Through rigorous experimentation and evaluation, we demonstrate the effectiveness of our feature set in accurately extracting BTC and USD transactions, thereby aiding in the early detection and prevention of ransomware-related financial flows. We introduce a Ransomware Feature Selection Algorithm (RFSA) based on Gini Impurity and Mutual Information (MI) for selecting crucial ransomware features from the UGRansome dataset. Insights from the visualization highlight the potential of Gini Impurity and MI-based feature selection to enhance ransomware detection systems by effectively discriminating between ransomware classes. The analysis reveals that approximately 68% of ransomware incidents involve BTC transactions within the range of 1.46 to 2.56, with an average of 2.01 BTC transactions per attack. The findings emphasize the dynamic and adaptable nature of ransomware demands, suggesting that there is no fixed amount for specific cyberattacks, highlighting the evolving landscape of ransomware threats.
翻译:勒索软件攻击的激增迫使人们亟需开发有效的检测与缓解策略。本研究探讨了利用特征选择算法区分比特币(BTC)和美元(USD)交易中勒索软件相关交易与良性交易的方法。基于UGRansome数据集——一个包含勒索软件相关BTC和USD交易的综合存储库——我们提出了一组新型特征,旨在捕捉加密货币生态系统中勒索软件活动的独特特征。这些特征涵盖交易元数据、赎金分析及行为模式,为勒索软件相关金融交易提供了多维度视角。通过严格的实验与评估,我们证明了所提特征集在精准提取BTC和USD交易方面的有效性,从而助力早期检测与预防勒索软件相关资金流动。我们引入了一种基于基尼不纯度与互信息(MI)的勒索软件特征选择算法(RFSA),用于从UGRansome数据集中选择关键勒索软件特征。可视化分析揭示,基于基尼不纯度和互信息的特征选择能有效区分勒索软件类别,从而增强检测系统性能。分析表明,约68%的勒索软件事件涉及金额介于1.46至2.56 BTC的交易,单次攻击平均包含2.01笔BTC交易。研究结果强调了勒索软件赎金需求的动态性与适应性,表明特定网络攻击不存在固定金额,凸显了勒索软件威胁不断演变的趋势。