[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-124428-en":3,"doc-seo-124428-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},124428,1374391974585,"Genevieve","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","A COMPREHENSIVE ANALYSIS OF MACHINE LEARNING BASED FILE TRAP SELECTION METHODS TO DETECT CRYPTO RANSOMWARE - Paper","The use of multi-threading and file prioritization accelerates ransomware encryption, increasing the need for early detection of file modifications. Selecting files as traps and monitoring their changes offers an endpoint-friendly way to identify ransomware at an early execution stage, reducing unnecessary overhead. This work evaluates machine learning-based trap selection methods and focuses on non-parametric clustering approaches for choosing M trap files from N directory files.","arXiv :2409 . 11428v1 [ cs .CR] 13 Sep 2024  \nA COMPREHENSIVE ANALYSIS OF MACHINE LEARNING BASED FILE TRAP SELECTION METHODS TO DETECT CRYPTO  \nRANSOMWARE  \nP. Mohan Anand, Hrushikesh Chunduri, Sandeep K Shukla  \nDepartment of Computer Science and Engineering Indian Institute of Technology Kanpur, INDIA {pmohan, hrushicnv, [sandeeps}@cse.iitk.ac.in](sandeeps}@cse.iitk.ac.in)  \nP.V. Sai Charan  \nNew York University USA  \n[v.putrevu@nyu.edu](v.putrevu@nyu.edu)  \nABSTRACT  \nThe use of multi-threading and file prioritization methods has accelerated the speed at which ransomware encrypts files. To minimize file loss during the ransomware attack, detecting file modifications at the earliest execution stage is considered very important. To achieve this, selecting files as traps and monitoring changes to them is a practical way to deal with modern ransomware variants.  \nThis approach minimizes overhead on the endpoint, facilitating early identification of ransomware.  \nThis paper evaluates various machine learning-based trap selection methods for reducing file loss, detection delay, and endpoint overhead. We specifically examine non-parametric clustering methods such as Affinity Propagation, Gaussian Mixture Models, Mean Shift, and Optics to assess their effectiveness in trap selection for ransomware detection. These methods select M files from a directory with N files (M\u003CN) and use them as traps. In order to address the shortcomings of existing machine learning-based trap selection methods, we propose APFO (Affinity Propagation with File Order) .  \nThis method is an improvement upon existing non-parametric clustering-based trap selection methods, and it helps to reduce the amount of file loss and detection delay encountered. APFO demonstrates a minimal file loss percentage of 0.32% and a detection delay of 1.03 seconds across 18 contemporary ransomware variants, including rapid encryption variants of lock-bit, AvosLocker, and Babuk.  \nKeywords Ransomware · Early Detection · Trap selection · non-parametric clustering · file loss  \n1 Introduction  \nCrypto ransomware is a pernicious malware that aims to encrypt files on any endpoint and subsequently demand a substantial ransom in exchange for the decryption key. Recent advancements in multithreading and intermittent encryption have allowed the encryption of files in parallel and only specific sections of files to be encrypted, resulting in a significant increase in file loss during ransomware attacks [1] . For example, LockBit 3.0 variants can encrypt 200,000 files in 7 minutes, whereas the Rorschach variant achieves the same in 4 .5 minutes [2] . In addition, researchers from Splunk assessed the encryption speed of various ransomware variants on 98,561 files totaling 53 GB, with their findings highlighting the rapid encryption rates of the LockBit and Babuk variants, as shown in Figure 1 [3] . The swift encryption rates showcased by these variants underscore the critical role of early detection in mitigating file loss and latency during a ransomware attack.  \nDetecting ransomware is difficult for static malware analysis methods because modern variants use packers and obfuscation techniques, complicating the detection process [4, 5, 6] . Static methods analyze strings, opcodes, and file section metadata extracted from the binary of ransomware to build models for identifying signatures. However, with recent trends, ransomware uses polymorphism techniques to mutate its structure into new versions and assist in crafting many different ransomware variants with the existing code [7] . Mutation effects, such as code alteration and structure modification, have been observed in numerous ransomware variants. For instance, cybercriminals leverage leaked code  \n[P. Mohan Anand et.al](P. Mohan Anand et.al)  \nFigure 1: Average duration of file encryption by multiple ransomware variants on 98,561 files totaling 53 GB-Reported by Splunk [3]  \nfrom Babuk variants to create new ransomware variants like ","cbCaikNzRG8tIb9T","https://ap.wps.com/l/cbCaikNzRG8tIb9T","pdf",9164006,1,19,"English","en",105,"# Introduction\n## Background and challenges in ransomware detection\n## Dynamic analysis and limitations in real-time scenarios\n## Trap-file deception and the importance of early targeting\n## Machine learning based trap selection approaches","[{\"question\":\"Why is early detection important in crypto ransomware attacks?\",\"answer\":\"Early detection can minimize file loss and detection latency, because modern ransomware can encrypt many files quickly, even in parallel or by targeting only specific sections.\"},{\"question\":\"How does the trap selection approach work for ransomware detection?\",\"answer\":\"It selects trap files on an endpoint and monitors changes to these traps so malicious activity can be identified when ransomware reaches them.\"},{\"question\":\"Which machine learning methods are evaluated for trap selection in the paper?\",\"answer\":\"The study evaluates non-parametric clustering methods including Affinity Propagation, Gaussian Mixture Models, Mean Shift, and Optics, and proposes APFO to improve shortcomings of existing methods.\"}]","A COMPREHENSIVE ANALYSIS OF MACHINE LEARNING BASED FILE TRAP SELECTION METHODS TO DETECT CRYPTO RANSOMWARE - Paper | PDF",1785822260,48,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"a-comprehensive-analysis-of-machine-learning-based-file-trap-selection-methods-to-detect-crypto-ransomware-paper","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/a-comprehensive-analysis-of-machine-learning-based-file-trap-selection-methods-to-detect-crypto-ransomware-paper/124428/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why is early detection important in crypto ransomware attacks?","Question",{"text":75,"@type":76},"Early detection can minimize file loss and detection latency, because modern ransomware can encrypt many files quickly, even in parallel or by targeting only specific sections.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the trap selection approach work for ransomware detection?",{"text":80,"@type":76},"It selects trap files on an endpoint and monitors changes to these traps so malicious activity can be identified when ransomware reaches them.",{"name":82,"@type":73,"acceptedAnswer":83},"Which machine learning methods are evaluated for trap selection in the paper?",{"text":84,"@type":76},"The study evaluates non-parametric clustering methods including Affinity Propagation, Gaussian Mixture Models, Mean Shift, and Optics, and proposes APFO to improve shortcomings of existing methods.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},"General","general"]