[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-126678-en":3,"doc-seo-126678-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},126678,962084925502,"Lucas Martin","https://ap-avatar.wpscdn.com/davatar_6f874abed73319feea01a86fa6f0fab8",6,"Technology","Opcodes to Images - A Framework for Early Detection of Ransomware by Utilising Machine Learning Techniques","Ransomware encrypts data and pressures victims for decryption keys, often after malicious execution has already caused irreversible disruption. The work proposes early detection by transforming ransomware binaries into image representations of extracted opcodes, then training a Convolutional Neural Network (CNN) to classify files as ransomware versus benignware. Benchmarking uses balanced accuracy, classification accuracy, and training time, with results reported as competitive against a state-of-the-art alternative, while emphasizing proactive defense through static analysis.","Opcodes to Images: A Framework for Early Detection of Ransomware by Utilising Machine  \nLearning Techniques  \nGrace Forsyth  \nAbstract—Ransomware is a type of malware that is used by attackers to encrypt data on a victim’s system and demand a ransom for the key. Ransomware is a devastating problem for individuals and businesses worldwide. The evolving world of technology opens the gates for information to be stolen and destroyed by ransomware, causing massive financial and personal data loss. To mitigate the harmful impact of ransomware, it is crucial to develop solutions that can prevent attacks by detecting them early. The problem with ransomware is that it is often not discovered on a system until it has executed. By then, it is too late to prevent all the damage it causes. This project aims to tackle this problem by developing a Convolutional Neural Network (CNN) trained on images created out of ransomware binaries. The model will be able to classify a file as ransomware, detecting it on its way into a system. The balanced accuracy, classification accuracy and training time was used for benchmarking. We compared this method to another state-of-the-art solution, where the training time was significantly smaller and the accuracy was effectively competitive.  \nI. INTRODUCTION  \nRANSOMWARE is a type of malware that is executed on  \na system and controlled by attackers. When executed, the ransomware traverses the system and encrypts files it finds and demands a ransom for the key [1] . This means that people lose access to data and disrupts business operations. Furthermore, some ransomware will lock down machines, obstructing access until the ransom is paid. However, even if the ransom is paid, the attackers may still have exfiltrated the files they found, andwill often sell the information on the dark web. Ransomware is a prominent problem today with the rise of technology, causing devastation to businesses and individuals. To truly grasp the impact of a ransomware attack, one must witness firsthand the aftermath it leaves behind. Every year, millions of people find their personal information up for sale on the dark web as a result of double-tap ransomware. Businesses suffer irreparable damage to their reputation due to ransomware attacks. The financial and personal lives of unsuspecting victims are often shattered, and the effects can be long-lasting.  \nOne of the most challenging aspects of ransomware is its stealthy nature, frequently catching its targets off guard. Without warning or early detection mechanisms in place, victims find themselves at the mercy of ransomware attacks, with limited options for recourse. The relevance of this project to society cannot be overstated. Ransomware attacks have emerged as threat, impacting individuals, businesses, and even  \nThis project was supervised by Harith Al-Sahaf (primary) and Shabbir Abbasi (secondary) .  \ncritical infrastructure. CERT NZ released that in just three months ransomware reports increased by 500% at the end of 2022 [2] . A ransomware attack on a small IT company at the end of 2022 in New Zealand gave attackers access to a large amount of data from different organisations the company had worked for. Thousands of people’s health insurance, business and personal data was found being sold on the dark web for up to $1.58 million, even though the company had paid the very expensive ransom [3] . A recent attack on Latitude resulted in over 7 million Australia and New Zealand customers having to replace drivers licenses and look out for suspicious activity around credit card applications [4] . The two methods for malware analysis are static and dynamic. Dynamic analysis requires the malware to be executed whereas static analysis gains file information without execution. Most existing ransomware detection utilises a form of machine learning to predict malicious activity based upon various aspects of ransomware. These aspects are; signatures of the file, functions the file ","cbCaibb3ueCWeLcE","https://ap.wps.com/l/cbCaibb3ueCWeLcE","pdf",6448738,1,10,"English","en",105,"# Introduction\n## Ransomware threat and impact\n## Malware analysis approaches\n## Project approach: opcodes to images and CNN\n# Goals\n## Overall aim\n## Key contributions","[{\"question\":\"为什么需要对勒索软件进行早期检测？\",\"answer\":\"勒索软件往往在执行后才被发现，导致难以及时阻止加密与业务破坏；早期识别可以降低扩散范围并减少受害者损失。\"},{\"question\":\"该项目如何实现勒索软件的检测？\",\"answer\":\"将勒索软件二进制文件提取的操作码（opcodes）转换为图像，再输入卷积神经网络（CNN）进行二分类，从而区分恶意文件与良性文件。\"},{\"question\":\"项目如何评估模型效果？\",\"answer\":\"使用平衡准确率、分类准确率和训练时间进行基准测试，并将结果与另一种前沿方案进行对比，报告其准确率具有竞争性且训练时间更短。\"}]","Opcodes to Images - A Framework for Early Detection of Ransomware by Utilising Machine Learning Techniques | PDF",1785934183,25,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"opcodes-to-images-a-framework-for-early-detection-of-ransomware-by-utilizing-machine-learning-techniques","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/technology/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/opcodes-to-images-a-framework-for-early-detection-of-ransomware-by-utilizing-machine-learning-techniques/126678/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-22","2026-08-05",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"为什么需要对勒索软件进行早期检测？","Question",{"text":76,"@type":77},"勒索软件往往在执行后才被发现，导致难以及时阻止加密与业务破坏；早期识别可以降低扩散范围并减少受害者损失。","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"该项目如何实现勒索软件的检测？",{"text":81,"@type":77},"将勒索软件二进制文件提取的操作码（opcodes）转换为图像，再输入卷积神经网络（CNN）进行二分类，从而区分恶意文件与良性文件。",{"name":83,"@type":74,"acceptedAnswer":84},"项目如何评估模型效果？",{"text":85,"@type":77},"使用平衡准确率、分类准确率和训练时间进行基准测试，并将结果与另一种前沿方案进行对比，报告其准确率具有竞争性且训练时间更短。","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,98,102,106,111,114,119,124,129,132,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":112,"slug":113},50,"technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":120,"doc_module":4,"doc_module_name":46,"category_name":121,"show_sort_weight":122,"slug":123},8,"Research & Report",30,"research-report",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":46,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":21,"slug":134},"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":107,"slug":138},19,"General","general"]