Cross-layer ransomware detection framework for SDN using HMM, LSTM, and Bayesian inference

Yükleniyor...
Küçük Resim

Tarih

2025-08-28

Dergi Başlığı

Dergi ISSN

Cilt Başlığı

Yayıncı

Institute of Electrical and Electronics Engineers Inc.

Erişim Hakkı

info:eu-repo/semantics/closedAccess

Araştırma projeleri

Organizasyon Birimleri

Dergi sayısı

Özet

Ransomware continues to pose a serious threat to endpoint computers as well as network systems, especially in Software Defined Networks (SDN) environments where programmability and centralized control offer novel attack surfaces. In this paper, a cross-layer detection model for ransomware is introduced that integrates host-based behavioral modeling using Hidden Markov Models (HMM), anomaly detection at flow level using Long Short-Term Memory (LSTM) networks, and probabilistic fusion through Bayesian inference. By correlating host and SDN layer anomalies, the system enhances early-stage detection and reduces false positives. A variational Bayesian approximation technique is utilized for decision score stabilization under ambiguous conditions. The model is evaluated with new ransomware datasets and obtains a range between 97.5%-99.92% F1-score across three benchmark datasets with less than 50 ms latency for detection. The hybrid framework gives a promising direction for real-time threat detection in resilient programmable networks.

Açıklama

Anahtar Kelimeler

Bayesian inference, HMM, Hybrid detection systems, LSTM, Ransomware, SDN, Variational approximation, Anomaly detection, Bayesian networks, Computation theory, Computer control systems, Computer networks, Hidden Markov models, Inference engines, Variational techniques, Cross layer, Detection framework, Detection system, Hidden-Markov models, Hybrid detection, Hybrid detection system, Short term memory, Software-defined networks, Malware

Kaynak

6th International Conference on Electrical, Communication and Computer Engineering, ICECCE 2025 - Conference Proceedings

WoS Q Değeri

Scopus Q Değeri

N/A

Cilt

Sayı

Künye

Serter, C. E. & Çeliktaş, B. (2025). Cross-layer ransomware detection framework for SDN using HMM, LSTM, and Bayesian inference. Paper presented at the 6th International Conference on Electrical, Communication and Computer Engineering, ICECCE 2025 - Conference Proceedings, 1-6. doi:https://doi.org/10.1109/ICECCE67514.2025.11257888