Malware Traffic and Ransomware Anomaly Detection Based on Wavelet Time-Frequency Analysis and Deep Learning

2Citations
Citations of this article
12Readers
Mendeley users who have this article in their library.

Abstract

This study proposes a method for detecting malicious software traffic using wavelet time-frequency analysis combined with machine learning. The public CICIDS2017 intrusion detection dataset was utilized to extract network flow data, on which wavelet transforms were applied to obtain spectral features (such as multi-scale energy distributions and entropy). These features were used to train classification models including Support Vector Machine (SVM), Random Forest (RF), and a deep neural network. Experimental results show that wavelet-derived features significantly improve anomaly detection performance. In particu-lar, the neural network model achieved over 97% detection accuracy, outperforming the tra-ditional classifiers. The wavelet analysis enabled the models to accurately distinguish normal versus ransomware-like malicious traffic, even for attacks with subtle or evolving patterns. These findings demonstrate that wavelet time-frequency analysis can enhance the detection of malware traffic and provide robust recognition capability against unknown attacks.

Cite

CITATION STYLE

APA

Chen, W. Y., Pao, T. L., & Kao, Y. (2025). Malware Traffic and Ransomware Anomaly Detection Based on Wavelet Time-Frequency Analysis and Deep Learning. Advances in Artificial Intelligence and Machine Learning, 5(2), 3866–3882. https://doi.org/10.54364/AAIML.2025.52219

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free