Research Article

Real-Time Malware Process Detection and Automated Process Killing

Table 13

Total number of files corrupted by ransomware with no process killing and with three process killing models within the first 30 seconds of execution. Damage reduction is the percentage of files spared when no killing is implemented.

ModelFiles damagedDamage reductionDetection rate (ransomware TPR)Test set TPR

No killing19,997
DT pro rolling mean 2399.98%100.0088.40
RF glo + pro min alerts 21,46492.68%100.0087.97
GBDT regressor + min 4 alerts15,43222.83%22.0756.04
AdaBoost regressor20,5780.00%9.098.83