Comparative Evaluation of Selected Machine Learning Classifier Algorithms for Ransomware Detection in Computer Networks
DOI:
https://doi.org/10.33003/fjs-2026-1018-5854Keywords:
Ransomware Detection (RD), Class imbalance, machine learning, network security, principal component analysis, Ransomware AttackAbstract
Network based extortion is the first order risk that has become the computer network, and has become a vital part of how organisations communicate, record and provide services. Ransomware wreaks havoc on services, encrypts files, finances, reputational and regulatory damage and signature-based ransomware defenses don't work very well for faster detection. In this study, the objective was to determine the best detector from four popular supervised classifiers for the case of class imbalance and feature redundancy. A quantitative experimental design was used. The UNSW-NB15 benchmark contained approximately 257,000 labelled records and 49 features was obtained. The records were cleaned, encoded and scaled, the class imbalance was corrected using an extreme gradient boosting model with a weighted loss function; the dimensionality was reduced using principal component analysis. The reduced set was then split in the ratio of 70:30 and then classified by four classifiers (SVM, RF, ANN and DT). The reproducibility was calculated with a fixed partitioning and an invariant pipeline and a peer reviewed benchmark. The accuracy rate of the neural network was 99.50 per cent and F1 score of 99.52 per cent, better than the other classifiers, random forest (98.38), support vector machine (98.04) and decision tree (96.00). The study is based on a like for like comparison, the imbalance correction and feature extraction are preserved and only the type of classifiers are changed. The choice of classifiers will have effect on the performance of the detection, however, the difference between good models-preprocessed models is not significant.
References
Akuboh, V. U., Awujoola, O. J., Monsuru, L. A., Shitu, S. S., Adebola, A., Abimuku, C. A., Musa, B. A., & Innocent, E. U. (2026). Enhancing ransomware classification using light weight machine learning algorithm and ensemble methods. FUDMA Journal of Sciences, 10(5), 275–282. https://doi.org/10.33003/fjs-2026-1005-5000
Albin Ahmed, A., Shaahid, A., Alnasser, F., Alfaddagh, S., Binagag, S., & Alqahtani, D. (2023). Android ransomware detection using supervised machine learning techniques based on traffic analysis. Sensors, 24(1), 189. https://doi.org/10.3390/s24010189
Al-Hawawreh, M., Alazab, M., Ferrag, M. A., & Hossain, M. S. (2024). Securing the industrial internet of things against ransomware attacks: A comprehensive analysis of the emerging threat landscape and detection mechanisms. Journal of Network and Computer Applications, 223, 103809. https://doi.org/10.1016/j.jnca.2023.103809
Alraizza, A., & Algarni, A. (2023). Ransomware detection using machine learning: A survey. Big Data and Cognitive Computing, 7(3), 143. https://doi.org/10.3390/bdcc7030143
Al-rimy, B. A. S., Maarof, M. A., & Shaid, S. Z. M. (2018). Ransomware threat success factors, taxonomy, and countermeasures: A survey and research directions. Computers & Security, 74, 144–166. https://doi.org/10.1016/j.cose.2018.01.001
Breiman, L. (2001). Random forests. Machine Learning, 45(1), 5–32. https://doi.org/10.1023/A:1010933404324
Chen, T., & Guestrin, C. (2016). XGBoost: A scalable tree boosting system. In Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (pp. 785–794). Association for Computing Machinery. https://doi.org/10.1145/2939672.2939785
Irankunda, D., El Fazazy, K., Hamid, T., & Riffi, J. (2025). A comparative study of deep learning-based ransomware detection for industrial IoT. International Journal of Advanced Technology and Engineering Exploration, 12(124), 450–466. https://doi.org/10.19101/IJATEE.2024.111101413
Ispahany, J., Islam, M. R., Islam, M. Z., & Khan, M. A. (2024). Ransomware detection using machine learning: A review, research limitations and future directions. IEEE Access, 12, 68785–68813. https://doi.org/10.1109/ACCESS.2024.3397921
Jolliffe, I. T., & Cadima, J. (2016). Principal component analysis: A review and recent developments. Philosophical Transactions of the Royal Society A, 374(2065), 20150202. https://doi.org/10.1098/rsta.2015.0202
Khan, F., Ncube, C., Ramasamy, L. K., Kadry, S., & Nam, Y. (2020). A digital DNA sequencing engine for ransomware detection using machine learning. IEEE Access, 8, 119710–119719. https://doi.org/10.1109/ACCESS.2020.3003785
Moustafa, N., & Slay, J. (2016). The evaluation of network anomaly detection systems: Statistical analysis of the UNSW-NB15 data set and the comparison with the KDD99 data set. Information Security Journal: A Global Perspective, 25(1–3), 18–31. https://doi.org/10.1080/19393555.2015.1125974
Moustafa, N., & Spay, J. (2015). UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). In 2015 Military Communications and Information Systems Conference (MilCIS) (pp. 1–6). IEEE. https://doi.org/10.1109/MilCIS.2015.7348942
Oz, H., Aris, A., Levi, A., & Uluagac, A. S. (2022). A survey on ransomware: Evolution, taxonomy, and defense solutions. ACM Computing Surveys, 54(11s), Article 238. https://doi.org/10.1145/3514229
Serror, M., Hack, S., Henze, M., Schuba, M., & Wehrle, K. (2021). Challenges and opportunities in securing the industrial internet of things. IEEE Transactions on Industrial Informatics, 17(5), 2985–2996. https://doi.org/10.1109/TII.2020.3023507
Urooj, U., Al-rimy, B. A. S., Zainal, A., Ghaleb, F. A., & Rassam, M. A. (2022). Ransomware detection using the dynamic analysis and machine learning: A survey and research directions. Applied Sciences, 12(1), 172. https://doi.org/10.3390/app12010172
Vehabovic, A., Ghani, N., Bou-Harb, E., Crichigno, J., & Yayimli, A. (2022). Ransomware detection and classification strategies. In 2022 IEEE International Black Sea Conference on Communications and Networking (BlackSeaCom) (pp. 316–324). IEEE. https://doi.org/10.1109/BlackSeaCom54372.2022.9858296
Zahoora, U., Khan, A., Rajarajan, M., Khan, S. H., Asam, M., & Jamal, T. (2022). Ransomware detection using deep learning based unsupervised feature extraction and a cost sensitive Pareto ensemble classifier. Scientific Reports, 12, 15647. https://doi.org/10.1038/s41598-022-19443-7
Downloads
Published
Issue
Section
Categories
License
Copyright (c) 2026 Abdulhakeem Musa, Kamil Kayode Saka, Ismail Jamiu Okunlola

This work is licensed under a Creative Commons Attribution 4.0 International License.