Comparative Evaluation of Selected Machine Learning Classifier Algorithms for Ransomware Detection in Computer Networks

Authors

  • Abdulhakeem Musa Al- Hikmah University, Ilorin
  • Kamil Kayode Saka
  • Ismail Jamiu Okunlola

DOI:

https://doi.org/10.33003/fjs-2026-1018-5854

Keywords:

Ransomware Detection (RD), Class imbalance, machine learning, network security, principal component analysis, Ransomware Attack

Abstract

Network based extortion is the first order risk that has become the computer network, and has become a vital part of how organisations communicate, record and provide services. Ransomware wreaks havoc on services, encrypts files, finances, reputational and regulatory damage and signature-based ransomware defenses don't work very well for faster detection. In this study, the objective was to determine the best detector from four popular supervised classifiers for the case of class imbalance and feature redundancy. A quantitative experimental design was used. The UNSW-NB15 benchmark contained approximately 257,000 labelled records and 49 features was obtained. The records were cleaned, encoded and scaled, the class imbalance was corrected using an extreme gradient boosting model with a weighted loss function; the dimensionality was reduced using principal component analysis. The reduced set was then split in the ratio of 70:30 and then classified by four classifiers (SVM, RF, ANN and DT). The reproducibility was calculated with a fixed partitioning and an invariant pipeline and a peer reviewed benchmark. The accuracy rate of the neural network was 99.50 per cent and F1 score of 99.52 per cent, better than the other classifiers, random forest (98.38), support vector machine (98.04) and decision tree (96.00). The study is based on a like for like comparison, the imbalance correction and feature extraction are preserved and only the type of classifiers are changed. The choice of classifiers will have effect on the performance of the detection, however, the difference between good models-preprocessed models is not significant.

References

Akuboh, V. U., Awujoola, O. J., Monsuru, L. A., Shitu, S. S., Adebola, A., Abimuku, C. A., Musa, B. A., & Innocent, E. U. (2026). Enhancing ransomware classification using light weight machine learning algorithm and ensemble methods. FUDMA Journal of Sciences, 10(5), 275–282. https://doi.org/10.33003/fjs-2026-1005-5000

Albin Ahmed, A., Shaahid, A., Alnasser, F., Alfaddagh, S., Binagag, S., & Alqahtani, D. (2023). Android ransomware detection using supervised machine learning techniques based on traffic analysis. Sensors, 24(1), 189. https://doi.org/10.3390/s24010189

Al-Hawawreh, M., Alazab, M., Ferrag, M. A., & Hossain, M. S. (2024). Securing the industrial internet of things against ransomware attacks: A comprehensive analysis of the emerging threat landscape and detection mechanisms. Journal of Network and Computer Applications, 223, 103809. https://doi.org/10.1016/j.jnca.2023.103809

Alraizza, A., & Algarni, A. (2023). Ransomware detection using machine learning: A survey. Big Data and Cognitive Computing, 7(3), 143. https://doi.org/10.3390/bdcc7030143

Al-rimy, B. A. S., Maarof, M. A., & Shaid, S. Z. M. (2018). Ransomware threat success factors, taxonomy, and countermeasures: A survey and research directions. Computers & Security, 74, 144–166. https://doi.org/10.1016/j.cose.2018.01.001

Breiman, L. (2001). Random forests. Machine Learning, 45(1), 5–32. https://doi.org/10.1023/A:1010933404324

Chen, T., & Guestrin, C. (2016). XGBoost: A scalable tree boosting system. In Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (pp. 785–794). Association for Computing Machinery. https://doi.org/10.1145/2939672.2939785

Irankunda, D., El Fazazy, K., Hamid, T., & Riffi, J. (2025). A comparative study of deep learning-based ransomware detection for industrial IoT. International Journal of Advanced Technology and Engineering Exploration, 12(124), 450–466. https://doi.org/10.19101/IJATEE.2024.111101413

Ispahany, J., Islam, M. R., Islam, M. Z., & Khan, M. A. (2024). Ransomware detection using machine learning: A review, research limitations and future directions. IEEE Access, 12, 68785–68813. https://doi.org/10.1109/ACCESS.2024.3397921

Jolliffe, I. T., & Cadima, J. (2016). Principal component analysis: A review and recent developments. Philosophical Transactions of the Royal Society A, 374(2065), 20150202. https://doi.org/10.1098/rsta.2015.0202

Khan, F., Ncube, C., Ramasamy, L. K., Kadry, S., & Nam, Y. (2020). A digital DNA sequencing engine for ransomware detection using machine learning. IEEE Access, 8, 119710–119719. https://doi.org/10.1109/ACCESS.2020.3003785

Moustafa, N., & Slay, J. (2016). The evaluation of network anomaly detection systems: Statistical analysis of the UNSW-NB15 data set and the comparison with the KDD99 data set. Information Security Journal: A Global Perspective, 25(1–3), 18–31. https://doi.org/10.1080/19393555.2015.1125974

Moustafa, N., & Spay, J. (2015). UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). In 2015 Military Communications and Information Systems Conference (MilCIS) (pp. 1–6). IEEE. https://doi.org/10.1109/MilCIS.2015.7348942

Oz, H., Aris, A., Levi, A., & Uluagac, A. S. (2022). A survey on ransomware: Evolution, taxonomy, and defense solutions. ACM Computing Surveys, 54(11s), Article 238. https://doi.org/10.1145/3514229

Serror, M., Hack, S., Henze, M., Schuba, M., & Wehrle, K. (2021). Challenges and opportunities in securing the industrial internet of things. IEEE Transactions on Industrial Informatics, 17(5), 2985–2996. https://doi.org/10.1109/TII.2020.3023507

Urooj, U., Al-rimy, B. A. S., Zainal, A., Ghaleb, F. A., & Rassam, M. A. (2022). Ransomware detection using the dynamic analysis and machine learning: A survey and research directions. Applied Sciences, 12(1), 172. https://doi.org/10.3390/app12010172

Vehabovic, A., Ghani, N., Bou-Harb, E., Crichigno, J., & Yayimli, A. (2022). Ransomware detection and classification strategies. In 2022 IEEE International Black Sea Conference on Communications and Networking (BlackSeaCom) (pp. 316–324). IEEE. https://doi.org/10.1109/BlackSeaCom54372.2022.9858296

Zahoora, U., Khan, A., Rajarajan, M., Khan, S. H., Asam, M., & Jamal, T. (2022). Ransomware detection using deep learning based unsupervised feature extraction and a cost sensitive Pareto ensemble classifier. Scientific Reports, 12, 15647. https://doi.org/10.1038/s41598-022-19443-7

Comparative accuracy of the four classifiers

Downloads

Published

16-09-2026

How to Cite

Musa, A., Saka, K. K., & Okunlola, I. J. (2026). Comparative Evaluation of Selected Machine Learning Classifier Algorithms for Ransomware Detection in Computer Networks. FUDMA Journal of Sciences, 10(18), 10-15. https://doi.org/10.33003/fjs-2026-1018-5854

Most read articles by the same author(s)