Learning the Language of NVMe Streams for Ransomware Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Bringoltz, Barak, Halperin, Elisha, Feraru, Ran, Blaichman, Evgeny, Berman, Amit
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929702377095168
author Bringoltz, Barak
Halperin, Elisha
Feraru, Ran
Blaichman, Evgeny
Berman, Amit
author_facet Bringoltz, Barak
Halperin, Elisha
Feraru, Ran
Blaichman, Evgeny
Berman, Amit
contents We apply language modeling techniques to detect ransomware activity in NVMe command sequences. We design and train two types of transformer-based models: the Command-Level Transformer (CLT) performs in-context token classification to determine whether individual commands are initiated by ransomware, and the Patch-Level Transformer (PLT) predicts the volume of data accessed by ransomware within a patch of commands. We present both model designs and the corresponding tokenization and embedding schemes and show that they improve over state-of-the-art tabular methods by up to 24% in missed-detection rate, 66% in data loss prevention, and 84% in identifying data accessed by ransomware.
format Preprint
id arxiv_https___arxiv_org_abs_2502_05011
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Learning the Language of NVMe Streams for Ransomware Detection
Bringoltz, Barak
Halperin, Elisha
Feraru, Ran
Blaichman, Evgeny
Berman, Amit
Machine Learning
Cryptography and Security
We apply language modeling techniques to detect ransomware activity in NVMe command sequences. We design and train two types of transformer-based models: the Command-Level Transformer (CLT) performs in-context token classification to determine whether individual commands are initiated by ransomware, and the Patch-Level Transformer (PLT) predicts the volume of data accessed by ransomware within a patch of commands. We present both model designs and the corresponding tokenization and embedding schemes and show that they improve over state-of-the-art tabular methods by up to 24% in missed-detection rate, 66% in data loss prevention, and 84% in identifying data accessed by ransomware.
title Learning the Language of NVMe Streams for Ransomware Detection
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2502.05011