Learning the Language of NVMe Streams for Ransomware Detection
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866929702377095168 |
|---|---|
| author | Bringoltz, Barak Halperin, Elisha Feraru, Ran Blaichman, Evgeny Berman, Amit |
| author_facet | Bringoltz, Barak Halperin, Elisha Feraru, Ran Blaichman, Evgeny Berman, Amit |
| contents | We apply language modeling techniques to detect ransomware activity in NVMe command sequences. We design and train two types of transformer-based models: the Command-Level Transformer (CLT) performs in-context token classification to determine whether individual commands are initiated by ransomware, and the Patch-Level Transformer (PLT) predicts the volume of data accessed by ransomware within a patch of commands. We present both model designs and the corresponding tokenization and embedding schemes and show that they improve over state-of-the-art tabular methods by up to 24% in missed-detection rate, 66% in data loss prevention, and 84% in identifying data accessed by ransomware. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2502_05011 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Learning the Language of NVMe Streams for Ransomware Detection Bringoltz, Barak Halperin, Elisha Feraru, Ran Blaichman, Evgeny Berman, Amit Machine Learning Cryptography and Security We apply language modeling techniques to detect ransomware activity in NVMe command sequences. We design and train two types of transformer-based models: the Command-Level Transformer (CLT) performs in-context token classification to determine whether individual commands are initiated by ransomware, and the Patch-Level Transformer (PLT) predicts the volume of data accessed by ransomware within a patch of commands. We present both model designs and the corresponding tokenization and embedding schemes and show that they improve over state-of-the-art tabular methods by up to 24% in missed-detection rate, 66% in data loss prevention, and 84% in identifying data accessed by ransomware. |
| title | Learning the Language of NVMe Streams for Ransomware Detection |
| topic | Machine Learning Cryptography and Security |
| url | https://arxiv.org/abs/2502.05011 |