Authors :
Kazeem O. N.; Abdul Kareem Olaitan Mummen; Shamsudeen Sani Saleh
Volume/Issue :
Volume 11 - 2026, Issue 8 - August
Google Scholar :
https://tinyurl.com/yw8bmp2e
DOI :
https://doi.org/10.38124/ijisrt/26aug299
Note : A published paper may take 4-5
working days from the publication date to appear in PlumX Metrics, Semantic Scholar, and
ResearchGate.
Abstract :
Ransomware threats continue to evade traditional signature-based security strategies, particularly when
exploiting zero-day attacks, polymorphic methods, and code obfuscation. Rather than relying on static file analysis, the
system continuously manages runtime process behavior by analyzing key indicators of ransomware operation, including file
encryption rates, mass file renaming, entropy fluctuations, registry modifications, and network connections. This dynamic
behavioral analysis enables the timely identification of malicious activities, consequently enhancing the system's capability
to recognize ransomware threats in real time. The identification engine was implemented using React and TypeScript and
uses a configurable, weighted rule-based scoring strategy to classify running processes as either malicious. During simulated
assessments involving well-known ransomware families, including WannaCry, LockBit3, and Ryuk, the application
efficiently differentiated malicious processes from legitimate ones, delivering a identification accuracy of 88.9% while
maintaining a low false-positive rate. In addition, the proposed solution indicated real-time responsiveness, with an average
event update latency of approximately 360 milliseconds. The experimental results show that the behavior-based
identification methods generates more effective coverage against novel, polymorphic, and fileless ransomware threats than
conventional signature-based identification approaches. Based on these results, it is suggested that the behavioral
identification engine be combined into Endpoint Identification and Response (EDR) platforms to promote intelligent threat
containment, increase incident response, and reduce the danger of data loss.
Keywords :
Ransomware, Behavior-Based Detection, Cybersecurity, Malware Detection, Behavioral Analysis, Threat Scoring, Real-Time Monitoring
References :
- Alqahtani, A., & Sheldon, F. T. (2022). A survey of crypto ransomware attack detection methodologies: An evolving outlook. Sensors, 22(5), 1837. https://doi.org/10.3390/s22051837.
- Alraizza, A., & Algarni, A. (2023). Ransomware detection using machine learning: A survey. Big Data and Cognitive Computing, 7(3), 143. https://doi.org/10.3390/bdcc7030143.
- Berrueta, E., Morato, D., Magaña, E., & Izal, M. (2022). Crypto-ransomware detection using machine learning models in file-sharing network scenarios with encrypted traffic. Expert Systems with Applications, 209, 118299. https://doi.org/10.1016/j.eswa.2022.118299.
- Chew, C. J. W., Kumar, V., Patros, P., & Malik, R. (2024). Real-time system call-based ransomware detection. International Journal of Information Security, 23(3), 1839–1858. https://doi.org/10.1007/s10207-024-00819-x.
- Hirano, M., & Kobayashi, R. (2022). Machine learning-based ransomware detection using low-level memory access patterns obtained from live-forensic hypervisor. arXiv. https://doi.org/10.48550/arXiv.2205.13765.
- Masum, M., Faruk, M. J. H., Adnan, M. I., et al. (2022). Ransomware classification and detection with machine learning algorithms. In 2022 IEEE 12th Annual Computing and Communication Workshop and Conference (CCWC) (pp. 316–322). IEEE. https://doi.org/10.1109/CCWC54503.2022.9720869.
- Rehman, M. U., Akbar, R., Omar, M., & Gilal, A. R. (2024). A systematic literature review of ransomware detection methods and tools for mitigating potential attacks. In Communications in Computer and Information Science (pp. 80–95). Springer. https://doi.org/10.1007/978-981-99-9589-9_7.
- Urooj, U., Al-Rimy, B. A. S., Zainal, A., Ghaleb, F. A., & Rassam, M. A. (2022). Ransomware detection using the dynamic analysis and machine learning: A survey and research directions. Applied Sciences, 12(1), 172. https://doi.org/10.3390/app12010172.
- Guerra-Manzanares, A., Luckner, M., & Bahsi, H. (2022). Android malware concept drift using system calls: Detection, characterization and challenges. Expert Systems with Applications, 206, 117200. https://doi.org/10.1016/j.eswa.2022.117200
- Abbasi, M. S., Al-Sahaf, H., Mansoori, M., & Welch, I. (2022). Behavior-based ransomware classification: A particle swarm optimization wrapper-based approach for feature selection. Applied Soft Computing, 121, 108744. https://doi.org/10.1016/j.asoc.2022.108744.
- Chew, C. J. W., Kumar, V., Patros, P., & Malik, R. (2024). Real-time system call-based ransomware detection. International Journal of Information Security, 23(3), 1839–1858. https://doi.org/10.1007/s10207-024-00819-x.
- Madani, H., Ouerdi, N., Boumesaoud, A., & Azizi, A. (2022). Classification of ransomware using different types of neural networks. Scientific Reports, 12, 4770. https://doi.org/10.1038/s41598-022-08504-6.
- Zahoora, U., Khan, A., Rajarajan, M., Khan, S. H., Asam, M., & Jamal, T. (2022). Ransomware detection using deep learning based unsupervised feature extraction and a cost sensitive Pareto Ensemble classifier. Scientific Reports, 12, 15647. https://doi.org/10.1038/s41598-022-19443-7.
- De Gaspari, F., Hitaj, D., Pagnotta, G., De Carli, L., & Mancini, L. V. (2022). Evading behavioral classifiers: A comprehensive analysis on evading ransomware detection techniques. Neural Computing and Applications, 34, 12077–12096. https://doi.org/10.1007/s00521-022-07096-6.
- Huertas Celdrán, A., Sánchez Sánchez, P. M., Azorín Castillo, M., Bovet, G., Martínez Pérez, G., & Stiller, B. (2023). Intelligent and behavioral-based detection of malware in IoT spectrum sensors. International Journal of Information Security, 22, 541–561. https://doi.org/10.1007/s10207-022-00602-w.
- Jawad, S., & Ahmed, H. M. (2024). Machine learning approaches to ransomware detection: A comprehensive review. International Journal of Safety and Security Engineering, 14(6), 1963–1973. https://doi.org/10.18280/ijsse.140630.
- Hirano, M., & Kobayashi, R. (2022). Machine learning-based ransomware detection using low-level memory access patterns obtained from live-forensic hypervisor. In 2022 IEEE International Conference on Cyber Security and Resilience (CSR) (pp. 323–330). IEEE. https://doi.org/10.1109/CSR54599.2022.9850340.
18. Masum, M., Faruk, M. J. H., Shahriar, H., Qian, K., Lo, D., & Adnan, M. I. (2022). Ransomware classification and detection with machine learning algorithms. In 2022 IEEE 12th Annual Computing and Communication Workshop and Conference (CCWC) (pp. 316–322). IEEE. https://doi.org/10.1109/CCWC54503.2022.9720869.
Ransomware threats continue to evade traditional signature-based security strategies, particularly when
exploiting zero-day attacks, polymorphic methods, and code obfuscation. Rather than relying on static file analysis, the
system continuously manages runtime process behavior by analyzing key indicators of ransomware operation, including file
encryption rates, mass file renaming, entropy fluctuations, registry modifications, and network connections. This dynamic
behavioral analysis enables the timely identification of malicious activities, consequently enhancing the system's capability
to recognize ransomware threats in real time. The identification engine was implemented using React and TypeScript and
uses a configurable, weighted rule-based scoring strategy to classify running processes as either malicious. During simulated
assessments involving well-known ransomware families, including WannaCry, LockBit3, and Ryuk, the application
efficiently differentiated malicious processes from legitimate ones, delivering a identification accuracy of 88.9% while
maintaining a low false-positive rate. In addition, the proposed solution indicated real-time responsiveness, with an average
event update latency of approximately 360 milliseconds. The experimental results show that the behavior-based
identification methods generates more effective coverage against novel, polymorphic, and fileless ransomware threats than
conventional signature-based identification approaches. Based on these results, it is suggested that the behavioral
identification engine be combined into Endpoint Identification and Response (EDR) platforms to promote intelligent threat
containment, increase incident response, and reduce the danger of data loss.
Keywords :
Ransomware, Behavior-Based Detection, Cybersecurity, Malware Detection, Behavioral Analysis, Threat Scoring, Real-Time Monitoring