⚠ Official Notice: www.ijisrt.com is the official website of the International Journal of Innovative Science and Research Technology (IJISRT) Journal for research paper submission and publication. Please beware of fake or duplicate websites using the IJISRT name.



Implementation of Ransomware Threat Detection Using Behavior-Based Detection Algorithm


Authors : Kazeem O. N.; Abdul Kareem Olaitan Mummen; Shamsudeen Sani Saleh

Volume/Issue : Volume 11 - 2026, Issue 8 - August


Google Scholar : https://tinyurl.com/yw8bmp2e

DOI : https://doi.org/10.38124/ijisrt/26aug299

Note : A published paper may take 4-5 working days from the publication date to appear in PlumX Metrics, Semantic Scholar, and ResearchGate.


Abstract : Ransomware threats continue to evade traditional signature-based security strategies, particularly when exploiting zero-day attacks, polymorphic methods, and code obfuscation. Rather than relying on static file analysis, the system continuously manages runtime process behavior by analyzing key indicators of ransomware operation, including file encryption rates, mass file renaming, entropy fluctuations, registry modifications, and network connections. This dynamic behavioral analysis enables the timely identification of malicious activities, consequently enhancing the system's capability to recognize ransomware threats in real time. The identification engine was implemented using React and TypeScript and uses a configurable, weighted rule-based scoring strategy to classify running processes as either malicious. During simulated assessments involving well-known ransomware families, including WannaCry, LockBit3, and Ryuk, the application efficiently differentiated malicious processes from legitimate ones, delivering a identification accuracy of 88.9% while maintaining a low false-positive rate. In addition, the proposed solution indicated real-time responsiveness, with an average event update latency of approximately 360 milliseconds. The experimental results show that the behavior-based identification methods generates more effective coverage against novel, polymorphic, and fileless ransomware threats than conventional signature-based identification approaches. Based on these results, it is suggested that the behavioral identification engine be combined into Endpoint Identification and Response (EDR) platforms to promote intelligent threat containment, increase incident response, and reduce the danger of data loss.

Keywords : Ransomware, Behavior-Based Detection, Cybersecurity, Malware Detection, Behavioral Analysis, Threat Scoring, Real-Time Monitoring

References :

  1. Alqahtani, A., & Sheldon, F. T. (2022). A survey of crypto ransomware attack detection methodologies: An evolving outlook. Sensors, 22(5), 1837. https://doi.org/10.3390/s22051837.
  2. Alraizza, A., & Algarni, A. (2023). Ransomware detection using machine learning: A survey. Big Data and Cognitive Computing, 7(3), 143. https://doi.org/10.3390/bdcc7030143.
  3. Berrueta, E., Morato, D., Magaña, E., & Izal, M. (2022). Crypto-ransomware detection using machine learning models in file-sharing network scenarios with encrypted traffic. Expert Systems with Applications, 209, 118299. https://doi.org/10.1016/j.eswa.2022.118299.
  4. Chew, C. J. W., Kumar, V., Patros, P., & Malik, R. (2024). Real-time system call-based ransomware detection. International Journal of Information Security, 23(3), 1839–1858. https://doi.org/10.1007/s10207-024-00819-x.
  5. Hirano, M., & Kobayashi, R. (2022). Machine learning-based ransomware detection using low-level memory access patterns obtained from live-forensic hypervisor. arXiv. https://doi.org/10.48550/arXiv.2205.13765.
  6. Masum, M., Faruk, M. J. H., Adnan, M. I., et al. (2022). Ransomware classification and detection with machine learning algorithms. In 2022 IEEE 12th Annual Computing and Communication Workshop and Conference (CCWC) (pp. 316–322). IEEE. https://doi.org/10.1109/CCWC54503.2022.9720869.
  7. Rehman, M. U., Akbar, R., Omar, M., & Gilal, A. R. (2024). A systematic literature review of ransomware detection methods and tools for mitigating potential attacks. In Communications in Computer and Information Science (pp. 80–95). Springer. https://doi.org/10.1007/978-981-99-9589-9_7.
  8. Urooj, U., Al-Rimy, B. A. S., Zainal, A., Ghaleb, F. A., & Rassam, M. A. (2022). Ransomware detection using the dynamic analysis and machine learning: A survey and research directions. Applied Sciences, 12(1), 172. https://doi.org/10.3390/app12010172.
  9. Guerra-Manzanares, A., Luckner, M., & Bahsi, H. (2022). Android malware concept drift using system calls: Detection, characterization and challenges. Expert Systems with Applications, 206, 117200. https://doi.org/10.1016/j.eswa.2022.117200
  10. Abbasi, M. S., Al-Sahaf, H., Mansoori, M., & Welch, I. (2022). Behavior-based ransomware classification: A particle swarm optimization wrapper-based approach for feature selection. Applied Soft Computing, 121, 108744. https://doi.org/10.1016/j.asoc.2022.108744.
  11. Chew, C. J. W., Kumar, V., Patros, P., & Malik, R. (2024). Real-time system call-based ransomware detection. International Journal of Information Security, 23(3), 1839–1858. https://doi.org/10.1007/s10207-024-00819-x.
  12. Madani, H., Ouerdi, N., Boumesaoud, A., & Azizi, A. (2022). Classification of ransomware using different types of neural networks. Scientific Reports, 12, 4770. https://doi.org/10.1038/s41598-022-08504-6.
  13. Zahoora, U., Khan, A., Rajarajan, M., Khan, S. H., Asam, M., & Jamal, T. (2022). Ransomware detection using deep learning based unsupervised feature extraction and a cost sensitive Pareto Ensemble classifier. Scientific Reports, 12, 15647. https://doi.org/10.1038/s41598-022-19443-7.
  14. De Gaspari, F., Hitaj, D., Pagnotta, G., De Carli, L., & Mancini, L. V. (2022). Evading behavioral classifiers: A comprehensive analysis on evading ransomware detection techniques. Neural Computing and Applications, 34, 12077–12096. https://doi.org/10.1007/s00521-022-07096-6.
  15. Huertas Celdrán, A., Sánchez Sánchez, P. M., Azorín Castillo, M., Bovet, G., Martínez Pérez, G., & Stiller, B. (2023). Intelligent and behavioral-based detection of malware in IoT spectrum sensors. International Journal of Information Security, 22, 541–561. https://doi.org/10.1007/s10207-022-00602-w.
  16. Jawad, S., & Ahmed, H. M. (2024). Machine learning approaches to ransomware detection: A comprehensive review. International Journal of Safety and Security Engineering, 14(6), 1963–1973. https://doi.org/10.18280/ijsse.140630.
  17. Hirano, M., & Kobayashi, R. (2022). Machine learning-based ransomware detection using low-level memory access patterns obtained from live-forensic hypervisor. In 2022 IEEE International Conference on Cyber Security and Resilience (CSR) (pp. 323–330). IEEE. https://doi.org/10.1109/CSR54599.2022.9850340.

18. Masum, M., Faruk, M. J. H., Shahriar, H., Qian, K., Lo, D., & Adnan, M. I. (2022). Ransomware classification and detection with machine learning algorithms. In 2022 IEEE 12th Annual Computing and Communication Workshop and Conference (CCWC) (pp. 316–322). IEEE. https://doi.org/10.1109/CCWC54503.2022.9720869.

Ransomware threats continue to evade traditional signature-based security strategies, particularly when exploiting zero-day attacks, polymorphic methods, and code obfuscation. Rather than relying on static file analysis, the system continuously manages runtime process behavior by analyzing key indicators of ransomware operation, including file encryption rates, mass file renaming, entropy fluctuations, registry modifications, and network connections. This dynamic behavioral analysis enables the timely identification of malicious activities, consequently enhancing the system's capability to recognize ransomware threats in real time. The identification engine was implemented using React and TypeScript and uses a configurable, weighted rule-based scoring strategy to classify running processes as either malicious. During simulated assessments involving well-known ransomware families, including WannaCry, LockBit3, and Ryuk, the application efficiently differentiated malicious processes from legitimate ones, delivering a identification accuracy of 88.9% while maintaining a low false-positive rate. In addition, the proposed solution indicated real-time responsiveness, with an average event update latency of approximately 360 milliseconds. The experimental results show that the behavior-based identification methods generates more effective coverage against novel, polymorphic, and fileless ransomware threats than conventional signature-based identification approaches. Based on these results, it is suggested that the behavioral identification engine be combined into Endpoint Identification and Response (EDR) platforms to promote intelligent threat containment, increase incident response, and reduce the danger of data loss.

Keywords : Ransomware, Behavior-Based Detection, Cybersecurity, Malware Detection, Behavioral Analysis, Threat Scoring, Real-Time Monitoring

Paper Submission Last Date
30 - September - 2026

SUBMIT YOUR PAPER CALL FOR PAPERS
Video Explanation for Published paper

Never miss an update from Papermashup

Get notified about the latest tutorials and downloads.

Subscribe by Email

Get alerts directly into your inbox after each post and stay updated.
Subscribe
OR

Subscribe by RSS

Add our RSS to your feedreader to get regular updates from us.
Subscribe