Skip to content
Open access

Implementation of Ransomware Threat Detection Using Behavior-Based Detection Algorithm

Sep 2026 · International Journal of Innovative Science and Research Technology · pp. 3138 · 0 citations · 15 references

TL;DR

It is suggested that the behavioral identification engine be combined into Endpoint Identification and Response (EDR) platforms to promote intelligent threat containment, increase incident response, and reduce the danger of data loss.

Abstract

Ransomware threats continue to evade traditional signature-based security strategies, particularly when exploiting zero-day attacks, polymorphic methods, and code obfuscation. Rather than relying on static file analysis, the system continuously manages runtime process behavior by analyzing key indicators of ransomware operation, including file encryption rates, mass file renaming, entropy fluctuations, registry modifications, and network connections. This dynamic behavioral analysis enables the timely identification of malicious activities, consequently enhancing the system's capability to recognize ransomware threats in real time. The identification engine was implemented using React and TypeScript and uses a configurable, weighted rule-based scoring strategy to classify running processes as either malicious. During simulated assessments involving well-known ransomware families, including WannaCry, LockBit3, and Ryuk, the application efficiently differentiated malicious processes from legitimate ones, delivering a identification accuracy of 88.9% while maintaining a low false-positive rate. In addition, the proposed solution indicated real-time responsiveness, with an average event update latency of approximately 360 milliseconds. The experimental results show that the behavior-based identification methods generates more effective coverage against novel, polymorphic, and fileless ransomware threats than conventional signature-based identification approaches. Based on these results, it is suggested that the behavioral identification engine be combined into Endpoint Identification and Response (EDR) platforms to promote intelligent threat containment, increase incident response, and reduce the danger of data loss.

Read PDF

Similar papers

Conference Aug 2026

Proactive Ransomware Detection & Mitigation Using Machine Learning

The ransomware attack is one of the most prominent forms of cybersecurity risks, as it can cause the crucial information unavailable and cause significant harm to the functioning of critical services within various sectors. The conventional techniques of signature-based detections have been proven highly ineffective wh...

Suvarna P. Bhatsangave, Rajkumar Jain · 0 citations
Open access 2026

Real-Time Endpoint Ransomware Detection and Prevention via Strategic Deception Directories and Block-Level Entropy Analysis

A lightweight host-based ransomware detection and prevention prototype for Windows endpoints that combines three mechanisms: strategically placed deception directories (1000_Trap), localized Shannon-entropy analysis, and automated process termination using psutil is presented.

Kia-Yi Tong, Muhammad Hafiey Mughnie Bin Amran, Megat Muhammad Ridzuan et al. · 0 citations
Open access Aug 2026

Behavior-Based Ransomware Detection Through File System Change Analysis Using Random Forest in a Virtual Environment

Ransomware has become one of the most significant cybersecurity threats due to its ability to encrypt files and disrupt system availability. Conventional signature-based detection methods often struggle to identify newly emerging ransomware variants, making behavior-based approaches a promising alternative. This study...

Taufik Hidayat, Zenal Alamsyah, H. Hermanto · 0 citations
Open access Aug 2026

DYNAMIC RANSOMWARE DETECTION USING TIME-BASED API CALLING ANALYSIS

The findings show that ensemble learning techniques, especially XGBoost, are very successful in classifying multi-class malware and can be used in practical cybersecurity systems.

Juveriya Rasheed, Umar Farooq · 0 citations
Open access Sep 2026

BehaviorGuard: A Host-Based Behavioral Ransomware Detection and Automated Containment System Using Wazuh SIEM and Microsoft Sysmon

Ransomware remains one of the most disruptive cyber threats facing organizations globally. Modern families including LockBit 3.0, ALPHV/BlackCat, Akira, and Cl0p employ polymorphic code, fileless execution, and living-off-the-land (LOLBin) techniques that defeat traditional signature-based defenses. BehaviorGuard is an...

Mohammad Arafath Uz Zaman Khan, Md. Kamrul Hasan · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.