Sep 2026· International Journal of Innovative Science and Research Technology· pp. 3138· 0 citations· 15 references
TL;DR
It is suggested that the behavioral identification engine be combined into Endpoint Identification and Response (EDR) platforms to promote intelligent threat containment, increase incident response, and reduce the danger of data loss.
Abstract
Ransomware threats continue to evade traditional signature-based security strategies, particularly when
exploiting zero-day attacks, polymorphic methods, and code obfuscation. Rather than relying on static file analysis, the
system continuously manages runtime process behavior by analyzing key indicators of ransomware operation, including file
encryption rates, mass file renaming, entropy fluctuations, registry modifications, and network connections. This dynamic
behavioral analysis enables the timely identification of malicious activities, consequently enhancing the system's capability
to recognize ransomware threats in real time. The identification engine was implemented using React and TypeScript and
uses a configurable, weighted rule-based scoring strategy to classify running processes as either malicious. During simulated
assessments involving well-known ransomware families, including WannaCry, LockBit3, and Ryuk, the application
efficiently differentiated malicious processes from legitimate ones, delivering a identification accuracy of 88.9% while
maintaining a low false-positive rate. In addition, the proposed solution indicated real-time responsiveness, with an average
event update latency of approximately 360 milliseconds. The experimental results show that the behavior-based
identification methods generates more effective coverage against novel, polymorphic, and fileless ransomware threats than
conventional signature-based identification approaches. Based on these results, it is suggested that the behavioral
identification engine be combined into Endpoint Identification and Response (EDR) platforms to promote intelligent threat
containment, increase incident response, and reduce the danger of data loss.
The ransomware attack is one of the most prominent forms of cybersecurity risks, as it can cause the crucial information unavailable and cause significant harm to the functioning of critical services within various sectors. The conventional techniques of signature-based detections have been proven highly ineffective wh...
Suvarna P. Bhatsangave, Rajkumar Jain· International Conference on...· 0 citations
A lightweight host-based ransomware detection and prevention prototype for Windows endpoints that combines three mechanisms: strategically placed deception directories (1000_Trap), localized Shannon-entropy analysis, and automated process termination using psutil is presented.
Kia-Yi Tong, Muhammad Hafiey Mughnie Bin Amran, Megat Muhammad Ridzuan et al.· International journal of re...· 0 citations
Ransomware has become one of the most significant cybersecurity threats due to its ability to encrypt files and disrupt system availability. Conventional signature-based detection methods often struggle to identify newly emerging ransomware variants, making behavior-based approaches a promising alternative. This study...
Taufik Hidayat, Zenal Alamsyah, H. Hermanto· bit-Tech· 0 citations
This proposed framework aims to fortify data protection and ensure user privacy in essential areas like healthcare, financial services, and e-governance, thereby fostering increased trust.
Sai Kiranmai Dornala, S. P.· International Journal of Int...· 0 citations
The findings show that ensemble learning techniques, especially XGBoost, are very successful in classifying multi-class malware and can be used in practical cybersecurity systems.
Juveriya Rasheed, Umar Farooq· International Journal of Eng...· 0 citations
Ransomware remains one of the most disruptive cyber threats facing organizations globally. Modern families including LockBit 3.0, ALPHV/BlackCat, Akira, and Cl0p employ polymorphic code, fileless execution, and living-off-the-land (LOLBin) techniques that defeat traditional signature-based defenses. BehaviorGuard is an...
Mohammad Arafath Uz Zaman Khan, Md. Kamrul Hasan· Journal of Artificial Intell...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.