Ransomware Detection on Windows Systems Using File System Activity Monitoring and a Hybrid XGBoost-Isolation Forest Approach

preprint OA: closed CC-BY-NC-SA-4.0
📄 Open PDF View at publisher

Abstract

Ransomware has rapidly evolved into one of the most significant cybersecurity threats, with the ability to encrypt critical data and demand ransoms, causing substantial financial and operational damage to organizations worldwide. The novel approach presented in this paper addresses the limitations of traditional signature-based detection methods through a hybrid model that combines supervised and unsupervised machine learning techniques, offering enhanced accuracy in identifying both known and previously unseen ransomware variants. Through real-time monitoring of file system activities on Windows environments, the model utilizes XGBoost for classifying known ransomware behaviors while leveraging Isolation Forest to detect anomalous activities indicative of novel threats. The experimental results demonstrate that the hybrid model achieves high detection accuracy, reduces false positives, and scales efficiently in dynamic environments with varying system loads, making it a viable solution for proactive ransomware mitigation. Moreover, the ability to generalize across zero-day ransomware variants provides a robust defense mechanism against evolving cyber threats. Overall, the proposed hybrid model offers a significant advancement in the field of ransomware detection, bridging the gap between traditional and contemporary detection strategies.

My notes (saved in your browser only)

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2024) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00
unpaywall
last seen: 2026-05-23T02:00:01.238055+00:00
License: CC-BY-NC-SA-4.0