Automated Ransomware Detection Using Windows File System Activity Monitoring and a Novel Machine Learning Approach

preprint OA: closed
View at publisher

Abstract

Ransomware has become a significant cybersecurity threat, targeting users and organizations through the encryption of critical files and demanding ransom payments for their recovery. Traditional detection methods, relying heavily on static signatures, often fail to identify novel ransomware variants, necessitating more adaptive and behavior-based approaches. In this work, a hybrid detection system combining Isolation Forest for anomaly detection and XGBoost for classification is proposed, enabling real-time monitoring of file system activities to detect ransomware with high precision. This method leverages the unique behaviors of ransomware, such as abnormal file modifications and encryption, allowing it to identify threats before significant damage occurs. The results demonstrate the system's ability to detect a wide range of ransomware variants, even those previously unseen, while maintaining low false positive rates, making it suitable for deployment in both enterprise and smaller-scale environments. Additionally, the system's architecture ensures scalability and efficient performance, enabling its integration into diverse operational settings where real-time detection is critical.

My notes (saved in your browser only)

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2024) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00