Machine Learning-Based Framework for Ransomware Detection and Classification

Authors

  • Gnanamani H
  • Akshata G. B
  • Ananya K
  • Anju K
  • Anusha

Keywords:

Cybersecurity, Deep learning, Feature extraction, Intrusion detection, Machine learning, Malware detection, Ransomware

Abstract

Ransomware has become one of the most dangerous cybersecurity threats, causing significant financial losses and compromising sensitive data across individuals and organizations. Traditional signature-based detection techniques are often ineffective against newly emerging and evolving ransomware variants. Consequently, Machine Learning (ML) has gained considerable attention as an effective approach for identifying ransomware based on behavioral patterns and system activities. This literature survey reviews recent research on ransomware detection using machine learning techniques. It analyzes various detection methods, datasets, feature extraction approaches, and machine learning algorithms such as Decision Trees, Random Forest, Support Vector Machines (SVM), K-Nearest Neighbors (KNN), Naïve Bayes, Artificial Neural Networks (ANN), and deep learning models. The survey compares the performance of these techniques using evaluation metrics including accuracy, precision, recall, and F1-score. Furthermore, this survey highlights the strengths and limitations of existing approaches, discusses the challenges involved in detecting zero-day ransomware attacks, handling imbalanced datasets, and achieving real-time detection. It also identifies current research gaps and explores future directions, including explainable artificial intelligence (XAI), federated learning, and lightweight machine learning models for edge and cloud environments.

References

M. Rele, J. Samuel, D. Patil, and U. Krishnan, “Exploring Ransomware Detection Based on Artificial Intelligence and Machine Learning,” Procedia Computer Science, vol. 252, pp. 548–556, Feb. 2025.

J. A. Herrera-Silva and M. Hernández-Álvarez, “Dynamic Feature Dataset for Ransomware Detection Using Machine Learning Algorithms,” Sensors, vol. 23, no. 3, p. 1053, Jan. 2023.

M. Hirano and R. Kobayashi, “Machine Learning-based Ransomware Detection Using Low-level Memory Access Patterns Obtained From Live-forensic Hypervisor,” arXiv (Cornell University), May 2022.

M. R. Ara, M. Siddula, and K. Roy, “Application of Explainable Machine Learning in Detecting and Classifying Ransomware Families Based on API Call Analysis,” arXiv (Cornell University), Jan. 2022.

S. I. Bae, G. Bin Lee, and E. G. Im, “Ransomware detection using machine learning algorithms,” Concurrency and Computation: Practice and Experience, vol. 32, no. 18, June 2019.

C.-Y. Yang and R. Sahita, “Towards a resilient machine learning classifier—A case study of ransomware detection,” 2020.

P. Azugo, H. Venter, and M. W. Nkongolo, “Ransomware Detection and Classification Using Random Forest: A Case Study with the UGRansome2024 Dataset,” arXiv (Cornell University), Apr. 2024.

Jamil Ispahany, MD Rafiqul Islam, MD Zahidul Islam, and M. Arif Khan, “Ransomware detection using machine learning: A review, research limitations and future directions,” IEEE Access, vol. 12, pp. 1–1, Jan. 2024.

Z. A. Khan, M. A. Mughal, M. U. Hashmi, R. Sarwar, and I. Haq, “Lightweight and Explainable Early Ransomware Detection Using Dynamic API‐Call Features and Ensemble Machine Learning,” Engineering Reports, vol. 8, no. 4, Apr. 2026.

A. Iqbal, M. Hussain, Q. Riaz, M. Khalid, R. Mumtaz, and K.-H. Jung, “Enhancing Ransomware Detection with Machine Learning Techniques and Effective API Integration,” Computers, Materials and Continua, vol. 85, no. 1, pp. 1693–1714, 2025.

Published

2026-09-05

How to Cite

Gnanamani H, Akshata G. B, Ananya K, Anju K, & Anusha. (2026). Machine Learning-Based Framework for Ransomware Detection and Classification. Journal of Security in Computer Networks and Distributed Systems, 1–10. Retrieved from https://matjournals.net/engineering/index.php/JoSCNDS/article/view/4070