1
Return

RansomFisher: Behavior-based ransomware detection without decoys

delete2026-06-11
delete0
delete
OA
AI
I
InHoe Ku
I
Iljun Jeong
S
Seunghun Han *
DOI:10.1016/j.icte.2026.06.002delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Ransomware remains a significant cyber threat for legacy and recent systems. This study revisits behavior-based detection and introduces RansomFisher, a novel decoyless ransomware detection system that monitors file access patterns. RansomFisher defines four features to characterize process behaviors and distinguish ransomware from benign applications: write ratio, bulk ratio, write count ratio, and continuous write count. RansomFisher was evaluated on eight recent ransomware samples and 96 benign processes, including four applications that exhibit ransomware-like behavior and 92 system services. RansomFisher detected ransomware with an average file loss of only 15.3 files before detection and a negligible average overhead of 3.7%.
Keywords:
Ransomware
Decoyless
Detection
Kernel hooking
File access patterns
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

ICT Express cover
ICT Express
IF:
4.2
Papers:
960
Citations:
2.5K

Organization

S
Soongsil University
Scholars:
3.3K
Papers: 3.4K
Citations: 3.2K
Cited Papers

Cited Papers

Citing Papers

Citing Papers