Return
RansomFisher: Behavior-based ransomware detection without decoys
I
I
S
DOI:10.1016/j.icte.2026.06.002.png)
Abstract
En 中文
Ransomware remains a significant cyber threat for legacy and recent systems. This study revisits behavior-based detection and introduces RansomFisher, a novel decoyless ransomware detection system that monitors file access patterns. RansomFisher defines four features to characterize process behaviors and distinguish ransomware from benign applications: write ratio, bulk ratio, write count ratio, and continuous write count. RansomFisher was evaluated on eight recent ransomware samples and 96 benign processes, including four applications that exhibit ransomware-like behavior and 92 system services. RansomFisher detected ransomware with an average file loss of only 15.3 files before detection and a negligible average overhead of 3.7%.
Keywords:
Ransomware
Decoyless
Detection
Kernel hooking
File access patterns
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.
Journal
IF:
4.2
Papers:
960
Citations:
2.5K
