International Journal of Innovative Research in Computer and Communication Engineering

ISSN Approved Journal | Impact factor: 8.771 | ESTD: 2013 | Follows UGC CARE Journal Norms and Guidelines

| Monthly, Peer-Reviewed, Refereed, Scholarly, Multidisciplinary and Open Access Journal | High Impact Factor 8.771 (Calculated by Google Scholar and Semantic Scholar | AI-Powered Research Tool | Indexing in all Major Database & Metadata, Citation Generator | Digital Object Identifier (DOI) |


TITLE Ransomware Early Detection System
ABSTRACT Ransomware has become one of the most destructive forms of cyberattacks, causing severe financial losses, data breaches, and disruption of critical services across organizations worldwide. Traditional signature-based antivirus solutions often fail to detect newly emerging and zero-day ransomware variants due to their dependence on previously known attack signatures. To overcome these limitations, this paper proposes the Ransomware Early Detection System (REDS), an intelligent machine learning-based framework designed to identify ransomware activities at an early stage before extensive file encryption occurs. The proposed system continuously monitors system behavior by analyzing file operations, process execution patterns, entropy values, CPU utilization, memory consumption, and other behavioral characteristics. The collected information is preprocessed and transformed into meaningful feature vectors that are used to train multiple machine learning classifiers, namely Random Forest (RF), Extreme Gradient Boosting (XGBoost), and Support Vector Machine (SVM). The trained models classify system activities as either benign or ransomware in real time. Whenever suspicious behavior is identified, the system immediately generates security alerts and displays the detection results through an interactive Streamlit dashboard. Experimental evaluation demonstrates that the proposed framework provides excellent ransomware detection performance. Among the evaluated classifiers, Random Forest achieved an accuracy of 99.62%, precision of 99.62%, recall of 99.72%, and F1-score of 99.67%, outperforming the remaining models. The proposed REDS framework successfully combines real-time behavioral monitoring with machine learning to provide accurate, efficient, and proactive ransomware detection while minimizing false alarms. The system offers an effective solution for protecting organizational data and strengthening cybersecurity against evolving ransomware threats.
AUTHOR DHARAVATH ANJALI, DR. M. DHANALAKSHMI Post Graduate Student, Department of Computer Science and Engineering, Jawaharlal Nehru Technological University, Hyderabad, India Professor, Department of Computer Science and Engineering, Jawaharlal Nehru Technological University, Hyderabad, India
VOLUME 187
DOI DOI: 10.15680/IJIRCCE.2026.1408011
PDF pdf/11_Ransomware Early Detection System.pdf
KEYWORDS
References [1] S. Saleh, "A Survey of Ransomware Detection Methods," 2025.
[2] J. Ispahany, "Ransomware Detection Using Machine Learning: A Review, Research Limitations and Future Directions," 2024.
[3] D. Smith, "Machine Learning Algorithms and Frameworks in Ransomware Detection," 2022.
[4] A. Almashhadani, M. Kaiiali, S. Sezer, and P. O'Kane, "A Multi-Classifier Network-Based Crypto Ransomware Detection System: A Case Study of Locky Ransomware," IEEE Access, vol. 7, pp. 47053–47067, 2019.
[5] N. Sgandurra, L. Muñoz-González, R. Mohsen, and E. C. Lupu, "Automated Dynamic Analysis of Ransomware: Benefits, Limitations and Use for Detection," arXiv preprint arXiv:1609.03020, 2016
[6] S. Scaife, H. Carter, P. Traynor, and K. R. B. Butler, "Cryptolock (and Drop It): Stopping Ransomware Attacks on User Data," Proceedings of the IEEE International Conference on Distributed Computing Systems (ICDCS), pp. 303–312, 2016.
[7] K. Cabaj and W. Mazurczyk, "Using Software-Defined Networking for Ransomware Mitigation: The Case of CryptoWall," IEEE Network, vol. 30, no. 6, pp. 14–20, 2016.
[8] X.. Ding and W. Feng, ‘‘Ananomaly detection method based on feature mining for wireless sensornetworks,’’ Int. J. Sens. Netw., vol. 36, no. 3,pp. 167–173, 2021
[9] N.Scaife, H. Carter, P. Traynor, and K. R. B. Butler, ‘‘CryptoLock (and drop It): Stopping ransomware attacks on user data,’’ in Proc. IEEE 36th Int. Conf. Distrib. Comput. Syst. (ICDCS), Jun. 2016, pp. 303–312
[10] K.Wang, M. Tong, J. Pang, J. Wang, and W. Han, ‘‘XRAD: Ransomware address detection method based on Bitcoin transaction relationships,’’ACM Trans. Web, vol. 18, no. 4, pp. 1–33, Oct. 2024.
[11] M. M. Ahmadian and H. R. Shahriari, ‘‘2entFOX: A framework for high survivable ransomwares detection,’’ in Proc. 13th Int. Iranian Soc. Cryptol. Conf. Inf. Secur. Cryptol. (ISCISC), Sep. 2016, pp. 79–84.
[12] J.Song, R. Paul, J. Yun, H. Kim, and Y. Choi, ‘‘CNN-based anomaly detection for packet payloads of industrial control system,’’ Int. J. Sens. Netw., vol. 36, no. 1, pp. 36–49, 2021.
Copyright © IJIRCCE 2020.All right reserved