Network Traffic-Based Ransomware Detection Using Anomaly Detection Algorithms: A Comprehensive Systematic Review
DOI:
https://doi.org/10.56714/bjrs.52.1.11Keywords:
Ransomware Detection, Anomaly Detection, Cybersecurity, network traffic analysis, Hybrid Algorithms, proactive defenseAbstract
The present study offers an exhaustive systematic review of various ransomware detection techniques, with a specific focus on network traffic analysis and anomaly detection algorithms. In accordance with the PRISMA protocol, this study analyzes fifteen research papers published between 2021 and 2025. The research papers are collected from prominent scientific database sources, including IEEE Xplore, Scopus, ScienceDirect, and Google Scholar. The corpus of research articles can be broadly classified into four main categories of ransomware detection techniques: supervised machine learning approaches, unsupervised anomaly detection techniques, deep learning approaches, and hybrid approaches for ransomware detection.A comparative analysis of the research articles reveals that the deep learning approaches have been able to achieve higher detection accuracies of more than 99%, while the unsupervised anomaly detection approaches have been able to demonstrate higher adaptability in the detection of ransomware. However, the area of ransomware detection has several research gaps that need to be addressed: the lack of standardized data sets for the experiments, the processing of encrypted network traffic, and the occurrence of false positives in the detection process. The research demonstrates the need to incorporate hybrid and behavioral detection techniques to strengthen the robustness of cybersecurity systems against new ransomware attacks
Downloads
References
[1] S. Morgan, “Global ransomware damage costs predicted to hit $57B annually in 2025,” Cybersecurity Ventures, Sausalito, CA, USA, 2025.
[2] Sophos Ltd., “The State of Ransomware 2025: Findings from an independent survey of 3,400 IT and cybersecurity leaders across 17 countries,” Abingdon, U.K., 2025.
[3] NCC Group and Fox-IT, "Cyber Threat Intelligence Report: Review of Q2 2025," NCC Group, U.K., Tech. Rep., 2025.
[4] Brandefense, "Ransomware Trends Report Q2 2025 with Comparison Q1 2025," Brandefense, Tech. Rep., 2025.
[5] J. Mongay Batalla, “Featured Papers on Network Security and Privacy,” Feb. 01, 2024, Multidisciplinary Digital Publishing Institute (MDPI). DOI: 10.3390/jsan13010011. DOI: https://doi.org/10.3390/jsan13010011
[6] “Network Security Concepts, Dangers, and Defense Best Practical,” Computer Engineering and Intelligent Systems, Mar. 2023, DOI: 10.7176/ceis/14-2-03. DOI: https://doi.org/10.7176/CEIS/14-2-03
[7] A. Alexei and A. Alexei, “THE DIFFERENCE BETWEEN CYBER SECURITY VS INFORMATION SECURITY,” Journal of Engineering Science, vol. 29, no. 4, pp. 72–83, Jan. 2023, DOI: 10.52326/jes.utm.2022.29(4).08. DOI: https://doi.org/10.52326/jes.utm.2022.29(4).08
[8] F. Ojo, B. Ojo, F. Fidelis, and S. Lawrence, “AN OVERVIEW OF NETWORK SECURITY AND MANAGEMENT,” 2024. [Online]. Available: https://www.researchgate.net/publication/381480940
[9] P. Rajesh Kanna and P. Santhi, “Exploring the landscape of network security: a comparative analysis of attack detection strategies,” J. Ambient Intell. Humaniz. Comput., vol. 15, no. 8, pp. 3211–3228, Aug. 2024, DOI: 10.1007/s12652-024-04794-y. DOI: https://doi.org/10.1007/s12652-024-04794-y
[10] J. Ferdous, R. Islam, A. Mahboubi, and M. Z. Islam, “A Review of State-of-the-Art Malware Attack Trends and Defense Mechanisms,” IEEE Access, vol. 11, pp. 121118–121141, 2023, DOI: 10.1109/ACCESS.2023.3328351. DOI: https://doi.org/10.1109/ACCESS.2023.3328351
[11] R. Hasan et al., “Enhancing malware detection with feature selection and scaling techniques using machine learning models,” Sci. Rep., vol. 15, no. 1, Dec. 2025, DOI: 10.1038/s41598-025-93447-x. DOI: https://doi.org/10.1038/s41598-025-93447-x
[12] S. Berrios, D. Leiva, B. Olivares, H. Allende-Cid, and P. Hermosilla, “Systematic review: Malware detection and classification in cybersecurity,” Applied Sciences, vol. 15, no. 14, p. 7747, 2025. DOI: https://doi.org/10.3390/app15147747
[13] S. F. Ali, M. R. Abdulrazzaq, and M. T. Gaata, “Learning Techniques-Based Malware Detection: A Comprehensive Review,” Jan. 10, 2025, Mesopotamian Academic Press. DOI: 10.58496/MJCS/2025/018. DOI: https://doi.org/10.58496/MJCS/2025/018
[14] M. Maghanaki, S. Keramati, F. F. Chen, and M. Shahin, “Generation of a Multi-Class IoT Malware Dataset for Cybersecurity,” Electronics (Switzerland), vol. 14, no. 21, Nov. 2025, DOI: 10.3390/electronics14214196. DOI: https://doi.org/10.3390/electronics14214196
[15] S. R. Kadari, G. Radhika, M. Shekar, R. V. V. S. Ravi Shankar, and C. Madhu, "A Study on the Key Applications of Malware," International Journal of Advanced Research in Science, Communication and Technology, pp. 481-485, Aug. 2024, DOI: 10.48175/IJARSCT-19359. DOI: https://doi.org/10.48175/IJARSCT-19359
[16] A. Z. Chahoki, H. R. Shahriari, and M. Roveri, “CryptojackingTrap: An Evasion Resilient Nature-Inspired Algorithm to Detect Cryptojacking Malware,” IEEE Transactions on Information Forensics and Security, vol. 19, pp. 7465–7477, 2024, DOI: 10.1109/TIFS.2024.3353072. DOI: https://doi.org/10.1109/TIFS.2024.3353072
[17] Ö. Aslan, S. S. Aktuğ, M. Ozkan-Okay, A. A. Yilmaz, and E. Akin, “A Comprehensive Review of Cyber Security Vulnerabilities, Threats, Attacks, and Solutions,” Mar. 01, 2023, MDPI. DOI: 10.3390/electronics12061333. DOI: https://doi.org/10.3390/electronics12061333
[18] A. Warikoo, “Perspective Chapter: Ransomware,” in Malware - Detection and Defense, IntechOpen, 2023. DOI: 10.5772/intechopen.108433. DOI: https://doi.org/10.5772/intechopen.108433
[19] L. Albshaier, S. Almarri, and M. M. H. Rahman, “Earlier Decision on Detection of Ransomware Identification: A Comprehensive Systematic Literature Review,” Aug. 01, 2024, Multidisciplinary Digital Publishing Institute (MDPI). DOI: 10.3390/info15080484. DOI: https://doi.org/10.3390/info15080484
[20] J. A. Gómez Hernández, P. García Teodoro, R. Magán Carrión, and R. Rodríguez Gómez, “Crypto-Ransomware: A Revision of the State of the Art, Advances and Challenges,” Nov. 01, 2023, Multidisciplinary Digital Publishing Institute (MDPI). DOI: 10.3390/electronics12214494. DOI: https://doi.org/10.3390/electronics12214494
[21] S. H. Kok, A. Abdullah, N. Z. Jhanjhi, and M. Supramaniam, “Prevention of crypto-ransomware using a pre-encryption detection algorithm,” Computers, vol. 8, no. 4, Dec. 2019, DOI: 10.3390/computers8040079. DOI: https://doi.org/10.3390/computers8040079
[22] A. Alqahtani and F. T. Sheldon, “Temporal Data Correlation Providing Enhanced Dynamic Crypto-Ransomware Pre-Encryption Boundary Delineation,” Sensors, vol. 23, no. 9, May 2023, DOI: 10.3390/s23094355. DOI: https://doi.org/10.3390/s23094355
[23] X. Fang, E. Song, C. Ning, H. Huseynov, and T. Saadawi, “Crypto-Ransomware Detection Through a Honeyfile-Based Approach with R-Locker,” 2025, DOI: 10.3390/math. DOI: https://doi.org/10.3390/math13121933
[24] S. Razaulla et al., “The Age of Ransomware: A Survey on the Evolution, Taxonomy, and Research Directions,” IEEE Access, vol. 11, pp. 40698–40723, 2023, DOI: 10.1109/ACCESS.2023.3268535. DOI: https://doi.org/10.1109/ACCESS.2023.3268535
[25] T. McIntosh et al., “Ransomware Reloaded: Re-examining Its Trend, Research and Mitigation in the Era of Data Exfiltration,” ACM Comput. Surv., vol. 57, no. 1, Oct. 2024, DOI: 10.1145/3691340. DOI: https://doi.org/10.1145/3691340
[26] J. Y. Marion, “Ransomware: Extortion Is My Business,” Commun. ACM, vol. 68, no. 5, pp. 36–47, May 2025, DOI: 10.1145/3697829.
[27] K. Drabent, R. Janowski, and J. Mongay Batalla, “How to Circumvent and Beat the Ransomware in Android Operating System—A Case Study of Locker.CB!tr,” Electronics (Switzerland), vol. 13, no. 11, Jun. 2024, DOI: 10.3390/electronics13112212. DOI: https://doi.org/10.3390/electronics13112212
[28] A. Albin Ahmed, A. Shaahid, F. Alnasser, S. Alfaddagh, S. Binagag, and D. Alqahtani, “Android Ransomware Detection Using Supervised Machine Learning Techniques Based on Traffic Analysis,” Sensors, vol. 24, no. 1, Jan. 2024, DOI: 10.3390/s24010189. DOI: https://doi.org/10.3390/s24010189
[29] E. Kritika, “A comprehensive literature review on ransomware detection using deep learning,” Dec. 01, 2025, KeAi Communications Co. DOI: 10.1016/j.csa.2024.100078. DOI: https://doi.org/10.1016/j.csa.2024.100078
[30] P. H. Meland, Y. F. F. Bayoumy, and G. Sindre, “The Ransomware-as-a-Service economy within the darknet,” Comput. Secur., vol. 92, p. 101762, 2020.
[31] D.-I. GRIGORIȚĂ, E. DIMA, I.-A. BUICĂ, and E. SIMION, “Ransomware in the Automotive Industry,” Romanian Cyber Security Journal, vol. 7, no. 1, pp. 3–22, Jun. 2025, DOI: 10.54851/v7i1y202501. DOI: https://doi.org/10.54851/v7i1y202501
[32] K. Oosthoek, J. Cable, and G. Smaragdakis, “A Tale of Two Markets: Investigating the Ransomware Payments Economy,” May 2022, [Online]. Available: http://arxiv.org/abs/2205.05028
[33] M. Cen, F. Jiang, X. Qin, Q. Jiang, and R. Doss, “Ransomware early detection: A survey,” Feb. 01, 2024, Elsevier B.V. DOI: 10.1016/j.comnet.2023.110138. DOI: https://doi.org/10.1016/j.comnet.2023.110138
[34] A. Alraizza and A. Algarni, “Ransomware Detection Using Machine Learning: A Survey,” Sep. 01, 2023, Multidisciplinary Digital Publishing Institute (MDPI). DOI: 10.3390/bdcc7030143. DOI: https://doi.org/10.3390/bdcc7030143
[35] J. Li, G. Yang, and Y. Shao, “Ransomware Detection Model Based on Adaptive Graph Neural Network Learning †,” Applied Sciences (Switzerland), vol. 14, no. 11, Jun. 2024, DOI: 10.3390/app14114579. DOI: https://doi.org/10.3390/app14114579
[36] B. A. S. Al-rimy, M. A. Maarof, and S. Z. M. Shaid, “Ransomware threat success factors, taxonomy, and countermeasures: A survey and research directions,” May 01, 2018, Elsevier Ltd. DOI: 10.1016/j.cose.2018.01.001. DOI: https://doi.org/10.1016/j.cose.2018.01.001
[37] F. Oelmaier, U. Knebelsberger, and A. Naefe, “Taktik, Tools und Vorgehen der Angreifer,” 2023, pp. 61–105. DOI: 10.1007/978-3-658-41614-0_5. DOI: https://doi.org/10.1007/978-3-658-41614-0_5
[38] Y. Lee, J. Lee, D. Ryu, H. Park, and D. Shin, “Clop Ransomware in Action: A Comprehensive Analysis of Its Multi-Stage Tactics,” Electronics (Basel)., vol. 13, no. 18, p. 3689, Sep. 2024, DOI: 10.3390/electronics13183689. DOI: https://doi.org/10.3390/electronics13183689
[39] H. Alshaikh, H. Ahmed, and N. Ramadan, “Crypto-Ransomware Detection and Prevention Techniques and Tools A Survey,” International Journal of Computing and Digital Systems, vol. 14, no. 1, pp. 10299–10308, Oct. 2023, DOI: 10.12785/ijcds/1401102. DOI: https://doi.org/10.12785/ijcds/1401102
[40] R. R. Simón et al., “Empirical Analysis and Practical Assessment of Ransomware Attacks to Data in Motion,” in 2024 IEEE International Conference on Cyber Security and Resilience (CSR), IEEE, Sep. 2024, pp. 216–221. DOI: 10.1109/CSR61664.2024.10679487. DOI: https://doi.org/10.1109/CSR61664.2024.10679487
[41] H. Siadati et al., “DevPhish: Exploring Social Engineering in Software Supply Chain Attacks on Developers,” Sep. 2024, [Online]. Available: http://arxiv.org/abs/2402.18401
[42] Surendra Vitla, “Unsecured Remote Desktop Protocol (RDP) Access: A Gateway for Ransomware Attacks and Corporate Extortion,” Journal of Computer Science and Technology Studies, vol. 6, no. 2, pp. 150–165, May 2024, DOI: 10.32996/jcsts.2024.6.2.17. DOI: https://doi.org/10.32996/jcsts.2024.6.2.17
[43] K. Gangwar, S. Mohanty, and A. K. Mohapatra, “Analysis and Detection of Ransomware Through Its Delivery Methods,” 2018, pp. 353–362. DOI: 10.1007/978-981-10-8527-7_29. DOI: https://doi.org/10.1007/978-981-10-8527-7_29
[44] K. Begovic, A. Al-Ali, and Q. Malluhi, “Cryptographic ransomware encryption detection: Survey,” Comput. Secur., vol. 132, p. 103349, 2023. DOI: https://doi.org/10.1016/j.cose.2023.103349
[45] Y. J. Seng et al., “In-Depth Analysis and Countermeasures for Ransomware Attacks: Case Studies and Recommendations,” Sep. 02, 2024. DOI: 10.20944/preprints202408.2261.v1. DOI: https://doi.org/10.20944/preprints202408.2261.v1
[46] C. B. Basha et al., “Understanding and Mitigating Ransomware Threats: Trends, Techniques, and Countermeasures in the Digital Age,” in 2023 International Conference for Technological Engineering and its Applications in Sustainable Development (ICTEASD), IEEE, Nov. 2023, pp. 383–387. DOI: 10.1109/ICTEASD57136.2023.10585140. DOI: https://doi.org/10.1109/ICTEASD57136.2023.10585140
[47] F. Bureau of Investigation, I. Security Agency, M.-S. Information Sharing, and A. Center, “#StopRansomware: Medusa Ransomware.”
[48] U. - United Nations Office on Drugs, “Ransomware policy paper UNITED NATIONS Vienna, 2023 UNITED NATIONS OFFICE ON DRUGS AND CRIME.”
[49] M. Aggarwal, “Ransomware Attack: An Evolving Targeted Threat,” in 2023 14th International Conference on Computing Communication and Networking Technologies, ICCCNT 2023, Institute of Electrical and Electronics Engineers Inc., 2023. DOI: 10.1109/ICCCNT56998.2023.10308249. DOI: https://doi.org/10.1109/ICCCNT56998.2023.10308249
[50] M. Said BOUFLIH, “Specificity of Ransomware Investigation (Analytical Study in Light of the European Cybercrime Programmed 2022) Introduction,” 2025. [Online]. Available: http://revue.umc.edu.dz/index.php/h DOI: https://doi.org/10.34174/0079-036-002-020
[51] J. Y. Marion, “Ransomware: Extortion Is My Business,” Commun. ACM, vol. 68, no. 5, pp. 36–47, May 2025, DOI: 10.1145/3697829. DOI: https://doi.org/10.1145/3697829
[52] “Ransomware in the EU: Assessment of the Threat Landscape and Cybersecurity Governance,” 2024.
[53] M. Mundt and H. Baier, “Threat-Based Simulation of Data Exfiltration Toward Mitigating Multiple Ransomware Extortions,” Digital Threats: Research and Practice, vol. 4, no. 4, Oct. 2023, DOI: 10.1145/3568993. DOI: https://doi.org/10.1145/3568993
[54] J. O. Buabeng and R. Essah, "Decoding Ransomware: A Thematic Analysis of Trends and Countermeasures," International Journal of Latest Technology in Engineering Management & Applied Science, vol. 14, no. 8, pp. 420-423, Sep. 2025, DOI: 10.51583/IJLTEMAS.2025.1408000051. DOI: https://doi.org/10.51583/IJLTEMAS.2025.1408000051
[55] C. Beaman, A. Barkworth, T. D. Akande, S. Hakak, and M. K. Khan, “Ransomware: Recent advances, analysis, challenges and future research directions,” Comput. Secur., vol. 111, Dec. 2021, DOI: 10.1016/j.cose.2021.102490. DOI: https://doi.org/10.1016/j.cose.2021.102490
[56] N. Vidović, V. M. Cvetković, H. Beriša, and S. Milašinović, “Understanding Ransomware Through the Lens of Disaster Risk: Implications for Cybersecurity and Economic Stability,” Apr. 27, 2025. DOI: 10.20944/preprints202504.1950.v1. DOI: https://doi.org/10.20944/preprints202504.1950.v1
[57] I. Security Agency, “TLP:CLEAR #StopRansomware Guide CHANGE RECORD,” 2020.
[58] S. Corbet and J. W. Goodell, “The reputational contagion effects of ransomware attacks.” [Online]. Available: https://ssrn.com/abstract=4674924
[59] Sophos Ltd, “THE STATE OF RANSOMWARE 2025,” Abingdon, Oxfordshire, UK, Jan. 2025. [Online]. Available: www.sophos.com
[60] S. Alzahrani, Y. Xiao, S. Asiri, J. Zheng, and T. Li, “A Survey of Ransomware Detection Methods,” 2025, Institute of Electrical and Electronics Engineers Inc. DOI: 10.1109/ACCESS.2025.3556187. DOI: https://doi.org/10.1109/ACCESS.2025.3556187
[61] M. M. Andronache, A. Vulpe, and C. Burileanu, “Integrated Analysis of Malicious Software: Insights from Static and Dynamic Perspectives,” Journal of Cybersecurity and Privacy, vol. 5, no. 4, Dec. 2025, DOI: 10.3390/jcp5040098. DOI: https://doi.org/10.3390/jcp5040098
[62] M. Kohli and I. Chhabra, “A comprehensive survey on techniques, challenges, evaluation metrics and applications of deep learning models for anomaly detection,” Jul. 01, 2025, Springer Nature. DOI: 10.1007/s42452-025-07312-7. DOI: https://doi.org/10.1007/s42452-025-07312-7
[63] R. Almuhanna and S. Dardouri, “A deep learning/machine learning approach for anomaly based network intrusion detection,” Front. Artif. Intell., vol. 8, 2025, DOI: 10.3389/frai.2025.1625891. DOI: https://doi.org/10.3389/frai.2025.1625891
[64] Z. He, D. Davila, S. Bi, T. Wang, and T. Hou, “Machine Learning for Cybersecurity: A Survey of Applications, Adversarial Challenges, and Future Research Directions,” Electronics (Switzerland), vol. 14, no. 23, Dec. 2025, DOI: 10.3390/electronics14234563. DOI: https://doi.org/10.3390/electronics14234563
[65] J. Ferdous, R. Islam, A. Mahboubi, and M. Z. Islam, “A novel technique for ransomware detection using image based dynamic features and transfer learning to address dataset limitations,” Sci. Rep., vol. 15, no. 1, Dec. 2025, DOI: 10.1038/s41598-025-17647-1. DOI: https://doi.org/10.1038/s41598-025-17647-1
[66] I. H. Ji, J. H. Lee, M. J. Kang, W. J. Park, S. H. Jeon, and J. T. Seo, “Artificial Intelligence-Based Anomaly Detection Technology over Encrypted Traffic: A Systematic Literature Review,” Feb. 01, 2024, Multidisciplinary Digital Publishing Institute (MDPI). DOI: 10.3390/s24030898. DOI: https://doi.org/10.3390/s24030898
[67] K. K. Verma, B. M. Singh, and A. Dixit, “A review of supervised and unsupervised machine learning techniques for suspicious behavior recognition in intelligent surveillance system,” International Journal of Information Technology (Singapore), vol. 14, no. 1, pp. 397–410, Feb. 2022, DOI: 10.1007/s41870-019-00364-0. DOI: https://doi.org/10.1007/s41870-019-00364-0
[68] O. Ahmed and O. Al-Dabbagh, “Ransomware Detection System Based on Machine Learning,” JOURNAL OF EDUCATION AND SCIENCE, vol. 30, no. 5, pp. 86–102, Dec. 2021, DOI: 10.33899/edusj.2021.130760.1173. DOI: https://doi.org/10.33899/edusj.2021.130760.1173
[69] E. Berrueta, D. Morato, E. Magaña, and M. Izal, “Crypto-ransomware detection using machine learning models in file-sharing network scenarios with encrypted traffic,” Expert Syst. Appl., vol. 209, Dec. 2022, DOI: 10.1016/j.eswa.2022.118299. DOI: https://doi.org/10.1016/j.eswa.2022.118299
[70] M. Venturini, F. Freda, E. Miotto, M. Conti, and A. Giaretta, “Differential Area Analysis for Ransomware: Attacks, Countermeasures, and Limitations,” IEEE Trans. Dependable Secure Comput., vol. 22, no. 4, pp. 3449–3464, 2025, DOI: 10.1109/TDSC.2025.3532324. DOI: https://doi.org/10.1109/TDSC.2025.3532324
[71] M. M. Singh, K. Selvaraj, and Z. Wei, “Enhanced detection of android ransomware families using machine learning and network traffic analysis,” Bulletin of Electrical Engineering and Informatics, vol. 14, no. 4, pp. 2987–2996, Aug. 2025, DOI: 10.11591/eei.v14i4.9485. DOI: https://doi.org/10.11591/eei.v14i4.9485
[72] N. Christakis and D. Drikakis, “Reducing Uncertainty and Increasing Confidence in Unsupervised Learning,” Mathematics, vol. 11, no. 14, Jul. 2023, DOI: 10.3390/math11143063. DOI: https://doi.org/10.3390/math11143063
[73] S. Chadler, S. Davis, T. Delacroix, and W. Carrington, “Ransomware Detection Using Multi-Vector Anomaly Profiling for Maximum Security,” Nov. 15, 2024. DOI: 10.21203/rs.3.rs-5452210/v1. DOI: https://doi.org/10.21203/rs.3.rs-5452210/v1
[74] A. Redhu, P. Choudhary, K. Srinivasan, and T. K. Das, “Deep learning-powered malware detection in cyberspace: a contemporary review,” 2024, Frontiers Media SA. DOI: 10.3389/fphy.2024.1349463. DOI: https://doi.org/10.3389/fphy.2024.1349463
[75] A. Hussain, A. Saadia, M. Alhussein, A. Gul, and K. Aurangzeb, “Enhancing ransomware defense: deep learning-based detection and family-wise classification of evolving threats,” PeerJ Comput. Sci., vol. 10, pp. 1–44, 2024, DOI: 10.7717/peerj-cs.2546. DOI: https://doi.org/10.7717/peerj-cs.2546
[76] M. Davidian, M. Kiperberg, and N. Vanetik, “Early Ransomware Detection with Deep Learning Models,” Future Internet, vol. 16, no. 8, Aug. 2024, DOI: 10.3390/fi16080291. DOI: https://doi.org/10.3390/fi16080291
[77] S. Alzahrani, Y. Xiao, S. Asiri, N. Alasmari, and T. Li, “RansomFormer: A Cross-Modal Transformer Architecture for Ransomware Detection via the Fusion of Byte and API Features,” Electronics (Switzerland), vol. 14, no. 7, Apr. 2025, DOI: 10.3390/electronics14071245. DOI: https://doi.org/10.3390/electronics14071245
[78] P. Wang, H. C. Lin, J. H. Chen, W. H. Lin, and H. C. Li, “Improving Cyber Defense Against Ransomware: A Generative Adversarial Networks-Based Adversarial Training Approach for Long Short-Term Memory Network Classifier,” Electronics (Switzerland), vol. 14, no. 4, Feb. 2025, DOI: 10.3390/electronics14040810. DOI: https://doi.org/10.3390/electronics14040810
[79] M. Abdur Rahman, G. A. Francia Iii, H. Shahriar, G. Francia III, E. El-Sheikh, and S. Iqbal Ahamed, “A Novel Approach to Fine-tune BERT using Non-Text Features for Enhanced Ransomware Detection”, DOI: 10.13140/RG.2.2.35576.15365.
[80] A. Lumazine et al., “Ransomware Detection in Network Traffic Using a Hybrid CNN and Isolation Forest Approach,” Oct. 15, 2024. DOI: 10.22541/au.172901014.44599790/v1. DOI: https://doi.org/10.22541/au.172901014.44599790/v1
[81] L. Woo, S. Tan, T. Tan, and G. Lao, “A Hybrid Approach to Ransomware Detection Using Convolutional Neural Networks and Random Forests on Network Traffic Patterns.”
[82] E. Li, H. He, C. Huang, J. Zhang, H. Cheng, and Y. Ge, “Anomaly-Driven Crypto-Locking Behavior Analysis for Ransomware Detection through Semantic Flow Mapping,” Dec. 12, 2024. DOI: 10.36227/techrxiv.173398043.39428308/v1. DOI: https://doi.org/10.36227/techrxiv.173398043.39428308/v1
[83] E. Itasoy, V. Rosenberg, N. Stavrakis, A. Dietrich, and C. Montanari, “Ransomware Detection on Windows Using File System Activity Monitoring and a Hybrid Isolation Forest-XGBoost Model,” Oct. 16, 2024. DOI: 10.21203/rs.3.rs-5257558/v1. DOI: https://doi.org/10.21203/rs.3.rs-5257558/v1
[84] S. Muhammad, “AI-Driven Ransomware Defense Framework for Digital Banking International Journal of Innovative Research in Science Engineering and Technology (IJIRSET) AI-Driven Ransomware Defense Framework for Digital Banking,” Article in International Journal of Innovative Research in Science Engineering and Technology, 2025, DOI: 10.15680/IJIRSET.2025.1406012.
[85] J. Deleon, C. Hatherleigh, A. Cumberbatch, J. Ashworth, and L. Heathcote, “Predictive Profiling Framework for Ransomware Detection Using Contextual Signature Extraction,” 2024. DOI: https://doi.org/10.31219/osf.io/fwkqd
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Journal of Basrah Researches (Sciences)

This work is licensed under a Creative Commons Attribution 4.0 International License.
This journal is licensed under the Creative Commons Attribution 4.0 International License (CC BY 4.0).
Under this license, users are permitted to read, download, copy, distribute, print, search, link to the full texts of articles, and create derivative works, including for commercial purposes, provided that appropriate credit is given to the original author(s) and the source.
Authors retain the copyright of their published work, while granting the Journal of Basrah Researches Sciences (JBRS) the right of first publication. Proper attribution must include the article title, author name(s), journal name, DOI, and a link to the Creative Commons license.





