Evaluating the Efficacy of Machine Learning Techniques in Ransomware Detection
| dc.contributor.author | Meechanchuang K. | |
| dc.contributor.author | Sitsaengchai P. | |
| dc.contributor.author | Bowornsujaritkul K. | |
| dc.contributor.author | Tritilanunt S. | |
| dc.contributor.author | Phienthrakul T. | |
| dc.contributor.correspondence | Meechanchuang K. | |
| dc.contributor.other | Mahidol University | |
| dc.date.accessioned | 2026-03-16T18:14:56Z | |
| dc.date.available | 2026-03-16T18:14:56Z | |
| dc.date.issued | 2025-01-01 | |
| dc.description.abstract | Ransomware continues to pose a critical threat to computer systems worldwide, requiring effective detection strategies that can generalize across evolving variants. This paper presents a comparative evaluation of multiple machine learning algorithms for ransomware detection using dynamic analysis. Behavioral features were extracted from ransomware samples via Cuckoo Sandbox, and standard classifiers including Decision Tree, Random Forest, Gradient Boosting, and XGBoost were evaluated with appropriate train-test splits and feature selection. Results show that Random Forest consistently achieves superior performance on unseen ransomware families, highlighting its robustness and practical applicability.Beyond accuracy, this study examines computational considerations, revealing that tree-based models offer favorable tradeoffs between detection efficacy and inference latency, making them suitable for near real-time deployment. Feature importance analysis further indicates that registry modifications, file operations, and cryptographic API calls are key behavioral traits distinguishing ransomware activity.Nevertheless, the study faces limitations, including a relatively small dataset (582 ransomware samples), basic class imbalance handling, and the absence of deep learning baselines. To address these gaps, future work will explore dataset expansion, advanced imbalance handling techniques, neural architectures, and large-scale deployment evaluation. By emphasizing both detection accuracy and forensic interpretability, this work contributes practical insights for improving ransomware defense in real-world environments. | |
| dc.identifier.citation | Jcsse 2025 22nd International Joint Conference on Computer Science and Software Engineering (2025) , 209-216 | |
| dc.identifier.doi | 10.1109/JCSSE67377.2025.11297864 | |
| dc.identifier.scopus | 2-s2.0-105032444619 | |
| dc.identifier.uri | https://repository.li.mahidol.ac.th/handle/123456789/115726 | |
| dc.rights.holder | SCOPUS | |
| dc.subject | Mathematics | |
| dc.subject | Computer Science | |
| dc.subject | Computer Science | |
| dc.subject | Decision Sciences | |
| dc.subject | Decision Sciences | |
| dc.title | Evaluating the Efficacy of Machine Learning Techniques in Ransomware Detection | |
| dc.type | Conference Paper | |
| mu.datasource.scopus | https://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=105032444619&origin=inward | |
| oaire.citation.endPage | 216 | |
| oaire.citation.startPage | 209 | |
| oaire.citation.title | Jcsse 2025 22nd International Joint Conference on Computer Science and Software Engineering | |
| oairecerif.author.affiliation | Mahidol University |
