Evaluating the Efficacy of Machine Learning Techniques in Ransomware Detection

dc.contributor.authorMeechanchuang K.
dc.contributor.authorSitsaengchai P.
dc.contributor.authorBowornsujaritkul K.
dc.contributor.authorTritilanunt S.
dc.contributor.authorPhienthrakul T.
dc.contributor.correspondenceMeechanchuang K.
dc.contributor.otherMahidol University
dc.date.accessioned2026-03-16T18:14:56Z
dc.date.available2026-03-16T18:14:56Z
dc.date.issued2025-01-01
dc.description.abstractRansomware continues to pose a critical threat to computer systems worldwide, requiring effective detection strategies that can generalize across evolving variants. This paper presents a comparative evaluation of multiple machine learning algorithms for ransomware detection using dynamic analysis. Behavioral features were extracted from ransomware samples via Cuckoo Sandbox, and standard classifiers including Decision Tree, Random Forest, Gradient Boosting, and XGBoost were evaluated with appropriate train-test splits and feature selection. Results show that Random Forest consistently achieves superior performance on unseen ransomware families, highlighting its robustness and practical applicability.Beyond accuracy, this study examines computational considerations, revealing that tree-based models offer favorable tradeoffs between detection efficacy and inference latency, making them suitable for near real-time deployment. Feature importance analysis further indicates that registry modifications, file operations, and cryptographic API calls are key behavioral traits distinguishing ransomware activity.Nevertheless, the study faces limitations, including a relatively small dataset (582 ransomware samples), basic class imbalance handling, and the absence of deep learning baselines. To address these gaps, future work will explore dataset expansion, advanced imbalance handling techniques, neural architectures, and large-scale deployment evaluation. By emphasizing both detection accuracy and forensic interpretability, this work contributes practical insights for improving ransomware defense in real-world environments.
dc.identifier.citationJcsse 2025 22nd International Joint Conference on Computer Science and Software Engineering (2025) , 209-216
dc.identifier.doi10.1109/JCSSE67377.2025.11297864
dc.identifier.scopus2-s2.0-105032444619
dc.identifier.urihttps://repository.li.mahidol.ac.th/handle/123456789/115726
dc.rights.holderSCOPUS
dc.subjectMathematics
dc.subjectComputer Science
dc.subjectComputer Science
dc.subjectDecision Sciences
dc.subjectDecision Sciences
dc.titleEvaluating the Efficacy of Machine Learning Techniques in Ransomware Detection
dc.typeConference Paper
mu.datasource.scopushttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=105032444619&origin=inward
oaire.citation.endPage216
oaire.citation.startPage209
oaire.citation.titleJcsse 2025 22nd International Joint Conference on Computer Science and Software Engineering
oairecerif.author.affiliationMahidol University

Files

Collections