<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="review-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">JCS</journal-id>
<journal-id journal-id-type="nlm-ta">JCS</journal-id>
<journal-id journal-id-type="publisher-id">JCS</journal-id>
<journal-title-group>
<journal-title>Journal of Cyber Security</journal-title>
</journal-title-group>
<issn pub-type="epub">2579-0064</issn>
<issn pub-type="ppub">2579-0072</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">82741</article-id>
<article-id pub-id-type="doi">10.32604/jcs.2026.082741</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Review</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>A Comprehensive and Critical Analysis of Ransomware Detection, Prevention, Mitigation, and Recovery Approaches</article-title>
<alt-title alt-title-type="left-running-head">A Comprehensive and Critical Analysis of Ransomware Detection, Prevention, Mitigation, and Recovery Approaches</alt-title>
<alt-title alt-title-type="right-running-head">A Comprehensive and Critical Analysis of Ransomware Detection, Prevention, Mitigation, and Recovery Approaches</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Manivannan</surname><given-names>Dakshnamoorthy</given-names></name><email>manivann@cs.uky.edu</email></contrib>
<aff id="aff-1"><institution>Department of Computer Science, University of Kentucky</institution>, <addr-line>Lexington, KY</addr-line>, <country>USA</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Dakshnamoorthy Manivannan. Email: <email>manivann@cs.uky.edu</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2026</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>06</day><month>07</month><year>2026</year>
</pub-date>
<volume>8</volume>
<issue>1</issue>
<fpage>397</fpage>
<lpage>468</lpage>
<history>
<date date-type="received">
<day>21</day>
<month>03</month>
<year>2026</year>
</date>
<date date-type="accepted">
<day>21</day>
<month>05</month>
<year>2026</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2026 The Author. Published by Tech Science Press.</copyright-statement>
<copyright-year>2026</copyright-year>
<copyright-holder>The Author</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_JCS_82741.pdf"></self-uri>
<abstract>
<p>Ransomware has emerged as one of the most disruptive and financially damaging forms of cybercrime, affecting individuals, enterprises, and critical infrastructures worldwide. Over the past decade, ransomware attacks have evolved from simple file-encryption malware to sophisticated, multi-stage campaigns involving data exfiltration, double extortion, and ransomware-as-a-service (RaaS) ecosystems. In response, a large body of research has proposed diverse techniques for detecting, preventing, mitigating, and recovering from ransomware attacks. This paper presents a comprehensive survey of ransomware research spanning behavioral and runtime detection, machine learning and deep learning-based approaches, network and SDN-based detection, platform-specific defenses for mobile and IoT environments, storage- and hardware-assisted protection mechanisms, deception-based defenses, and backup and recovery strategies. In addition, the survey examines adversarial evasion techniques, blockchain-based analysis of ransomware payments, economic and policy perspectives, and the real-world operational impacts of ransomware attacks, particularly in critical sectors such as healthcare. Based on a synthesis of the literature, we identify key open challenges related to adversarial robustness, dataset availability, evolving threat models, and the need for integrated cross-layer defense architectures. Finally, we outline promising research directions for developing scalable, resilient, and trustworthy ransomware defense mechanisms capable of addressing the rapidly evolving ransomware threat landscape.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Ransomware detection</kwd>
<kwd>ransomware prevention</kwd>
<kwd>ransomware mitigation</kwd>
<kwd>computer security</kwd>
<kwd>network security</kwd>
<kwd>machine learning</kwd>
<kwd>deep learning</kwd>
<kwd>explainable AI</kwd>
<kwd>cybersecurity</kwd>
</kwd-group></article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>Ransomware has evolved into one of the most pervasive and damaging cyber threats facing modern digital infrastructure. First observed in the late 1980s, ransomware attacks have transitioned from rudimentary denial-of-access mechanisms to highly organized, financially motivated operations capable of crippling enterprises, public institutions, and critical services. At its core, ransomware is a form of cyber extortion in which adversaries encrypt, lock, ex-filtrate, or destroy victims&#x2019; data and demand payment, typically in cryptocurrency, in exchange for restoration or non-disclosure. While early ransomware primarily relied on simple file encryption, contemporary attacks increasingly combine cryptographic denial, data theft, operational disruption, and psychological coercion, significantly amplifying their impact.</p>
<p>Cryptographic ransomware remains the dominant variant, exploiting strong encryption primitives to render data inaccessible. Ironically, encryption, long regarded as a cornerstone of data confidentiality and privacy, has been repurposed by attackers as a weapon to deny access rather than protect it. Despite decades of technical progress in cybersecurity, the fundamental characteristics of ransomware attacks have remained remarkably consistent: unauthorized encryption, coercive communication, and monetization through anonymous or pseudonymous payment channels. These defining traits distinguish ransomware from other malware classes and make them a critical focal point for detection, prevention, and mitigation research.</p>
<p>In recent years, ransomware operations have matured into sophisticated ecosystems. The emergence of double and triple extortion schemes, where attackers ex-filtrate sensitive data prior to encryption and threaten public disclosure or secondary attacks, has fundamentally altered the risk landscape. Victims are often forced to make decisions under severe information asymmetry, uncertain recovery guarantees, and ambiguous attacker signaling. The widespread adoption of Ransomware-as-a-Service (RaaS) has further lowered the barrier to entry, enabling loosely affiliated actors to share infrastructure, tooling, and revenue. As a result, ransomware is no longer a stand-alone executable artifact but a coordinated socio-technical phenomenon shaped by economics, geopolitics, human negotiation, and cyber-criminal governance.</p>
<p>The increasing frequency, scale, and severity of ransomware incidents have led to substantial financial losses and societal harm. High-profile attacks on healthcare systems, energy infrastructure, supply chains, and public services have demonstrated that ransomware can directly threaten human safety, national security, and economic stability. The accelerated shift toward remote work, cloud services, and interconnected cyber-physical systems has expanded the attack surface across information technology (IT), operational technology (OT), industrial control systems (ICS), and software supply chains. Healthcare and Internet of Things (IoT)-enabled environments are particularly vulnerable due to their reliance on resource-constrained devices, real-time data availability, and strict availability requirements.</p>
<p>From a defensive perspective, ransomware detection and prevention have proven challenging. Traditional signature-based antivirus systems are effective against known samples but fail to generalize to rapidly evolving variants. In response, research has increasingly shifted toward behavior-based and dynamic analysis techniques that monitor file system activity, system calls, memory usage, API invocations, and runtime execution patterns. While such approaches improve resilience to polymorphism and obfuscation, they introduce new limitations, including execution overhead, dependence on controlled environments, susceptibility to evasion, and difficulties in reproducible evaluation. Advanced ransomware can fingerprint virtualized or sandboxed environments, delay payload execution, selectively encrypt files, or deactivate itself when command-and-control (C&#x0026;C) infrastructure is disrupted, thereby undermining dynamic detection pipelines. Machine learning and deep learning methods now play a central role in ransomware detection and classification. These techniques leverage static, dynamic, and hybrid features to identify malicious behavior and, increasingly, classify ransomware into families for threat intelligence and response prioritization. However, many proposed models rely on narrow datasets, binary classification assumptions, or opaque decision processes that limit interpretability and operational trust. The lack of explainability, standardized benchmarks, and realistic deployment-level evaluations hinders both comparative analysis and real-world adoption. Moreover, adversarial adaptation, where attackers actively probe and evade learned detection features, remains insufficiently addressed in much of the existing literature. At the same time, emerging computational paradigms such as quantum computing are expected to further reshape the cybersecurity landscape. Although current ransomware primarily relies on classical cryptographic primitives for file encryption and key exchange, future advances in quantum algorithms, particularly Shor&#x2019;s algorithm, may threaten widely used public-key cryptosystems. Consequently, there is growing interest in post-quantum cryptography (PQC) and quantum-resistant security mechanisms that can preserve long-term confidentiality and resilience. In the ransomware context, this creates a dual implication: quantum-capable adversaries could eventually exploit weaknesses in existing cryptographic infrastructures, while defenders may adopt PQC-based secure storage, backup protection, and key-management frameworks to strengthen resilience against future threats. Although quantum-enabled ransomware remains largely theoretical, incorporating forward-looking cryptographic defenses and post-quantum security models into ransomware mitigation strategies is becoming increasingly important.</p>
<p>Beyond endpoint detection, ransomware mitigation and recovery introduce additional challenges. OS-level defenses can be compromised by privileged adversaries, while storage-level solutions lack semantic visibility into file system structures and application behavior. Blockchain-based ransom payment analysis has improved visibility into cryptocurrency flows, yet most studies focus on individual addresses and overlook macro-level transaction patterns and victim response behaviors. The scarcity of labeled ransomware data, especially in payment networks and large-scale enterprise environments, further complicates impact assessment and defense validation.</p>
<p>Despite extensive academic and industrial attention, current ransomware research exhibits notable gaps. Many studies rely on outdated assumptions, limited samples, or isolated technical perspectives, often neglecting governance frameworks, incident response practices, cyber insurance dynamics, and coordinated law-enforcement actions. At the same time, ransomware continues to evolve under the influence of geopolitical tensions, state-aligned threat actors, and international counter-ransomware initiatives. These dynamics underscore the need to study ransomware holistically&#x2014;as an ecosystem encompassing technical mechanisms, organizational structures, economic incentives, and human decision-making.</p>
<p>The goal of this survey is to provide a comprehensive and critical synthesis of ransomware detection, prevention, mitigation, and recovery techniques proposed over the past decade, with particular emphasis on developments from the last three years, during which research activity has accelerated significantly. We systematically classify existing approaches across multiple dimensions, analyze their assumptions and limitations, and identify persistent open challenges that hinder practical deployment. By integrating insights from peer-reviewed literature, government advisories, and industry reports, this survey aims to bridge the gap between academic innovation and operational resilience. In doing so, it provides a structured foundation for future research and a reference framework for practitioners seeking robust, explainable, adaptive, and future-ready defenses against ransomware.</p>
<p><bold>Cross-cutting Research Challenges:</bold> Based on the surveyed literature, we identify the following key challenges:<list list-type="bullet">
<list-item>
<p><bold>C1: Dataset Realism and Benchmarking</bold>&#x2014;Lack of realistic, diverse, and continuously updated datasets.</p></list-item>
<list-item>
<p><bold>C2: Adversarial Robustness</bold>&#x2014;Vulnerability to evasion, poisoning, and adaptive attacks.</p></list-item>
<list-item>
<p><bold>C3: Generalization and Concept Drift</bold>&#x2014;Poor cross-dataset generalization and lack of long-term robustness.</p></list-item>
<list-item>
<p><bold>C4: Explainability and Trustworthiness</bold>&#x2014;Limited interpretability and lack of trustworthy explanations for ML/DL-based systems.</p></list-item>
<list-item>
<p><bold>C5: Computational Efficiency and Scalability</bold>&#x2014;High overhead and limited scalability in real-world systems.</p></list-item>
<list-item>
<p><bold>C6: Deployment and Integration Constraints</bold>&#x2014;Challenges in integrating solutions into operational environments.</p></list-item>
<list-item>
<p><bold>C7: Cross-Layer Coordination</bold>&#x2014;Lack of unified frameworks across host, network, storage, and cloud layers.</p></list-item>
<list-item>
<p><bold>C8: Recovery and Resilience</bold>&#x2014;Weak integration of recovery, backup, and response mechanisms.</p></list-item>
<list-item>
<p><bold>C9: Economic and Policy Factors</bold>&#x2014;Misaligned incentives and limited integration of economic and regulatory perspectives.</p></list-item>
<list-item>
<p><bold>C10: Emerging and Evolving Threat Models</bold>&#x2014;Rapid evolution of ransomware tactics and attack surfaces.</p></list-item>
</list></p>
<p><xref ref-type="table" rid="table-1">Table 1</xref> summarizes the above key cross-cutting challenges identified in this survey and outlines corresponding research directions. Unlike subsection-specific limitations given in each subsection, these challenges capture fundamental gaps that span multiple ransomware defense paradigms and system layers. The mapping highlights that future research must move beyond isolated solutions toward adaptive, cross-layer, and deployment-aware frameworks that address adversarial robustness, dataset realism, and evolving threat models in a unified manner.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Cross-cutting challenges and research directions in ransomware defense.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th>ID</th>
<th>Challenge Theme</th>
<th>Key Limitations</th>
<th>Research Directions</th>
<th>Applicable Domains</th>
</tr>
</thead>
<tbody>
<tr>
<td><bold>C1</bold></td>
<td>Dataset Realism and Benchmarking</td>
<td>Existing datasets are outdated, small-scale, and fail to capture modern ransomware behaviors (e.g., exfiltration, multi-stage attacks); lack of standardized evaluation protocols.</td>
<td>Develop large-scale, continuously updated, and multi-platform datasets; establish standardized benchmarking frameworks; incorporate real-world workloads and longitudinal data.</td>
<td>ML/DL-based detection, IoT, CPS</td>
</tr>
<tr>
<td><bold>C2</bold></td>
<td>Adversarial Robustness</td>
<td>Detection systems are vulnerable to evasion, poisoning, and mimicry attacks; lack of adversarial evaluation benchmarks.</td>
<td>Design adversarially robust models; develop invariant behavioral features; introduce standardized adversarial testing frameworks; integrate adversarial training.</td>
<td>ML/DL-based detection, behavioral detection</td>
</tr>
<tr>
<td><bold>C3</bold></td>
<td>Generalization and Concept Drift</td>
<td>Models trained on static datasets fail under evolving ransomware behaviors and cross-environment deployment.</td>
<td>Develop adaptive and online learning methods; incorporate domain adaptation and continual learning; perform cross-dataset validation.</td>
<td>ML/DL-based detection, semi-supervised systems</td>
</tr>
<tr>
<td><bold>C4</bold></td>
<td>Explainability and Trustworthiness</td>
<td>Limited interpretability of ML/DL-based models; lack of explanation fidelity and user trust in decisions.</td>
<td>Develop robust and domain-specific XAI techniques; evaluate explanation fidelity and stability; integrate human-in-the-loop validation.</td>
<td>XAI-enabled ML-based systems, SOC environments</td>
</tr>
<tr>
<td><bold>C5</bold></td>
<td>Computational Efficiency and Scalability</td>
<td>High computational and memory overhead limits deployment in real-time, cloud, and resource-constrained environments.</td>
<td>Design lightweight detection models; optimize inference pipelines; leverage edge/fog computing; develop energy-efficient architectures.</td>
<td>IoT, IIoT, CPS, cloud systems</td>
</tr>
<tr>
<td><bold>C6</bold></td>
<td>Deployment and Integration Constraints</td>
<td>Many solutions require OS, firmware, or infrastructure modifications; limited integration with real-world systems.</td>
<td>Develop deployable and modular architectures; ensure compatibility with existing systems; integrate with SIEM/SOC pipelines; minimize operational overhead.</td>
<td>Enterprise, cloud, mobile systems</td>
</tr>
<tr>
<td><bold>C7</bold></td>
<td>Cross-Layer Coordination</td>
<td>Lack of integration across host, network, storage, and cloud layers; fragmented visibility.</td>
<td>Design unified cross-layer detection frameworks; enable data fusion across telemetry sources; standardize interfaces and protocols.</td>
<td>Enterprise, cloud, CPS</td>
</tr>
<tr>
<td><bold>C8</bold></td>
<td>Recovery and Resilience</td>
<td>Recovery mechanisms assume intact backups; limited integration with detection; weak handling of exfiltration-based ransomware.</td>
<td>Develop tamper-resistant backup systems; design adaptive and partial recovery techniques; integrate detection with recovery workflows.</td>
<td>Storage systems, enterprise IT</td>
</tr>
<tr>
<td><bold>C9</bold></td>
<td>Economic and Policy Factors</td>
<td>Misaligned incentives (e.g., ransom payments, cyber insurance); limited integration of policy and economic perspectives.</td>
<td>Develop game-theoretic models; align technical defenses with policy interventions; improve regulation and cross-border enforcement.</td>
<td>Governance, cybersecurity policy</td>
</tr>
<tr>
<td><bold>C10</bold></td>
<td>Emerging and Evolving Threat Models</td>
<td>Rapid evolution of ransomware (fileless, exfiltration-based, cross-layer attacks); defenses lag behind attacker innovation.</td>
<td>Design adaptive and predictive defense systems; incorporate threat intelligence; develop frameworks for emerging attack surfaces (cloud, browser, hardware).</td>
<td>All domains</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><bold><italic>Organization of the Paper</italic></bold></p>
<p>The remainder of this paper is organized as follows. <xref ref-type="sec" rid="s2">Section 2</xref> reviews recent survey articles on ransomware detection, prevention, and mitigation, and critically analyzes their scope and limitations to motivate the need for the present survey. In addition, this section also summarizes the major contributions of this survey. <xref ref-type="sec" rid="s3">Section 3</xref> describes the selection methodology for selecting papers to review, including inclusion and exclusion criteria, and illustrates the review process using a PRISMA-style flow diagram (<xref ref-type="fig" rid="fig-1">Fig. 1</xref>). It also discusses some background for the paper. <xref ref-type="sec" rid="s4">Section 4</xref> presents a comprehensive classification, characterization, and synthesis of ransomware-related research published since 2016. The surveyed studies are organized into well-defined categories based on detection techniques, prevention techniques, system models, and threat assumptions, with the overall taxonomy summarized. For each category, we provide a critical comparative analysis, discuss representative approaches, and identify open research challenges. <xref ref-type="sec" rid="s5">Section 5</xref> provides references to additional relevant studies, including peer-reviewed conference papers, technical reports, and unrefereed preprints, that fall outside the primary scope of this survey and are therefore not discussed in detail.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>PRISMA-style diagram representing the inclusion/exclusion criteria for selecting the papers.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="JCS_82741-fig-1.tif"/>
</fig>
<p><xref ref-type="sec" rid="s6">Section 6</xref> consolidates and discusses cross-cutting open issues and grand challenges that span multiple categories, including robustness to adversarial adaptation, key limitations, deployment feasibility, as well as mapping of attack capabilities to vulnerable defenses and countermeasures and suitability of evaluation metrics for various approaches. Finally, <xref ref-type="sec" rid="s7">Section 7</xref> concludes the paper by summarizing the key findings of the survey, highlighting overarching insights derived from the comparative analysis, and outlining promising directions for future research in ransomware detection, prevention, mitigation, and recovery.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Existing Recent Survey Papers</title>
<p>This section analyzes existing ransomware-related surveys, published after 2020, motivates the need for this survey, summarizes the major contributions of this survey.</p>
<p>Fernando et al. [<xref ref-type="bibr" rid="ref-1">1</xref>] review ML/DL-based ransomware detection and analyze the impact of malware evolution, with emphasis on emerging IoT threats. However, their focus remains largely detection-centric and does not extend to broader system-level or socio-technical considerations. Wang et al. [<xref ref-type="bibr" rid="ref-2">2</xref>] analyze ransomware-related Bitcoin transactions to uncover payment flows and attacker strategies. While providing valuable economic insights, their work is limited to the financial dimension and does not integrate detection, prevention, or operational defenses.</p>
<p>Moussaileb et al. [<xref ref-type="bibr" rid="ref-3">3</xref>] propose a lifecycle-based taxonomy mapping defenses to attack stages, whereas McIntosh et al. [<xref ref-type="bibr" rid="ref-4">4</xref>] focus on evaluation frameworks and methodological rigor. Both contribute structured analysis, but remain limited in scope and lack cross-layer integration and recent coverage. Alqahtani and Sheldon [<xref ref-type="bibr" rid="ref-5">5</xref>] and Smith et al. [<xref ref-type="bibr" rid="ref-6">6</xref>] primarily survey crypto-ransomware detection techniques, emphasizing modeling approaches and accuracy challenges. Their focus is narrowly detection-oriented, with limited discussion of deployment, recovery, or adversarial robustness.</p>
<p>Aldauiji et al. [<xref ref-type="bibr" rid="ref-7">7</xref>] examine ransomware from a cyber-threat-intelligence perspective, while Oz et al. [<xref ref-type="bibr" rid="ref-8">8</xref>] provide a cross-platform overview across PCs, mobile, and IoT systems. Although broader in scope, these works lack a unified analytical framework and do not fully capture recent developments in ransomware tactics and defenses. More recent surveys such as Ispahany et al. [<xref ref-type="bibr" rid="ref-9">9</xref>] and Alzahrani et al. [<xref ref-type="bibr" rid="ref-10">10</xref>] continue to emphasize ML-based detection and dataset analysis, with improved coverage of recent works. However, they remain largely detection-focused and do not provide deep comparative analysis or cross-layer synthesis.</p>
<p>Overall, existing surveys are fragmented across detection, economics, or platform-specific perspectives, with limited integration across technical, operational, and policy dimensions. Most also emphasize pre-2022 work and do not fully reflect the rapid evolution of modern ransomware, including exfiltration-driven attacks and RaaS ecosystems.</p>
<p>In contrast, this survey provides a comprehensive and critical cross-layer synthesis, integrating detection, prevention, mitigation, recovery, and economic perspectives. It emphasizes comparative analysis, adversarial robustness, and real-world deployment challenges, offering a unified and up-to-date framework for understanding modern ransomware defense. <xref ref-type="table" rid="table-2">Table 2</xref> highlights these distinctions.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Comparison of existing ransomware surveys with the present survey.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Survey</th>
<th>Year</th>
<th>Focus</th>
<th>Key Contributions</th>
<th>Limitations</th>
<th>Difference from This Survey</th>
</tr>
</thead>
<tbody>
<tr>
<td>Fernando et al. [<xref ref-type="bibr" rid="ref-1">1</xref>]</td>
<td>2020</td>
<td>ML/DL detection</td>
<td>Reviews ML/DL-based ransomware detection; analyzes malware evolution; discusses IoT trends.</td>
<td>Detection-centric; limited coverage of mitigation, recovery, and recent advances.</td>
<td>Our survey provides a holistic, up-to-date synthesis beyond detection, including defense, recovery, and ecosystem-level analysis.</td>
</tr>
<tr>
<td>Wang et al. [<xref ref-type="bibr" rid="ref-2">2</xref>]</td>
<td>2021</td>
<td>Bitcoin analysis</td>
<td>Analyzes ransomware payments and fund flows (2012&#x2013;2021) using clustering and classification.</td>
<td>Focus limited to economic/payment analysis; lacks technical defense coverage.</td>
<td>We integrate economic insights within a broader technical and operational ransomware framework.</td>
</tr>
<tr>
<td>Moussaileb et al. [<xref ref-type="bibr" rid="ref-3">3</xref>]</td>
<td>2021</td>
<td>Lifecycle defenses</td>
<td>Maps countermeasures to ransomware lifecycle stages; identifies research gaps.</td>
<td>Limited focus on ML/DL, adversarial aspects, and emerging threat models.</td>
<td>Our survey extends lifecycle analysis with unified taxonomies, adversarial insights, and broader coverage.</td>
</tr>
<tr>
<td>McIntosh et al. [<xref ref-type="bibr" rid="ref-4">4</xref>]</td>
<td>2021</td>
<td>Mitigation evaluation</td>
<td>Proposes evaluation framework; compares mitigation techniques across studies.</td>
<td>Focused on evaluation; narrower technical scope.</td>
<td>We complement evaluation insights with a comprehensive cross-layer taxonomy and analysis.</td>
</tr>
<tr>
<td>Alqahtani and Sheldon [<xref ref-type="bibr" rid="ref-5">5</xref>]</td>
<td>2022</td>
<td>Crypto- ransomware detection</td>
<td>Surveys detection methods; highlights accuracy and robustness issues.</td>
<td>Detection-focused; limited coverage of other defense aspects.</td>
<td>Our survey includes detection but also prevention, mitigation, recovery, and emerging threats.</td>
</tr>
<tr>
<td>Smith et al. [<xref ref-type="bibr" rid="ref-6">6</xref>]</td>
<td>2022</td>
<td>Detection techniques</td>
<td>Reviews detection approaches and open issues in modeling.</td>
<td>Primarily detection-centric; lacks system-level and economic perspectives.</td>
<td>We provide a full-spectrum analysis across technical and organizational dimensions.</td>
</tr>
<tr>
<td>Aldauiji et al. [<xref ref-type="bibr" rid="ref-7">7</xref>]</td>
<td>2022</td>
<td>CTI-based detection</td>
<td>Explores CTI models and datasets for ransomware detection.</td>
<td>Specialized focus; limited system-level and recovery analysis.</td>
<td>Our survey incorporates CTI within a broader, integrated ransomware defense framework.</td>
</tr>
<tr>
<td>Oz et al. [<xref ref-type="bibr" rid="ref-8">8</xref>]</td>
<td>2022</td>
<td>Cross- platform survey</td>
<td>Analyzes ransomware across PCs, mobile, and IoT/CPS; discusses evolution and defenses.</td>
<td>Covers work mostly up to 2020; limited focus on recent advances and adversarial issues.</td>
<td>Our survey is more recent and expands analysis to adversarial, economic, and recovery aspects.</td>
</tr>
<tr>
<td>Ispahany et al. [<xref ref-type="bibr" rid="ref-9">9</xref>]</td>
<td>2024</td>
<td>ML detection architectures</td>
<td>Summarizes ML-based detection designs and limitations.</td>
<td>Restricted to ML-based detection.</td>
<td>We extend beyond ML to include cross-layer defenses and broader ecosystem analysis.</td>
</tr>
<tr>
<td>Alzahrani et al. [<xref ref-type="bibr" rid="ref-10">10</xref>]</td>
<td>2025</td>
<td>Platform-specific detection</td>
<td>Reviews Windows/Android detection methods and datasets.</td>
<td>Platform-specific and detection-focused.</td>
<td>Our survey provides cross-platform, cross-layer coverage including mitigation and recovery.</td>
</tr>
<tr>
<td><bold>This survey</bold></td>
<td><bold>2026</bold></td>
<td><bold>Comprehensive ransomware research landscape</bold></td>
<td><bold>Provides a holistic and critical synthesis of ransomware detection, prevention, mitigation, recovery, and response; proposes unified taxonomies for detection and defense mechanisms; analyzes adversarial evasion, emerging threat models, blockchain/payment tracing, economic and policy perspectives, and operational impacts on critical sectors; emphasizes advances from the last decade, especially the post-2022 surge in research.</bold></td>
<td><bold>&#x2014;</bold></td>
<td><bold>Distinguished by its breadth, recency, cross-layer perspective, and integration of technical, economic, organizational, and policy dimensions into a single survey framework.</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<p><bold><italic>Contributions of This Survey</italic></bold></p>
<p>The principal contributions of this survey are as follows:</p>
<list list-type="bullet">
<list-item>
<p><bold>Comprehensive and up-to-date literature coverage.</bold> Provides a broad survey of ransomware research published during the past decade, with particular emphasis on recent advances in detection, prevention, mitigation, recovery, and response across enterprise, cloud, IoT, IIoT, CPS, and healthcare environments.</p></list-item>
<list-item>
<p><bold>Multi-dimensional taxonomy contribution.</bold> Introduces a unified taxonomy that categorizes ransomware research across multiple dimensions simultaneously, including detection paradigm, deployment environment, defense layer, analytical technique, operational objective, and adversarial resilience. Unlike many prior surveys that rely on a single classification perspective, the proposed taxonomy enables more structured cross-domain comparison and synthesis.</p></list-item>
<list-item>
<p><bold>Cross-layer ransomware defense framework.</bold> Presents a systematic classification framework for ransomware defenses spanning host-level, network-level, storage-level, hardware-assisted, deception-based, blockchain-assisted, and recovery-oriented mechanisms, thereby providing a holistic view of how different defense layers interact and complement each other.</p></list-item>
<list-item>
<p><bold>Comparative analytical synthesis of detection approaches.</bold> Provides a critical comparison of behavioral, ML/DL-based, network-based, storage-level, and hybrid ransomware detection techniques with respect to detection capability, explainability, deployment feasibility, adversarial robustness, scalability, false positives, and time-to-detection trade-offs.</p></list-item>
<list-item>
<p><bold>Analysis of emerging ransomware threat models.</bold> Examines the evolution of modern ransomware ecosystems, including double/triple extortion, Ransomware-as-a-Service (RaaS), fileless ransomware, selective and intermittent encryption, exfiltration-based attacks, and cross-platform ransomware targeting cloud, IoT, and virtualized environments.</p></list-item>
<list-item>
<p><bold>Integrated economic, operational, and policy perspective.</bold> Synthesizes technical and non-technical aspects of ransomware, including attacker incentives, cryptocurrency-enabled monetization, ransom negotiation dynamics, cyber insurance implications, and regulatory and law-enforcement responses.</p></list-item>
<list-item>
<p><bold>Critical assessment of blockchain-based payment analysis.</bold> Reviews blockchain analytics approaches used for ransomware payment tracking, attribution, and cryptocurrency flow analysis, while also highlighting limitations related to scalability, privacy-preserving transactions, and incomplete attribution.</p></list-item>
<list-item>
<p><bold>Identification of recurring limitations and research gaps.</bold> Synthesizes common weaknesses observed across the literature, including dataset bias, lack of standardized benchmarks, insufficient adversarial evaluation, limited explainability, scalability issues, and gaps between research prototypes and real-world deployment.</p></list-item>
<list-item>
<p><bold>Future research directions and next-generation defense insights.</bold> Highlights promising future directions, including adaptive and cross-layer ransomware defenses, explainable and adversarially robust detection, standardized evaluation methodologies, post-quantum security considerations, and resilient recovery-oriented architectures.</p></list-item>
</list>
<p>This survey distinguishes itself through a <italic>critical, comparative, and cross-layer synthesis</italic> of ransomware research, highlighting limitations, assumptions, and deployment challenges, and providing a unified, forward-looking framework for ransomware defense.</p>
</sec>
<sec id="s3">
<label>3</label>
<title>Methodology Used for Selecting Papers and Background</title>
<sec id="s3_1">
<label>3.1</label>
<title>Methodology Used for Selecting Papers</title>
<p>To ensure rigor, transparency, and reproducibility, we adopted a systematic survey methodology inspired by PRISMA guidelines. Major digital libraries, including IEEE Xplore, ACM Digital Library, Springer, Elsevier, and arXiv, were searched using combinations of keywords such as <italic>&#x201C;ransomware detection&#x201D;, &#x201C;ransomware defense&#x201D;, &#x201C;ransomware recovery&#x201D;, &#x201C;machine learning&#x201D;, &#x201C;cyber extortion&#x201D;, and &#x201C;ransomware mitigation&#x201D;</italic>. The search focused on publications from 2016 to 2025, with particular emphasis on studies published after 2022 to capture the rapid evolution of ransomware research in recent years.</p>
<p><bold>Inclusion criteria:</bold> (i) peer-reviewed articles or widely cited preprints, (ii) clear relevance to ransomware detection, prevention, mitigation, or recovery, (iii) substantive technical, empirical, or analytical contribution.</p>
<p><bold>Exclusion criteria:</bold> (i) non-technical reports or opinion articles, (ii) duplicate or highly incremental studies, (iii) papers lacking sufficient methodological or experimental detail, (iv) works outside the scope of ransomware defense.</p>
<p>The initial search yielded approximately 600 papers. During the first screening stage, titles and abstracts were reviewed, resulting in the removal of more than 200 papers that were either outside the scope of the survey, lacked technical depth, or originated from lower-impact venues. The remaining 350<inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mo>+</mml:mo></mml:math></inline-formula> studies underwent a more detailed abstract- and content-level assessment, leading to the exclusion of approximately 150 additional papers that did not directly address ransomware detection, prevention, mitigation, or recovery. Ultimately, nearly 200 high-quality and representative studies were selected for comprehensive analysis and comparison.</p>
<p>More than 125 of the selected papers were published between 2022 and 2025, reflecting the significant recent growth of ransomware research. The remaining references include foundational works, influential earlier studies, and prior surveys that provide historical context and background. The final corpus was then systematically categorized based on dimensions such as detection paradigm, deployment environment, defense layer, analytical technique, and operational objective.</p>
<p>Overall, the resulting papers provides a comprehensive and representative foundation for analyzing the evolution, strengths, limitations, and practical applicability of ransomware defense mechanisms across diverse systems and deployment environments. The PRISMA-style flow diagram <xref ref-type="fig" rid="fig-1">Fig. 1</xref> presents clearly defined screening stages, paper counts, and explicit exclusion at each stage of the selection process.</p>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Some Background Related to Machine Learning</title>
<p>Machine Learning (ML) has become a key component of modern cybersecurity, enabling automated analysis of large-scale and evolving threat data. In ransomware detection and prevention, ML techniques are widely used to identify malicious behavior, detect anomalies, and classify attacks.</p>
<p><bold>Data Imbalance:</bold> Data imbalance in datasets occurs when the number of samples belonging to one class is significantly larger than the number of samples belonging to another class. In cybersecurity and ransomware detection datasets, benign samples often vastly outnumber malicious samples. For example, a dataset may contain 95% normal activity and only 5% ransomware activity. Class imbalance can severely affect the performance of detection systems. Machine Learning models trained on highly imbalanced datasets tend to become biased toward the majority class, causing them to predict benign behavior more frequently while failing to detect minority-class attacks. As a result, a model may achieve very high overall accuracy while still producing a high False Negative Rate (FNR), meaning many ransomware instances go undetected. This is particularly dangerous in ransomware detection because missing even a small number of attacks can lead to significant damage. Imbalanced datasets may also distort evaluation metrics, making accuracy alone unreliable. Therefore, researchers often use techniques such as oversampling, under-sampling, data augmentation, cost-sensitive learning, and metrics like Recall, F1-score, ROC-AUC, and Precision-Recall to properly evaluate and improve ransomware detection systems when imbalanced datasets are used.</p>
<p><bold>Ransomware-Specific Interpretation of Evaluation Metrics:</bold> In ransomware detection, evaluation metrics must be interpreted in terms of security risk and operational impact.</p>
<p><bold>True positive rate (TPR):</bold> Measures correctly detected ransomware; high TPR is critical to avoid missed attacks.</p>
<p><bold>False negative rate (FNR):</bold> Captures missed ransomware; even small values pose severe risk.</p>
<p><bold>False positive rate (FPR):</bold> Indicates false alarms; high FPR disrupts normal operations and reduces trust.</p>
<p><bold>Time-to-detection (TTD):</bold> Amount of time elapsed between the moment ransomware begins its malicious activity and the moment the security system successfully detects it.</p>
<p><bold>Precision:</bold> Measures reliability of alerts; low precision increases investigation overhead.</p>
<p><bold>F1-score:</bold> Balances precision and recall, useful for imbalanced datasets.</p>
<p><bold>Accuracy:</bold> Can be misleading under class imbalance.</p>
<p><bold>ROC-AUC:</bold> Evaluates model discrimination across thresholds.</p>
<p>Overall, ransomware detection prioritizes minimizing false negatives while maintaining acceptable false positives, with the balance depending on deployment context (e.g., endpoints, cloud, or critical infrastructure).</p>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>Evaluation Challenges and Standardization</title>
<p>While metrics such as accuracy, precision, recall, F1-score, and ROC-AUC are widely reported, their interpretation in ransomware detection requires careful consideration. In real-world deployments, ransomware events are rare, making <italic>false positive rate (FPR)</italic> and <italic>time-to-detection</italic> more critical than aggregate accuracy. Moreover, many studies evaluate models on static and balanced datasets, which can inflate performance due to distributional bias and lack of temporal drift. Cross-dataset generalization, robustness to adversarial manipulation, and evaluation under realistic workloads remain underexplored.</p>
<p>Beyond predictive performance, practical deployment requires consideration of: (i) computational overhead and latency, (ii) scalability in cloud and IoT environments, (iii) explainability and analyst interpretability, (iv) resilience against evasion and poisoning attacks.</p>
<p>These gaps highlight the need for standardized benchmarks and evaluation protocols aligned with real-world ransomware scenarios.</p>
<p><xref ref-type="table" rid="table-3">Table 3</xref> summarizes representative datasets commonly used in ransomware research. These datasets span multiple modalities, including binary analysis, network traffic, memory forensics, and IoT telemetry, reflecting the diverse nature of ransomware detection approaches. However, many datasets suffer from limitations such as lack of realism, outdated attack scenarios, and limited coverage of modern ransomware behaviors such as data exfiltration and multi-stage attacks. This highlights the need for more comprehensive and continuously updated benchmarking datasets.</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Representative datasets used in ransomware detection research.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> 
</colgroup>
<thead>
<tr>
<th>Dataset</th>
<th>Year</th>
<th>Type</th>
<th>Data Modality</th>
<th>Key Features</th>
</tr>
</thead>
<tbody>
<tr>
<td>VirusShare [<xref ref-type="bibr" rid="ref-11">11</xref>]</td>
<td>Ongoing</td>
<td>Malware Repository</td>
<td>Binary samples</td>
<td>Large collection of ransomware and malware binaries; widely used for static and dynamic analysis.</td>
</tr>
<tr>
<td>Malicia Dataset [<xref ref-type="bibr" rid="ref-12">12</xref>]</td>
<td>2015</td>
<td>Malware Dataset</td>
<td>Binary &#x002B; API calls</td>
<td>Contains ransomware and benign samples; used for ML-based malware classification.</td>
</tr>
<tr>
<td>EMBER Dataset [<xref ref-type="bibr" rid="ref-13">13</xref>]</td>
<td>2018</td>
<td>Malware Dataset</td>
<td>Static features<break/> (PE files)</td>
<td>Large-scale labeled dataset for malware classification; includes feature vectors extracted from binaries.</td>
</tr>
<tr>
<td>CIC-MalMem-2022 [<xref ref-type="bibr" rid="ref-14">14</xref>]</td>
<td>2022</td>
<td>Memory-based</td>
<td>Memory dumps</td>
<td>Focuses on ransomware detection using memory analysis; includes benign and ransomware processes.</td>
</tr>
<tr>
<td>CIC-IDS2017 [<xref ref-type="bibr" rid="ref-15">15</xref>]</td>
<td>2017</td>
<td>Network Intrusion</td>
<td>Network traffic flows</td>
<td>Includes ransomware-related traffic; widely used for network-based detection benchmarking.</td>
</tr>
<tr>
<td>CSE-CIC-IDS2018 [<xref ref-type="bibr" rid="ref-16">16</xref>]</td>
<td>2018</td>
<td>Network Intrusion</td>
<td>Network flows</td>
<td>Improved version of CIC-IDS2017; includes modern attack scenarios including ransomware traffic.</td>
</tr>
<tr>
<td>UNSW-NB15 [<xref ref-type="bibr" rid="ref-17">17</xref>]</td>
<td>2015</td>
<td>Network Intrusion</td>
<td>Network traffic</td>
<td>Contains synthetic attack traffic including malware behaviors; used for anomaly detection.</td>
</tr>
<tr>
<td>IoT-23 Dataset [<xref ref-type="bibr" rid="ref-18">18</xref>]</td>
<td>2020</td>
<td>IoT Network</td>
<td>Network traffic</td>
<td>Captures IoT malware traffic including ransomware-like behavior; useful for IoT security research.</td>
</tr>
<tr>
<td>ToN_IoT Dataset [<xref ref-type="bibr" rid="ref-19">19</xref>]</td>
<td>2020</td>
<td>IoT/IIoT</td>
<td>Network &#x002B; telemetry</td>
<td>Includes telemetry, system logs, and network traffic; supports cross-layer ransomware detection.</td>
</tr>
<tr>
<td>UCI Android Malware Dataset [<xref ref-type="bibr" rid="ref-20">20</xref>]</td>
<td>2017</td>
<td>Mobile Malware</td>
<td>APK features</td>
<td>Includes ransomware samples for Android; supports static and dynamic analysis.</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="table" rid="table-4">Table 4</xref> contains a list of frequently used acronyms (Abbreviations) in the literature that are used in this paper. Acronyms of specific algorithms/schemes discussed in this paper are not included in this list.</p>
<table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>Abbreviations used in this paper.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Abbreviation</th>
<th>Elaboration</th>
<th>Detailed Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>AE</td>
<td>Auto Encoder</td>
<td>It is a type of ANN used to learn efficient codings of unlabeled data.</td>
</tr>
<tr>
<td>ANN</td>
<td>Artificial Neural Network</td>
<td>First developed in the 1950s, inspired by the structure and functioning of brain.</td>
</tr>
<tr>
<td>CNN</td>
<td>Convolutional Neural Network</td>
<td>A type of ANN.</td>
</tr>
<tr>
<td>CPS</td>
<td>Cyber Physical Systems</td>
<td>Systems that help in integrating sensing, computation, control and networking and connecting them to the Internet and to each other.</td>
</tr>
<tr>
<td>DL</td>
<td>Deep learning</td>
<td>Machine learning based on Deep Neural Network (DNN).</td>
</tr>
<tr>
<td>DNN</td>
<td>Deep Neural Network</td>
<td>A type of ANN.</td>
</tr>
<tr>
<td>DT</td>
<td>Decision Tree</td>
<td>A flowchart-like structure used for classification of data.</td>
</tr>
<tr>
<td>FL</td>
<td>Federated Learning</td>
<td>A Machine Learning Model designed to use on data spread across multiple nodes.</td>
</tr>
<tr>
<td>HFL</td>
<td>Heterogeneous Federated Learning</td>
<td>A Machine Learning Model designed to use on data spread across multiple heterogeneous nodes.</td>
</tr>
<tr>
<td>IDS</td>
<td>Intrusion detection system</td>
<td>A system designed for detecting intrusions in computer networks.</td>
</tr>
<tr>
<td>IIoT</td>
<td>Industrial Internet of Things</td>
<td>Interconnected sensors and other devices networked together with other industrial applications.</td>
</tr>
<tr>
<td>IoT</td>
<td>Internet of Things</td>
<td>Network of objects/devices connecting and exchanging data with other devices and systems over the Internet.</td>
</tr>
<tr>
<td>K-NN</td>
<td>K-Nearest Neighbors</td>
<td>A classification method.</td>
</tr>
<tr>
<td>LIME</td>
<td>Local Interpretable Model-agnostic Explanations</td>
<td>XAI model proposed by Ribeiro et al. [<xref ref-type="bibr" rid="ref-21">21</xref>].</td>
</tr>
<tr>
<td>LR</td>
<td>Linear Regression</td>
<td>A linear approach for modeling the relationship between a scalar response and one or more dependent variables.</td>
</tr>
<tr>
<td>JRIP</td>
<td>A rule-based classification algorithm</td>
<td>This classification algorithm is derived from RIPPER (Repeated Incremental Pruning to Produce Error Reduction). JRIP is the Java implementation of RIPPER.</td>
</tr>
<tr>
<td>J48</td>
<td>A decision tree algorithm</td>
<td>Java implementation of C4.5, a decision tree-based supervised classification algorithm developed by Ross Quinlan [<xref ref-type="bibr" rid="ref-22">22</xref>].</td>
</tr>
<tr>
<td>MLP</td>
<td>Multilayer Perceptron</td>
<td>A class of feed-forward ANNs.</td>
</tr>
<tr>
<td>NIDS</td>
<td>Network Intrusion detection System</td>
<td>An intrusion detection system designed for detecting intrusions at the network level.</td>
</tr>
<tr>
<td>NLP</td>
<td>Natural Language Processing</td>
<td>A field of AI that enables computers to understand, interpret, generate, and interact using human language.</td>
</tr>
<tr>
<td>RF</td>
<td>Random Forest</td>
<td>An ensemble learning method for classification.</td>
</tr>
<tr>
<td>RNN</td>
<td>Recurrent Neural network</td>
<td>A class of ANNs.</td>
</tr>
<tr>
<td>SDN</td>
<td>Software Defined Networking</td>
<td>An approach to networking that uses software-based controllers or application programming interfaces (APIs) to communicate with underlying hardware infrastructure and direct traffic on a network.</td>
</tr>
<tr>
<td>SHAP</td>
<td>SHapley Additive exPlanations</td>
<td>Proposed by Lundberg and Lee [<xref ref-type="bibr" rid="ref-23">23</xref>] to generate explanations for the predictions of black-box models.</td>
</tr>
<tr>
<td>SMOTE</td>
<td>Synthetic Minority Oversampling</td>
<td>A method for balancing data by over-sampling the minority (abnormal) class and under-sampling the majority (normal) class [<xref ref-type="bibr" rid="ref-24">24</xref>].</td>
</tr>
<tr>
<td>SVM</td>
<td>Support Vector Machine</td>
<td>SVM can learn from sample examples and assign labels to unknown objects. It can help in solving classification and regression problems. It supports standard kernel functions and lets the user choose their own function.</td>
</tr>
<tr>
<td>XAI</td>
<td>Explainable AI</td>
<td>A set of processes and methods that allows human users to comprehend and trust the results and output created by Machine Learning (ML) algorithms [<xref ref-type="bibr" rid="ref-25">25</xref>].</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Research Works Surveyed in This Paper</title>
<p>In this section, we systematically classify, characterize, and critically synthesize ransomware-related research published in leading peer-reviewed journals and top-tier international conferences, primarily from venues such as IEEE, ACM, Elsevier, and Springer. The surveyed literature is organized into two principal classes: (i) detection-focused studies that aim to identify ransomware activity using behavioral, statistical, or learning-based techniques, and (ii) prevention, mitigation, and recovery oriented works that seek to limit damage, enable system restoration, and reduce attacker leverage. Within each class, we further categorize the research and provide a critical comparative analysis of the studies, emphasizing their core contributions, strengths, limitations, and the open challenges associated with each line of work. <italic>We note that this classification and categorization are not intended to be rigid or exhaustive, as certain studies naturally span multiple classes or categories</italic>. <xref ref-type="fig" rid="fig-2">Fig. 2</xref> provides our taxonomy of the ransomware research presented in the literature.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>Our taxonomy of ransomware research surveyed in this paper.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="JCS_82741-fig-2.tif"/>
</fig>
<sec id="s4_1">
<label>4.1</label>
<title>Ransomware Detection-Focused Research Works</title>
<p>In this subsection, we systematically categorize detection-oriented research and review representative studies within each category. For each category, we provide a critical synthesis of the literature, highlighting key design principles, strengths, and limitations, and outline the open research challenges that remain to be addressed.</p>
<sec id="s4_1_1">
<label>4.1.1</label>
<title>Research Works That Use Behavioral/Runtime Approaches for Detection</title>
<p>In this subsection, we comparatively analyze ransomware detection approaches that infer attacks from abnormal runtime behavior. Across the literature, the central intuition is consistent: ransomware must eventually interact with system resources&#x2013;especially files, processes, APIs, registry entries, memory, or the desktop&#x2013;in ways that differ from benign software. The main differences among existing works lie in <italic>where</italic> they monitor behavior (user level, API level, kernel/hypervisor level), <italic>how early</italic> they aim to detect the attack (pre-encryption vs. during encryption), and <italic>what trade-offs</italic> they make among detection speed, robustness, overhead, and deployability.</p>
<p>Early systems such as CryptoDrop [<xref ref-type="bibr" rid="ref-26">26</xref>] and UNVEIL [<xref ref-type="bibr" rid="ref-27">27</xref>] established the practical feasibility of behavior-based ransomware detection. Both exploit the observation that ransomware must manipulate user files or desktop artifacts to achieve its objective, but they do so differently. CryptoDrop emphasizes <italic>online early warning</italic> through correlated file-access indicators and rapid process termination, making it particularly valuable for limiting damage. UNVEIL, in contrast, relies on a synthetic execution environment to observe suspicious file and desktop manipulations, offering richer behavioral visibility but under more controlled conditions. Works such as Chen and Bridges [<xref ref-type="bibr" rid="ref-28">28</xref>] and Homayoun et al. [<xref ref-type="bibr" rid="ref-29">29</xref>] extend this line of research by showing that execution traces are not only useful for detection, but also for extracting discriminative behavioral patterns and even attributing activity to ransomware families. The key insight from these early studies is that runtime behavior provides stronger semantic signals than purely static artifacts, although many results still depend on controlled experimental settings.</p>
<p>A major subsequent research direction centers on Windows API-call analysis, which offers a more fine-grained and machine-learning-ready behavioral representation. Hampton et al. [<xref ref-type="bibr" rid="ref-30">30</xref>] show that API-call frequencies already provide meaningful separation between ransomware and benign processes, while later studies improve on this idea through richer modeling choices. For example, PEDA and its extensions [<xref ref-type="bibr" rid="ref-31">31</xref>,<xref ref-type="bibr" rid="ref-32">32</xref>] emphasize <italic>pre-encryption detection</italic> by combining fast hashing with API-based learning, reflecting a design choice that prioritizes early intervention over deeper but slower analysis. Hwang et al. [<xref ref-type="bibr" rid="ref-33">33</xref>] capture sequential dependencies through Markov modeling, Ullah et al. [<xref ref-type="bibr" rid="ref-34">34</xref>] and Molina et al. [<xref ref-type="bibr" rid="ref-35">35</xref>] show that compact feature representations can capture reconnaissance and evasion behavior, and Herrera-Silva and Hern&#x00E1;ndez-&#x00C1;lvarez [<xref ref-type="bibr" rid="ref-36">36</xref>] strengthen the empirical side of the literature through more recent cross-dataset evaluations. Compared with earlier log-driven methods, API-centric approaches generally offer better granularity and are easier to integrate with learning pipelines, but they are also more exposed to adversarial API obfuscation, delayed execution, and runtime overhead. Thus, their main strength is sensitivity to fine behavioral patterns, whereas their main weakness is brittleness under adaptive attackers.</p>
<p>Another important branch of the literature moves the observation point deeper into the system stack to improve tamper resistance and capture lower-level signals. Javaheri et al. [<xref ref-type="bibr" rid="ref-37">37</xref>] and Zhang et al. [<xref ref-type="bibr" rid="ref-38">38</xref>] use kernel-level instrumentation, while Tang et al. [<xref ref-type="bibr" rid="ref-39">39</xref>] employ virtual machine introspection below the guest OS, and McIntosh et al. [<xref ref-type="bibr" rid="ref-40">40</xref>] explore dynamic user-driven access control as a means of intercepting suspicious file accesses. Compared with user-level or API-level monitoring, these approaches are generally more resistant to evasion and privilege manipulation, and they can sometimes detect attacks earlier in the execution chain. However, that improved robustness comes at the cost of substantially greater deployment complexity, privileged integration requirements, and potential portability challenges. The broader lesson is that deeper visibility often improves resilience, but also makes real-world adoption harder.</p>
<p>Several works focus specifically on detecting ransomware before substantial encryption begins, highlighting a recurring tension between <italic>earliness</italic> and <italic>evidence quality</italic>. Kok et al. [<xref ref-type="bibr" rid="ref-32">32</xref>] and Al Sabeh et al. [<xref ref-type="bibr" rid="ref-41">41</xref>] target environment-inspection and reconnaissance APIs to stop attacks before encryption starts, while Ramesh and Menen [<xref ref-type="bibr" rid="ref-42">42</xref>] model ransomware progression as a finite-state machine across multiple families. Abbasi et al. [<xref ref-type="bibr" rid="ref-43">43</xref>] improve efficiency through optimized behavioral feature selection, and Ayub et al. [<xref ref-type="bibr" rid="ref-44">44</xref>] combine dynamic analysis with prior knowledge from static ML models to improve early detection of previously unseen samples. Taken together, these studies show that pre-encryption detection is attractive because it can significantly reduce damage, but it also relies on the assumption that early-stage malicious behaviors are both observable and sufficiently distinct from benign activity. This assumption is increasingly strained by stealthy, low-and-slow, or staged ransomware.</p>
<p>More recent work reflects a shift from proof-of-concept detection toward operational scalability, transparency, and deployment realism. Hou et al. [<xref ref-type="bibr" rid="ref-45">45</xref>] address a longstanding weakness in the literature, namely, small and unrealistic datasets, by constructing MarauderMap, a multi-terabyte runtime dataset spanning multiple attack stages, which enables more realistic analysis of ransomware behavior across reconnaissance, tampering, exfiltration, and encryption phases. Marcinkowski et al. [<xref ref-type="bibr" rid="ref-46">46</xref>] respond to the interpretability gap by proposing MIRAD, which uses interpretable machine learning over API and registry behaviors, while Wang et al. [<xref ref-type="bibr" rid="ref-47">47</xref>] emphasize deployment practicality through CanCal, a lightweight industrial-scale pipeline that filters candidate processes before applying more expensive behavioral analysis. Compared with earlier sandbox-oriented systems, these recent approaches are less concerned with demonstrating mere detectability and more focused on <italic>scalability, explainability, and low false-positives</italic>. This marks an important maturation of the field.</p>
<p><bold>Open Issues:</bold> Behavioral and runtime-based detection approaches fundamentally rely on the assumption that ransomware exhibits observable pre-encryption activity patterns. However, modern ransomware increasingly adopts stealthy, delayed, or low-and-slow encryption strategies that minimize detectable anomalies. Kernel- and API-level monitoring further introduces runtime overhead and scalability concerns, particularly in cloud and resource-constrained environments. Additionally, these approaches are rarely evaluated under adversarial conditions, where attackers may mimic benign processes or inject noise into behavioral traces, limiting robustness in real-world deployments. These limitations directly relate to challenges <bold>C2</bold> (adversarial robustness), <bold>C5</bold> (efficiency), and <bold>C10</bold> (evolving threat models).</p>
</sec>
<sec id="s4_1_2">
<label>4.1.2</label>
<title>Classical Machine Learning&#x2013;Based Detection Approaches</title>
<p>Classical machine learning (ML) has been widely adopted for ransomware detection due to its ability to learn discriminative patterns from heterogeneous data while maintaining relatively low computational overhead. Across the literature, the key design differences lie in the <italic>choice of feature modality</italic> (static, behavioral, memory), the <italic>degree of feature engineering</italic>, and the <italic>integration with system-level defenses</italic>. These choices directly influence robustness, deployability, and generalization.</p>
<p>Early works explore diverse feature spaces, highlighting a fundamental trade-off between visibility and robustness. Static-analysis approaches (e.g., opcode N-grams with TF-IDF weighting [<xref ref-type="bibr" rid="ref-48">48</xref>]) are computationally efficient and easy to deploy, but are inherently fragile under packing and obfuscation. In contrast, behavioral and screen-content&#x2013;based methods [<xref ref-type="bibr" rid="ref-49">49</xref>] attempt to capture runtime semantics, improving resilience to code transformation at the cost of requiring dynamic analysis environments. Memory-forensics&#x2013;based approaches [<xref ref-type="bibr" rid="ref-50">50</xref>,<xref ref-type="bibr" rid="ref-51">51</xref>] provide even deeper visibility into execution artifacts and can detect fileless or previously unseen ransomware, but introduce significant monitoring overhead and deployment complexity. While these works show that carefully engineered features combined with classifiers such as Random Forest or XGBoost can achieve high reported accuracy, their effectiveness is tightly coupled to the observability and stability of the chosen feature space.</p>
<p>A second line of work focuses on behavioral sequence modeling and feature optimization, revealing that <italic>feature engineering often matters more than model complexity</italic>. Studies modeling API-call sequences and process behaviors [<xref ref-type="bibr" rid="ref-52">52</xref>&#x2013;<xref ref-type="bibr" rid="ref-54">54</xref>] demonstrate that incorporating temporal structure improves detection fidelity compared to simple frequency-based features. Techniques such as Enhanced Maximum-Relevance and Minimum-Redundancy (EmRMR), Principle Component Analysis (PCA), and bio-inspired representations (e.g., digital DNA k-mers) further reduce redundancy and enhance discriminative power. Notably, works such as Jain et al. [<xref ref-type="bibr" rid="ref-55">55</xref>] show that well-designed feature-selection pipelines can allow classical models to match or even outperform deep learning methods. The key insight here is that classical ML remains competitive not because of model sophistication, but because of <italic>efficient and domain-aware feature representations</italic>. However, these approaches remain vulnerable to adversarial manipulation of behavioral features and to concept drift in evolving ransomware.</p>
<p>Another important trend is the integration of ML with cross-layer or system-level defenses. Approaches such as the one proposed by Fernandez Maimo et al. [<xref ref-type="bibr" rid="ref-56">56</xref>] embed ML detection within SDN/NFV-enabled architectures to enable rapid isolation, while Poudyal and Dasgupta [<xref ref-type="bibr" rid="ref-57">57</xref>] and Iqbal et al. [<xref ref-type="bibr" rid="ref-58">58</xref>] combine multi-level and multimodal features (DLL, function calls, assembly, text, images) to improve detection coverage and support family attribution. Compared to standalone classifiers, these systems offer better contextual awareness and response capability, but at the cost of more complex feature pipelines and tighter integration requirements. This highlights a recurring trade-off between <italic>detection accuracy and system complexity</italic>.</p>
<p>Recent work shifts the focus from accuracy-centric evaluation to <italic>scalability and deployment realism</italic>. Stream-based learning approaches [<xref ref-type="bibr" rid="ref-59">59</xref>] address latency constraints in real-time environments, while comparative studies [<xref ref-type="bibr" rid="ref-60">60</xref>] demonstrate that classical ML remains competitive with deep learning when properly tuned. Expanding beyond endpoint detection, blockchain analytics [<xref ref-type="bibr" rid="ref-61">61</xref>] illustrate the applicability of ML to ransomware-related financial activity. Importantly, Rios-Ochoa et al. [<xref ref-type="bibr" rid="ref-62">62</xref>] show that models achieving near-perfect offline accuracy often degrade significantly in live deployments, exposing the gap between laboratory evaluation and operational performance. <bold>Open Issues:</bold> Classical ML-based approaches depend heavily on handcrafted features, which are inherently vulnerable to obfuscation, polymorphism, and feature manipulation by adaptive ransomware. Many studies rely on curated and balanced datasets, resulting in limited generalization under real-world class imbalance and evolving attack distributions. Furthermore, issues such as concept drift, feature instability, and lack of cross-dataset validation remain insufficiently addressed. Adversarial machine learning threats, including evasion and poisoning attacks, are also largely overlooked in existing evaluations. These issues highlight challenges <bold>C1</bold> (dataset realism), <bold>C2</bold> (adversarial robustness), and <bold>C3</bold> (generalization and drift).</p>
</sec>
<sec id="s4_1_3">
<label>4.1.3</label>
<title>Deep Learning&#x2013;Based Ransomware Detection Approaches</title>
<p>In recent years, deep learning (DL) has become a prominent paradigm for ransomware detection due to its ability to automatically learn hierarchical representations from raw or minimally processed data. Unlike classical ML approaches that rely heavily on handcrafted features, DL-based methods shift the design focus toward <italic>representation learning</italic>, enabling models to capture complex temporal, structural, and semantic patterns. However, this shift also introduces new trade-offs related to data dependence, computational cost, interpretability, and robustness.</p>
<p>A dominant line of work models ransomware behavior as temporal sequences, particularly using API calls, system events, or execution traces. Hybrid CNN&#x2013;RNN architectures such as DRTHIS [<xref ref-type="bibr" rid="ref-63">63</xref>] and more recent systems like RansoGuard [<xref ref-type="bibr" rid="ref-64">64</xref>] and iCNN-LSTM&#x002B; [<xref ref-type="bibr" rid="ref-65">65</xref>] demonstrate that combining spatial feature extraction (CNNs) with temporal modeling (LSTMs or attention) improves detection of both known and unseen ransomware variants. These approaches emphasize <italic>early-stage detection</italic> by capturing pre-encryption behaviors and adapting incrementally to evolving threats. Compared to classical ML, they offer greater expressive power and reduced reliance on manual feature engineering. However, this advantage comes at the cost of higher computational overhead, more complex training pipelines, and increased vulnerability to adversarial manipulation of event sequences. Thus, DL-based sequence models trade feature engineering effort for <italic>data and compute dependence</italic>.</p>
<p>A parallel research direction focuses on advanced representation learning from static or hybrid artifacts. Self-attention-based models (e.g., Zhang et al. [<xref ref-type="bibr" rid="ref-66">66</xref>]) address the limitations of RNNs in handling long opcode sequences by capturing global dependencies more efficiently, while image-based approaches (e.g., RansomShield [<xref ref-type="bibr" rid="ref-67">67</xref>]) transform binaries into visual representations that CNNs can process. Hybrid systems such as SwiftR [<xref ref-type="bibr" rid="ref-68">68</xref>] combine static intermediate representations with dynamic behavioral embeddings, aiming to improve generalization to unknown families. These approaches highlight DL&#x2019;s flexibility in handling diverse data modalities and learning high-level abstractions. However, compared to behavioral sequence models, static and image-based methods remain more susceptible to obfuscation, packing, and adversarial perturbations, revealing a key trade-off between <italic>representation richness and robustness</italic>.</p>
<p>To address data scarcity and improve generalization, recent works incorporate generative and data-efficient learning techniques. GAN-based frameworks (e.g., TGAN-IDS [<xref ref-type="bibr" rid="ref-69">69</xref>], BGM-GAN [<xref ref-type="bibr" rid="ref-70">70</xref>]) synthesize realistic ransomware behaviors to enhance detection of early-stage or unseen attacks, while few-shot and meta-learning approaches [<xref ref-type="bibr" rid="ref-71">71</xref>] aim to reduce dependence on large labeled datasets. These methods represent a shift toward <italic>data-centric robustness</italic>, attempting to bridge the gap between limited training data and evolving threat landscapes. However, GAN-based systems introduce training instability and additional complexity, and their effectiveness depends on how well the generated samples reflect real-world attack distributions.</p>
<p>Another emerging trend is the movement toward scalable and deployment-aware DL systems. Approaches such as DeepWare [<xref ref-type="bibr" rid="ref-72">72</xref>] and VM-level monitoring frameworks [<xref ref-type="bibr" rid="ref-73">73</xref>] leverage hardware performance counters and low-level telemetry to enable efficient detection with reduced overhead. Federated learning frameworks [<xref ref-type="bibr" rid="ref-74">74</xref>] extend DL-based detection across distributed environments, addressing data privacy and heterogeneity, while large-scale empirical systems [<xref ref-type="bibr" rid="ref-75">75</xref>] demonstrate cross-domain applicability in mobile and network settings. Compared to earlier prototype models, these systems prioritize <italic>scalability and real-world deployment</italic>, but introduce new challenges such as communication overhead, Non-Independent and Identically Distributed (non-IID) data handling, and vulnerability to poisoning attacks.</p>
<p>Finally, explainability and trustworthiness have emerged as critical concerns for DL-based detection. Frameworks such as XRan [<xref ref-type="bibr" rid="ref-76">76</xref>] and recent hybrid models [<xref ref-type="bibr" rid="ref-77">77</xref>] integrate XAI techniques (e.g., SHAP, LIME) and uncertainty estimation to improve transparency and analyst trust. While these efforts address the black-box nature of DL-based models, they remain limited by the lack of standardized evaluation for explanation fidelity and by potential adversarial manipulation of explanations themselves. This reflects a broader trade-off between <italic>model complexity and interpretability</italic>.</p>
<p><bold>Open Issues:</bold> DL-based ransomware detection methods require large volumes of labeled data and incur significant computational overhead, limiting their applicability in real-time and resource-constrained environments. These models are also susceptible to adversarial examples and traffic manipulation, which can distort learned representations. Moreover, the lack of interpretability and inconsistent evaluation of explanation fidelity raises concerns about trust and usability in operational settings. Cross-dataset generalization and robustness to evolving ransomware behaviors remain open challenges. These challenges correspond to <bold>C2</bold> (adversarial robustness), <bold>C4</bold> (explainability), and <bold>C5</bold> (computational efficiency).</p>
</sec>
<sec id="s4_1_4">
<label>4.1.4</label>
<title>Semi-Supervised/Zero-Shot/Drift-Aware Detection Approaches</title>
<p>Semi-supervised, zero-shot, and drift-aware ransomware detection approaches are motivated by a common limitation of supervised methods, namely, their dependence on large labeled datasets and their inability to generalize to unseen or evolving ransomware variants. While all three paradigms aim to improve adaptability, they differ in <italic>how</italic> they address uncertainty: semi-supervised methods leverage unlabeled data, zero-shot approaches rely on abstract representations, and drift-aware systems explicitly model temporal evolution.</p>
<p>Semi-supervised approaches primarily seek to bridge the gap between limited labeled dataset and abundant unlabeled observations. For example, Sharmeen et al. [<xref ref-type="bibr" rid="ref-78">78</xref>] combine unsupervised representation learning with supervised classification to improve adaptability, whereas Urooj et al. [<xref ref-type="bibr" rid="ref-79">79</xref>] extend this idea using GAN-based augmentation to explicitly model evolving ransomware behavior over time. Compared to fully supervised methods, these approaches improve robustness to unseen variants by leveraging latent structure in data. However, their effectiveness critically depends on the <italic>representativeness of unlabeled or synthesized data</italic>, which is often difficult to guarantee in practice. Thus, they trade improved coverage of unknown threats for increased training complexity and potential sensitivity to distribution bias.</p>
<p>A complementary line of work focuses on early-stage detection under weak or sparse signals, highlighting the importance of <italic>feature quality over model complexity</italic>. The DPBD-FE and subsequent EMIFS/MM-EMIFS frameworks [<xref ref-type="bibr" rid="ref-80">80</xref>,<xref ref-type="bibr" rid="ref-81">81</xref>] emphasize dynamic identification of the pre-encryption boundary and adaptive feature selection tailored to early runtime behavior. Compared to generic feature extraction pipelines, these approaches detect the onset of encryption by monitoring cryptography-related API calls, demonstrating that careful feature engineering can significantly enhance performance even under limited signal conditions. However, their reliance on observable pre-encryption behavior introduces a key vulnerability: stealthy or delayed-encryption ransomware can bypass such assumptions, exposing a trade-off between <italic>early detection and behavioral visibility</italic>.</p>
<p>Zero-shot and drift-aware approaches further generalize detection to previously unseen ransomware and evolving environments, but through different mechanisms. Zero-shot methods such as Zero-Ran Sniff (ZRS) [<xref ref-type="bibr" rid="ref-82">82</xref>] abstract ransomware behavior into high-level attributes using autoencoders and attention mechanisms, enabling detection without family-specific training data. In contrast, drift-aware systems such as FeSAD [<xref ref-type="bibr" rid="ref-83">83</xref>] focus on maintaining performance over time by explicitly modeling and adapting to changes in data distribution. Moreover, FeSAD is designed to detect evolutionary ransomware under concept drift by integrating feature selection, drift calibration, and drift decision layers to enable reliable classification in non-stationary environments. While zero-shot learning emphasizes <italic>generalization across classes</italic>, drift-aware methods emphasize <italic>stability across time</italic>. Both represent a shift away from static models, yet they face a shared challenge: distinguishing benign distributional changes from adversarial evolution. Moreover, their evaluation is often limited to controlled or short-term settings, leaving long-term robustness uncertain.</p>
<p><bold>Open Issues:</bold> Semi-supervised and zero-shot detection approaches aim to address data scarcity but depend heavily on the quality and representativeness of unlabeled or synthetic data. Existing attribute-based or embedding-based representations often fail to capture evolving ransomware semantics and multi-stage attack behaviors. Additionally, these methods lack long-term evaluation under realistic threat evolution scenarios, and their robustness against adversarial manipulation or poisoning of unlabeled data remains largely unexplored. These limitations relate to <bold>C1</bold> (dataset realism), <bold>C3</bold> (generalization), and <bold>C10</bold> (emerging threat models).</p>
</sec>
<sec id="s4_1_5">
<label>4.1.5</label>
<title>Network-Based and SDN-Based Detection</title>
<p>Network- and SDN-based ransomware detection approaches exploit visibility of data at traffic-level and centralized control to identify and contain attacks at the network layer. Unlike host-based methods, these approaches provide <italic>global visibility and rapid response</italic>, but offer limited insight into host-level semantics.</p>
<p>SDN-based frameworks (e.g., [<xref ref-type="bibr" rid="ref-84">84</xref>&#x2013;<xref ref-type="bibr" rid="ref-86">86</xref>]) leverage programmable control planes to detect and block ransomware by analyzing communication patterns and dynamically enforcing flow rules. Their works focus on detecting specific ransomwares (CryptoWall, and WannaCry). Their key advantage lies in <italic>real-time containment and network-wide enforcement</italic>. However, they rely on the assumption that ransomware exhibits identifiable and stable communication signatures, which is increasingly invalid due to encryption, proxying, and domain fronting.</p>
<p>In contrast, passive traffic-analysis approaches (e.g., [<xref ref-type="bibr" rid="ref-87">87</xref>&#x2013;<xref ref-type="bibr" rid="ref-90">90</xref>]) focus on statistical and flow-level features to enable scalable and lightweight detection across enterprise and IoT environments. They [<xref ref-type="bibr" rid="ref-88">88</xref>,<xref ref-type="bibr" rid="ref-89">89</xref>] also focus on specific ransomwares&#x2013;Locky, LooCipher. These methods are easier to deploy and do not require SDN infrastructure, but their effectiveness degrades when malicious traffic is encrypted, tunneled, or indistinguishable from benign flows. Thus, they trade <italic>scalability and deployability</italic> for reduced robustness.</p>
<p>Some works expand the threat model by considering unconventional communication channels such as blockchain-based C&#x0026;C (e.g., [<xref ref-type="bibr" rid="ref-91">91</xref>]) coordination mechanism used by the Cerber ransomware and routing-level anomalies (e.g., [<xref ref-type="bibr" rid="ref-92">92</xref>]) by analyzing routing records from the WestRock ransomware event. These approaches improve coverage against stealthy coordination strategies but introduce significant monitoring complexity and depend on infrastructure-level data that may not be available in practice.</p>
<p><bold>Open Issues:</bold> Network-based detection approaches face significant visibility limitations due to the widespread use of encryption and the adoption of covert C&#x0026;C channels leveraging cloud services, P2P networks, or blockchain infrastructure. Anomaly-based methods often suffer from high false positive rates and lack contextual correlation with host-level activities. SDN-based mitigation strategies further require tight integration with network infrastructure, raising deployment complexity and scalability concerns in large-scale environments. These issues reflect challenges <bold>C6</bold> (deployment constraints), <bold>C7</bold> (cross-layer coordination), and <bold>C10</bold> (evolving attack channels).</p>
</sec>
<sec id="s4_1_6">
<label>4.1.6</label>
<title>Ransomware Detection for Android and Mobile Systems</title>
<p>Ransomware detection in mobile environments differs fundamentally from desktop settings due to <italic>resource constraints, limited system visibility, and strict privacy controls</italic>. As a result, existing approaches can be broadly categorized into behavioral/runtime, static/API-based, and hybrid methods, each offering distinct trade-offs between accuracy, efficiency, and robustness.</p>
<p>Behavioral and runtime monitoring approaches focus on detecting anomalous system activity such as file encryption, system calls, or user&#x2013;application interaction mismatches. Early systems (e.g., [<xref ref-type="bibr" rid="ref-93">93</xref>&#x2013;<xref ref-type="bibr" rid="ref-95">95</xref>]) emphasize real-time detection and damage prevention by continuously monitoring processor usage, memory consumption, unauthorized encryption and I/O activity of critical processes and directories, while more recent methods (e.g., [<xref ref-type="bibr" rid="ref-96">96</xref>,<xref ref-type="bibr" rid="ref-97">97</xref>]) improve efficiency through lightweight streaming models and compiler-assisted instrumentation. These approaches provide strong semantic visibility and early detection capability, but incur runtime overhead and must carefully balance detection accuracy with battery consumption and user experience.</p>
<p>In contrast, static and API-based techniques (e.g., [<xref ref-type="bibr" rid="ref-98">98</xref>&#x2013;<xref ref-type="bibr" rid="ref-100">100</xref>]) prioritize efficiency and scalability by analyzing permissions, API usage, and code structure prior to execution. These methods are well-suited for on-device deployment and large-scale screening, but are inherently fragile under code obfuscation, packing, and dynamic payload loading. Thus, they trade <italic>efficiency for reduced robustness</italic> compared to behavioral approaches.</p>
<p>Hybrid and traffic-based methods (e.g., [<xref ref-type="bibr" rid="ref-101">101</xref>&#x2013;<xref ref-type="bibr" rid="ref-104">104</xref>]) combine static, dynamic, and network-level features to improve generalization across diverse ransomware variants. While these approaches enhance detection robustness and coverage, they introduce higher computational complexity and are less suitable for strictly resource-constrained environments. Similarly, formal and recovery-oriented solutions [<xref ref-type="bibr" rid="ref-105">105</xref>,<xref ref-type="bibr" rid="ref-106">106</xref>] extend beyond detection to provide stronger guarantees or post-attack recovery, but often require deeper system integration.</p>
<p>Overall, the comparison reveals a fundamental trade-off in mobile ransomware detection: <italic>efficiency vs. robustness vs. visibility</italic>. These challenges are further exacerbated by platform constraints such as limited energy, restricted monitoring capabilities, and rapid malware evolution, highlighting the need for lightweight, privacy-preserving, and adaptively robust detection frameworks tailored to mobile ecosystems.</p>
<p><bold>Open Issues:</bold> Mobile ransomware detection remains constrained by limited resources, privacy restrictions, and restricted system visibility. Static methods struggle against obfuscation and dynamic loading, while runtime approaches incur non-trivial overhead. Encrypted traffic and evolving attack strategies further limit detection effectiveness, particularly against zero-day variants. These challenges align with <bold>C5</bold> (efficiency), <bold>C6</bold> (deployment), and <bold>C10</bold> (platform-specific threats).</p>
</sec>
<sec id="s4_1_7">
<label>4.1.7</label>
<title>Ransomware Detection for IoT/IIoT/CPS/Edge/Healthcare (ICE/IoMT) Environments</title>
<p>Ransomware detection in IoT/IIoT/CPS and healthcare environments differs fundamentally from traditional IT systems due to <italic>extreme resource constraints, heterogeneity, and safety-critical requirements</italic>. Existing approaches can be broadly categorized into lightweight behavioral detection, federated/distributed learning, and domain-specific resilience mechanisms, each reflecting different trade-offs between efficiency, scalability, and robustness.</p>
<p>Lightweight behavioral and hybrid approaches (e.g., [<xref ref-type="bibr" rid="ref-107">107</xref>,<xref ref-type="bibr" rid="ref-108">108</xref>]) exploit low-level telemetry (e.g., kernel activity, device signals) to enable early detection with minimal overhead. These methods are well-suited for resource-constrained IIoT edge gateways, but struggle with scalability and cross-device heterogeneity in large deployments.</p>
<p>Federated and distributed learning frameworks (e.g., [<xref ref-type="bibr" rid="ref-109">109</xref>,<xref ref-type="bibr" rid="ref-110">110</xref>]) address data heterogeneity and privacy constraints of IoT/IoMT networks by enabling collaborative detection across devices without centralized data collection. Compared to standalone models, they improve adaptability and coverage, but introduce communication overhead, synchronization complexity, and vulnerability to poisoning attacks.</p>
<p>Domain-specific approaches (e.g., [<xref ref-type="bibr" rid="ref-111">111</xref>,<xref ref-type="bibr" rid="ref-112">112</xref>]) integrate additional mechanisms such as blockchain, fog computing, and economic modeling to enhance resilience in safety-critical systems such as smart healthcare systems and vehicle ecosystems. These methods extend beyond detection to address integrity, traceability, and operational continuity, but significantly increase architectural complexity and may impact real-time performance.</p>
<p>Overall, the comparison reveals a fundamental trade-off in ICE/IoMT ransomware detection: <italic>efficiency vs. scalability vs. resilience</italic>. Lightweight methods prioritize deployability but lack global coordination, federated approaches improve adaptability but add system complexity, and domain-specific solutions enhance resilience at the cost of overhead. These challenges are further compounded by limited visibility into encrypted industrial protocols and the need to maintain safety and regulatory compliance, highlighting the importance of cross-layer, resource-aware, and deployment-specific defense strategies.</p>
<p><bold>Open Issues:</bold> Detection in IoT/IIoT/CPS remains constrained by limited resources, heterogeneity, and safety requirements. Many approaches fail to scale across diverse devices and protocols, while federated methods introduce risks such as poisoning and privacy leakage. Restricted visibility into encrypted industrial traffic further limits effectiveness. These challenges align with <bold>C5</bold> (scalability), <bold>C6</bold> (deployment), and <bold>C7</bold> (cross-layer coordination).</p>
</sec>
<sec id="s4_1_8">
<label>4.1.8</label>
<title>Adversarial and Evasion Analysis of Ransomware</title>
<p>Ransomware evasion can be broadly categorized into <italic>inference-time evasion</italic> (manipulating runtime behavior to bypass detectors) and <italic>poisoning attacks</italic> (corrupting training data to degrade model performance). Across the literature, these strategies expose a fundamental limitation: most detection systems implicitly assume that malicious behavior remains sufficiently distinct from benign activity.</p>
<p>Early studies demonstrate the fragility of existing defenses. Works such as [<xref ref-type="bibr" rid="ref-113">113</xref>,<xref ref-type="bibr" rid="ref-114">114</xref>] show that both signature-based and behavioral detectors can be bypassed through carefully crafted execution patterns, including distributing malicious actions across processes. These results reveal that <italic>behavioral distinctiveness alone does not guarantee robustness</italic>, especially under adaptive attackers.</p>
<p>More recent work shifts toward intelligent and adaptive evasion. Frameworks such as RansomAI [<xref ref-type="bibr" rid="ref-115">115</xref>] and Animagus [<xref ref-type="bibr" rid="ref-116">116</xref>] demonstrate that ransomware can actively optimize its behavior, either by tuning encryption strategies or mimicking benign I/O patterns, to minimize detection probability. Compared to earlier heuristic evasion, these approaches represent a transition to <italic>learning-driven adversaries</italic>, significantly challenging ML/DL-based detectors.</p>
<p>In response to this, defensive efforts increasingly focus on identifying <italic>invariant signals</italic> that are difficult to conceal, such as the coupling between encryption operations and disk I/O (e.g., [<xref ref-type="bibr" rid="ref-117">117</xref>,<xref ref-type="bibr" rid="ref-118">118</xref>]). Zhao et al. [<xref ref-type="bibr" rid="ref-117">117</xref>] ERW-Radar system integrates contextual correlation, fine-grained content analysis, and adaptive optimization mechanisms, while Guo et al. [<xref ref-type="bibr" rid="ref-118">118</xref>] approach is based on the inherent temporal correlation between encryption computation and disk I/O activity. While these methods improve robustness against mimicry, they rely on assumptions about fundamental encryption behavior, which may be weakened by throttling, partial encryption, or distributed execution.</p>
<p>Finally, recent frameworks (e.g., Minerva [<xref ref-type="bibr" rid="ref-119">119</xref>]) integrate adversarial robustness directly into model design, moving from reactive to <italic>proactive defense</italic>. However, such approaches remain limited by the lack of standardized adversarial benchmarks and comprehensive evaluation under realistic attack conditions.</p>
<p>Overall, the comparison highlights an ongoing arms race: attackers evolve from static obfuscation to adaptive, learning-driven evasion, while defenders shift from heuristic detection to invariant-based and adversarially robust models. The key insight is that robustness cannot be achieved through feature design alone; it requires adversarially aware training, cross-layer signals, and continuous adaptation.</p>
<p><bold>Open Issues:</bold> Adversarial robustness remains a major gap. Detection systems are vulnerable to mimicry, temporal distribution of malicious actions, and feature manipulation. Adversarial training, robustness benchmarks, and evaluation under realistic attack scenarios remain limited, while poisoning and model-extraction threats are underexplored. These challenges correspond to <bold>C2</bold> (adversarial robustness) and <bold>C3</bold> (generalization).</p>
<p><xref ref-type="table" rid="table-5">Table 5</xref> provides a summary of common ransomware evasion strategies and representative defensive countermeasures. <xref ref-type="table" rid="table-6">Table 6</xref> provides a mapping of some of the ransomware evasion studies, to adversarial ML threat models.</p>
<table-wrap id="table-5">
<label>Table 5</label>
<caption>
<title>Summary of common ransomware evasion strategies and representative defensive countermeasures.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Evasion Strategy</th>
<th>Description</th>
<th>Representative Defense Measures</th>
</tr>
</thead>
<tbody>
<tr>
<td>Multi-process cooperation</td>
<td>Distributing malicious activities across multiple benign-looking processes to suppress strong behavioral signals</td>
<td>Cross-process correlation, contextual behavior aggregation</td>
</tr>
<tr>
<td>Benign behavior imitation</td>
<td>Mimicking I/O and execution patterns of legitimate applications to hide encryption activity</td>
<td>Fine-grained content analysis, invariant-based detection</td>
</tr>
<tr>
<td>Adaptive encryption scheduling</td>
<td>Dynamically adjusting encryption rate, duration, and algorithm to avoid triggering detectors</td>
<td>Temporal correlation between computation and I/O</td>
</tr>
<tr>
<td>Reinforcement learning-driven evasion</td>
<td>Learning optimal attack policies through feedback from detection outcomes</td>
<td>Robust-by-design models, adversarially trained detectors</td>
</tr>
<tr>
<td>Statistical camouflage</td>
<td>Producing encrypted outputs that resemble benign file modifications in size and access patterns</td>
<td>Byte distribution analysis, <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:msup><mml:mi>&#x03C7;</mml:mi><mml:mn>2</mml:mn></mml:msup></mml:math></inline-formula> tests</td>
</tr>
<tr>
<td>Assumption breaking</td>
<td>Exploiting outdated detection assumptions (e.g., single-process, burst encryption)</td>
<td>Adaptive thresholds, continual model updating</td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-6">
<label>Table 6</label>
<caption>
<title>Mapping ransomware evasion studies to adversarial ML threat models.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Work</th>
<th>Primary Technique</th>
<th>Threat Model</th>
<th>Key Insight</th>
</tr>
</thead>
<tbody>
<tr>
<td>Beaman et al. [<xref ref-type="bibr" rid="ref-113">113</xref>] (2021)</td>
<td>Custom ransomware engineering</td>
<td>Evasion</td>
<td>Commercial anti-virus solutions remain vulnerable to handcrafted evasive logic</td>
</tr>
<tr>
<td>De Gaspari et al. [<xref ref-type="bibr" rid="ref-114">114</xref>] (2022)</td>
<td>Multi-process workload splitting</td>
<td>Evasion, Mimicry</td>
<td>Behavioral features can be neutralized via coordinated benign-looking processes</td>
</tr>
<tr>
<td>von der Assen et al. [<xref ref-type="bibr" rid="ref-115">115</xref>] (2023)</td>
<td>Reinforcement learning-based encryption control</td>
<td>Adaptive Learning</td>
<td>Attackers can learn optimal stealth policies against deployed detectors</td>
</tr>
<tr>
<td>Zhou et al. [<xref ref-type="bibr" rid="ref-116">116</xref>] (2023)</td>
<td>Imitation of benign I/O behavior</td>
<td>Mimicry</td>
<td>Behavior-based detectors fail when ransomware emulates legitimate workflows</td>
</tr>
<tr>
<td>Zhao et al. [<xref ref-type="bibr" rid="ref-117">117</xref>] (2025)</td>
<td>I/O repetitiveness and content statistics</td>
<td>Evasion (Defense-Oriented)</td>
<td>Invariant properties of encryption can expose evasive ransomware</td>
</tr>
<tr>
<td>Guo et al. [<xref ref-type="bibr" rid="ref-118">118</xref>] (2025)</td>
<td>Temporal correlation of encryption and I/O</td>
<td>Evasion (Defense-Oriented)</td>
<td>Temporal invariants remain effective despite behavioral camouflage</td>
</tr>
<tr>
<td>Hitaj et al. [<xref ref-type="bibr" rid="ref-119">119</xref>] (2025)</td>
<td>Robust-by-design architecture</td>
<td>Evasion, Adaptive Learning</td>
<td>Adversarial resilience must be embedded at model and feature levels</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>In contrast, semi-supervised, zero-shot, and drift-aware approaches attempt to address the limitations of static models by improving adaptability to unseen and evolving threats. However, these methods shift the challenge from feature design to <italic>representation reliability and data realism</italic>, and they remain sensitive to distribution bias and adversarial drift.</p>
<p>Overall, the comparison highlights a fundamental insight: no single approach is sufficient under realistic ransomware threat models. Instead, effective defense requires a cross-layer, adaptive framework that combines complementary strengths&#x2013;early detection (behavioral), pattern learning (ML/DL), resilience (storage), and adaptability (semi-supervised/zero-shot/drift-aware)&#x2013;while explicitly accounting for adversarial behavior, dataset limitations, and deployment constraints.</p>
</sec>
<sec id="s4_1_9">
<label>4.1.9</label>
<title>Research on Cryptocurrency Address Identification and Transaction Analysis</title>
<p>Ransomware operators exploit the pseudonymity of cryptocurrencies to conduct difficult-to-trace financial transactions, motivating research on identifying attacker-controlled addresses and analyzing transaction flows. Existing approaches can be broadly categorized into <italic>heuristic/graph-based analysis</italic>, <italic>learning-based detection</italic>, and <italic>ecosystem-level studies</italic>, each offering different trade-offs between interpretability, scalability, and attribution accuracy.</p>
<p>Early works (e.g., [<xref ref-type="bibr" rid="ref-120">120</xref>&#x2013;<xref ref-type="bibr" rid="ref-122">122</xref>]) rely on address clustering heuristics and transaction graph analysis to quantify ransomware payments and identify attacker-controlled entities. These methods provide valuable macro-level insights into the economic structure of ransomware campaigns and are relatively interpretable, but depend on simplifying assumptions about address reuse and transaction patterns, limiting their robustness under evasion techniques.</p>
<p>More recent approaches adopt learning-based frameworks (e.g., [<xref ref-type="bibr" rid="ref-61">61</xref>,<xref ref-type="bibr" rid="ref-123">123</xref>]) to improve scalability and generalization. By leveraging graph-based feature aggregation and semi-supervised or imbalance-aware learning, these methods can detect both known and previously unseen ransomware-related transactions. Compared to heuristic approaches, they offer improved detection performance, but are highly dependent on labeled data quality, graph construction accuracy, and feature design, and may suffer from reduced interpretability.</p>
<p>A complementary line of work focuses on ecosystem-level analysis (e.g., [<xref ref-type="bibr" rid="ref-124">124</xref>]), integrating blockchain data with incident-level and economic information to study long-term trends such as payment behaviors and double-extortion strategies. While these approaches provide broader contextual understanding, they are less suited for real-time detection and rely on aggregated or delayed data.</p>
<p>Overall, the comparison reveals a key trade-off: heuristic methods are interpretable but brittle, learning-based methods are scalable but data-dependent, and ecosystem-level analyses are comprehensive but largely retrospective. A fundamental limitation across all approaches is the difficulty of linking pseudonymous blockchain activity to real-world actors, particularly in the presence of mixers, cross-chain transactions, and privacy-enhancing techniques.</p>
<p><bold>Open Issues:</bold> Accurate attribution remains challenging due to obfuscation techniques such as mixers, tumblers, and cross-chain transfers. The lack of high-quality labeled datasets and limited visibility into off-chain transactions further constrain detection and forensic analysis. These issues correspond to <bold>C1</bold> (data limitations) and <bold>C9</bold> (economic and policy factors).</p>
</sec>
<sec id="s4_1_10">
<label>4.1.10</label>
<title>Critical Insights and Lessons Learned from Research Works on Ransomware Detection</title>
<p><bold>Critical Insights and Lessons Learned:</bold> A comparative analysis of existing ransomware detection approaches reveals several important trends, contradictions, and unresolved limitations across the literature. First, although many ML- and DL-based approaches report very high detection accuracy, these results are often obtained using curated, static, and highly imbalanced datasets under controlled laboratory settings. In contrast, studies that evaluate models under more realistic conditions&#x2013;such as temporal drift, cross-family testing, or zero-day scenarios&#x2013;typically report substantially lower robustness and generalization capability. This suggests that the apparent superiority of many learning-based methods may partly reflect dataset bias and experimental design rather than true operational effectiveness.</p>
<p>Second, there exists a clear contradiction between early-detection objectives and stealth-resistant detection requirements. Several behavioral and runtime-monitoring approaches assume that ransomware exhibits rapid and observable pre-encryption activities such as burst file modifications, entropy changes, or intensive API calls. However, recent ransomware families increasingly adopt delayed execution, partial encryption, intermittent encryption, and low-and-slow strategies specifically designed to evade such assumptions. As a result, approaches optimized for rapid detection may suffer from high false positives, whereas more conservative systems often detect the attack too late to prevent significant damage. This highlights a fundamental trade-off between detection speed, accuracy, and damage prevention.</p>
<p>Third, cross-study comparison shows that no single detection paradigm provides comprehensive coverage against the evolving ransomware threat landscape. Behavioral approaches capture runtime anomalies but are sensitive to workload variability; network-based methods can identify C&#x0026;C communication but may fail against offline or encrypted attacks; memory- and storage-level techniques can detect low-level malicious activities but often incur deployment overhead; and ML/DL methods are effective at pattern recognition yet remain vulnerable to adversarial evasion, poisoning, and feature manipulation attacks. Collectively, these findings indicate that ransomware defense cannot rely on a single-layer solution and instead requires cross-layer, multi-modal, and adaptive frameworks that combine host-, network-, memory-, and storage-level visibility.</p>
<p>Another important insight is the growing gap between research prototypes and deployment feasibility. Many studies optimize primarily for detection performance while overlooking practical operational constraints such as latency, computational overhead, scalability, privacy concerns, explainability, interoperability, and false alarm management. This issue becomes even more pronounced in resource- constrained environments such as IoT, IIoT, CPS, and edge systems, where heavyweight monitoring and complex deep learning models may not be practical. Furthermore, explainability and analyst trust remain underexplored despite their importance in operational SOC and incident response environments.</p>
<p>Finally, current evaluation methodologies remain fragmented and inconsistent across studies. Different works use different datasets, feature sets, attack scenarios, and performance metrics, making direct comparison difficult. Moreover, many evaluations ignore adversarial settings, longitudinal behavior changes, and realistic deployment conditions. These inconsistencies hinder reproducibility and may inflate perceived effectiveness. Overall, the surveyed literature suggests that future ransomware detection systems must move beyond isolated accuracy-driven designs toward robust, adaptive, deployment-aware, and explainable solutions evaluated using realistic, standardized, and continuously updated benchmarks.</p>
<p><xref ref-type="table" rid="table-7">Table 7</xref> presents a classification of the ransomware detection approaches, along with the detection principle used with representative references, discussed in this subsection.</p>
<table-wrap id="table-7">
<label>Table 7</label>
<caption>
<title>Summary of detection-focused ransomware research.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Category</th>
<th>Detection Principle</th>
<th>Representative References</th>
</tr>
</thead>
<tbody>
<tr>
<td>Behavioral/Runtime Detection (Host-Based)</td>
<td>Detect abnormal runtime behavior via file I/O, entropy, API calls, registry or kernel activity</td>
<td>Scaife et al. [<xref ref-type="bibr" rid="ref-26">26</xref>] (2016); Kharaz et al. [<xref ref-type="bibr" rid="ref-27">27</xref>] (2016); Chen and Bridges [<xref ref-type="bibr" rid="ref-28">28</xref>] (2017); Homayoun et al. [<xref ref-type="bibr" rid="ref-29">29</xref>] (2017); Hampton et al. [<xref ref-type="bibr" rid="ref-30">30</xref>] (2018); Kok et al. [<xref ref-type="bibr" rid="ref-31">31</xref>] (2019); Kok et al. [<xref ref-type="bibr" rid="ref-32">32</xref>] (2022); Hwang et al. [<xref ref-type="bibr" rid="ref-33">33</xref>] (2020); Ullah et al. [<xref ref-type="bibr" rid="ref-34">34</xref>] (2020); Molina et al. [<xref ref-type="bibr" rid="ref-35">35</xref>] (2021); Herrera-Silva and Hern&#x00E1;ndez-&#x00C1;lvarez [<xref ref-type="bibr" rid="ref-36">36</xref>]; Javaheri et al. [<xref ref-type="bibr" rid="ref-37">37</xref>] (2018); Zhang et al. [<xref ref-type="bibr" rid="ref-38">38</xref>] (2024); Tang et al. [<xref ref-type="bibr" rid="ref-39">39</xref>] (2020); McIntosh et al. [<xref ref-type="bibr" rid="ref-40">40</xref>] (2021); Al Sabeh et al. [<xref ref-type="bibr" rid="ref-41">41</xref>] (2020); Ramesh and Menen [<xref ref-type="bibr" rid="ref-42">42</xref>] (2020); Abbasi et al. [<xref ref-type="bibr" rid="ref-43">43</xref>] (2022); Ayub et al. [<xref ref-type="bibr" rid="ref-44">44</xref>]; Hou et al. [<xref ref-type="bibr" rid="ref-45">45</xref>] (2024); Marcinkowski et al. [<xref ref-type="bibr" rid="ref-46">46</xref>] (2024); Wang et al. [<xref ref-type="bibr" rid="ref-47">47</xref>] (2024)</td>
</tr>
<tr>
<td>Machine Learning-Based Detection (Classical)</td>
<td>Supervised ML models using static, dynamic, or hybrid features</td>
<td>Zhang et al. [<xref ref-type="bibr" rid="ref-48">48</xref>] (2019); Su et al. [<xref ref-type="bibr" rid="ref-49">49</xref>] (2018); Cohen and Nissim [<xref ref-type="bibr" rid="ref-50">50</xref>] (2018); Ahmed et al. [<xref ref-type="bibr" rid="ref-52">52</xref>] (2020); Khan et al. [<xref ref-type="bibr" rid="ref-53">53</xref>] (2020); Arabo et al. [<xref ref-type="bibr" rid="ref-54">54</xref>] (2020); Jain et al. [<xref ref-type="bibr" rid="ref-55">55</xref>] (2025); Poudyal and Dasgupta [<xref ref-type="bibr" rid="ref-57">57</xref>] (2021); Iqbal et al. [<xref ref-type="bibr" rid="ref-58">58</xref>] (2022); Ba&#x2019;abbad and Batarfi [<xref ref-type="bibr" rid="ref-59">59</xref>] (2023); Jemal and Lo [<xref ref-type="bibr" rid="ref-60">60</xref>] (2023); Rios-Ochoa et al. [<xref ref-type="bibr" rid="ref-62">62</xref>] (2025)</td>
</tr>
<tr>
<td>Deep/Representation Learning-Based Detection</td>
<td>CNN, RNN, LSTM, attention, and GAN-based ransomware detection</td>
<td>Hwang et al. [<xref ref-type="bibr" rid="ref-33">33</xref>]; Ullah et al. [<xref ref-type="bibr" rid="ref-34">34</xref>]; Molina et al. [<xref ref-type="bibr" rid="ref-35">35</xref>]; Herrera-Silva and Hern&#x00E1;ndez-&#x00C1;lvarez [<xref ref-type="bibr" rid="ref-36">36</xref>]; Abbasi et al. [<xref ref-type="bibr" rid="ref-43">43</xref>]; Ayub et al. [<xref ref-type="bibr" rid="ref-44">44</xref>]; Aljabri et al. [<xref ref-type="bibr" rid="ref-51">51</xref>]; Fernandez Maimo et al. [<xref ref-type="bibr" rid="ref-56">56</xref>]; Dib et al. [<xref ref-type="bibr" rid="ref-61">61</xref>]; Homayoun et al. [<xref ref-type="bibr" rid="ref-63">63</xref>]; Cen et al. [<xref ref-type="bibr" rid="ref-64">64</xref>]; Ispahany et al. [<xref ref-type="bibr" rid="ref-65">65</xref>]; Zhang et al. [<xref ref-type="bibr" rid="ref-66">66</xref>]; Lachtar et al. [<xref ref-type="bibr" rid="ref-67">67</xref>]; Karbab et al. [<xref ref-type="bibr" rid="ref-68">68</xref>]; Zhang et al. [<xref ref-type="bibr" rid="ref-69">69</xref>]; Gazzan and Sheldon [<xref ref-type="bibr" rid="ref-70">70</xref>]; Zhu et al. [<xref ref-type="bibr" rid="ref-71">71</xref>]; Ganfure et al. [<xref ref-type="bibr" rid="ref-72">72</xref>]; Thummapudi et al. [<xref ref-type="bibr" rid="ref-73">73</xref>]; Lan et al. [<xref ref-type="bibr" rid="ref-74">74</xref>]; Hossain et al. [<xref ref-type="bibr" rid="ref-75">75</xref>]; Gulmez et al. [<xref ref-type="bibr" rid="ref-76">76</xref>]; Kabuye et al. [<xref ref-type="bibr" rid="ref-77">77</xref>]</td>
</tr>
<tr>
<td>Semi-supervised/Zero-shot</td>
<td>Detect zero-day ransomware and handle behavioral drift</td>
<td>Sharmeen et al. [<xref ref-type="bibr" rid="ref-78">78</xref>] (2020); Urooj et al. [<xref ref-type="bibr" rid="ref-79">79</xref>] (2023); Al-Rimy et al. [<xref ref-type="bibr" rid="ref-80">80</xref>] (2020); Al-Rimy et al. [<xref ref-type="bibr" rid="ref-81">81</xref>] (2021); Cen et al. [<xref ref-type="bibr" rid="ref-82">82</xref>] (2024); Fernando and Komninos [<xref ref-type="bibr" rid="ref-83">83</xref>] (2024)</td>
</tr>
<tr>
<td>Network-Based Detection &#x0026; SDN</td>
<td>Detect ransomware via traffic analysis</td>
<td>Cabaj and Mazurczyk [<xref ref-type="bibr" rid="ref-84">84</xref>] (2016); Cabaj et al. [<xref ref-type="bibr" rid="ref-85">85</xref>]; Akbanov et al. [<xref ref-type="bibr" rid="ref-86">86</xref>] (2019); Morato et al. [<xref ref-type="bibr" rid="ref-87">87</xref>] (2018); Almashhadani et al. [<xref ref-type="bibr" rid="ref-88">88</xref>] (2019); Liu et al. [<xref ref-type="bibr" rid="ref-89">89</xref>] (2020); Hernandez-Jaimes et al. [<xref ref-type="bibr" rid="ref-90">90</xref>] (2024); Pletinckx et al. [<xref ref-type="bibr" rid="ref-91">91</xref>] (2018); Li et al. [<xref ref-type="bibr" rid="ref-92">92</xref>] (2022)</td>
</tr>
<tr>
<td>Ransomware Detection for Mobile and Android Systems</td>
<td>Mobile-specific detection using permissions, user behavior, traffic, and lightweight ML</td>
<td>Song et al. [<xref ref-type="bibr" rid="ref-93">93</xref>] (2016); Chen et al. [<xref ref-type="bibr" rid="ref-94">94</xref>] (2017); Faghihi and Zulkernine [<xref ref-type="bibr" rid="ref-95">95</xref>] (2021); Chew et al. [<xref ref-type="bibr" rid="ref-96">96</xref>] (2024); Ma et al. [<xref ref-type="bibr" rid="ref-97">97</xref>] (2025); Scalas et al. [<xref ref-type="bibr" rid="ref-98">98</xref>] (2019); Alsoghyer and Almomani [<xref ref-type="bibr" rid="ref-99">99</xref>] (2019); Singh and Tripathy [<xref ref-type="bibr" rid="ref-100">100</xref>] (2024); Ahmed et al. [<xref ref-type="bibr" rid="ref-101">101</xref>] (2022); Hossain et al. [<xref ref-type="bibr" rid="ref-102">102</xref>] (2022); Albin Ahmed et al. [<xref ref-type="bibr" rid="ref-103">103</xref>] (2023); Jeremiah et al. [<xref ref-type="bibr" rid="ref-104">104</xref>] (2024); Cimitile et al. [<xref ref-type="bibr" rid="ref-105">105</xref>] (2018); Elkhail et al. [<xref ref-type="bibr" rid="ref-106">106</xref>] (2025);</td>
</tr>
<tr>
<td>IoT/IIoT/CPS/Edge/ Healthcare</td>
<td>Targeted ransomware detection</td>
<td>Fernandez Maimo et al. [<xref ref-type="bibr" rid="ref-56">56</xref>] (2019); Al-Hawawreh et al. [<xref ref-type="bibr" rid="ref-107">107</xref>] (2019); Al-Hawawreh et al. [<xref ref-type="bibr" rid="ref-109">109</xref>] (2021); Celdran et al. [<xref ref-type="bibr" rid="ref-108">108</xref>] (2023); Tariq et al. [<xref ref-type="bibr" rid="ref-110">110</xref>] (2022); Wazid et al. [<xref ref-type="bibr" rid="ref-111">111</xref>] (2022); Malik et al. [<xref ref-type="bibr" rid="ref-112">112</xref>] (2022)</td>
</tr>
<tr>
<td>Adversarial &#x0026; Evasion Analysis</td>
<td>Study evasion strategies that bypass detection mechanisms</td>
<td>Beaman et al. [<xref ref-type="bibr" rid="ref-113">113</xref>] (2021); De Gaspari et al. [<xref ref-type="bibr" rid="ref-114">114</xref>] (2022); von der Assen et al. [<xref ref-type="bibr" rid="ref-115">115</xref>] (2023); Zhou et al. [<xref ref-type="bibr" rid="ref-116">116</xref>] (2023); Zhao et al. [<xref ref-type="bibr" rid="ref-117">117</xref>] (2025); Guo et al. [<xref ref-type="bibr" rid="ref-118">118</xref>] (2025); Hitaj et al. [<xref ref-type="bibr" rid="ref-119">119</xref>] (2025)</td>
</tr>
<tr>
<td>Cryptocurrency Address &#x0026; Transaction Detection</td>
<td>Detect ransomware-related Bitcoin addresses and payments</td>
<td>Dib et al. [<xref ref-type="bibr" rid="ref-61">61</xref>] (2024); Conti et al. [<xref ref-type="bibr" rid="ref-120">120</xref>] (2018); Huang et al. [<xref ref-type="bibr" rid="ref-121">121</xref>] (2018); Paquet-Clouston et al. [<xref ref-type="bibr" rid="ref-122">122</xref>] (2019); Wang et al. [<xref ref-type="bibr" rid="ref-123">123</xref>] (2024); Sarabi et al. [<xref ref-type="bibr" rid="ref-124">124</xref>] (2025)</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><bold>Unified Insights:</bold> <xref ref-type="table" rid="table-8">Table 8</xref> shows that no single defense paradigm is sufficient under realistic ransomware threat models. Behavioral and learning-based methods are valuable for early detection, but they often degrade under stealthy, adaptive, or distribution-shifted attacks. Network-based approaches provide broader visibility but may miss host-local encryption activity, while storage-level and backup-based mechanisms improve resilience yet often operate after some damage has already occurred. These comparisons highlight fundamental trade-offs between accuracy and latency, detection and prevention, interpretability and model complexity, and broad coverage and deployment cost. Consequently, robust ransomware defense requires cross-layer, defense-in-depth designs that combine early detection, damage containment, and recovery support.</p>
<table-wrap id="table-8">
<label>Table 8</label>
<caption>
<title>Comparative analysis of major ransomware defense approaches under realistic threat models.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Approach</th>
<th>Main Strengths</th>
<th>Why It Fails Under Realistic Threat Models</th>
<th>Fundamental Trade-Offs</th>
<th>Typical Best-Fit Use Cases</th>
</tr>
</thead>
<tbody>
<tr>
<td>Behavioral/ Runtime Detection</td>
<td>Can detect previously unseen ransomware by monitoring file I/O, API calls, process behavior, and entropy changes; often effective against fast encryption attacks.</td>
<td>Assumes ransomware exhibits clear pre-encryption or early-encryption behavioral signals. Stealthy, delayed, selective, intermittent, or low-and-slow encryption can reduce detectability. Attackers may also mimic benign backup, compression, or synchronization workloads.</td>
<td>High sensitivity vs. false alarms; early detection vs. runtime overhead; broader monitoring vs. deployability.</td>
<td>Endpoint protection, host monitoring, enterprise desktops, managed servers.</td>
</tr>
<tr>
<td>Classical ML-based Detection</td>
<td>Efficient inference, interpretable feature sets, and suitability for tabular telemetry such as API-call counts, file activity, or registry events.</td>
<td>Relies on handcrafted features that may become brittle under obfuscation, polymorphism, concept drift, and feature manipulation. Performance often drops when evaluated outside the original dataset or environment.</td>
<td>Interpretability and lower latency vs. weaker robustness to drift and adversarial manipulation; simpler models vs. limited expressiveness.</td>
<td>Resource-aware endpoint monitoring, fast screening, operational settings requiring moderate interpretability.</td>
</tr>
<tr>
<td>Deep Learning-based Detection</td>
<td>Can learn complex temporal or structural patterns from raw or minimally processed data; useful for sequence, memory, and traffic analysis.</td>
<td>Requires large, representative labeled datasets and often assumes training data covers realistic future behaviors. Vulnerable to adversarial perturbations, dataset bias, and distribution shift; may be difficult to explain and validate in practice.</td>
<td>Potentially higher accuracy vs. higher computation cost; expressive modeling vs. explainability; robustness vs. training complexity.</td>
<td>High-volume telemetry analysis, cloud-scale monitoring, sequence-based detection, research prototypes with sufficient data.</td>
</tr>
<tr>
<td>Semi-supervised/Zero-shot Detection</td>
<td>Useful when labeled ransomware data are scarce; can improve detection of novel or rare families.</td>
<td>Depends heavily on the quality of unlabeled data, attribute design, or latent representations. Novel attacks that diverge from assumed semantic structure may evade detection; robustness under poisoning or adversarial drift is often unclear.</td>
<td>Novelty detection vs. uncertainty in decision quality; broader coverage vs. reduced reliability and interpretability.</td>
<td>Emerging-threat detection, environments with limited labels, exploratory threat hunting.</td>
</tr>
<tr>
<td>Network-based Detection</td>
<td>Can detect ransomware-related communication, lateral movement, C&#x0026;C traffic, or exfiltration without relying solely on endpoint instrumentation.</td>
<td>Assumes malicious behavior is visible in traffic patterns. Encryption, legitimate cloud services, P2P channels, DNS tunneling, and intermittent communication reduce visibility. Host-only encryption without clear network signals may evade detection entirely.</td>
<td>Broader network visibility vs. weaker host context; lower endpoint overhead vs. higher false positives; detection coverage vs. limited actionability.</td>
<td>Perimeter monitoring, NDR/SOC pipelines, enterprise networks, exfiltration-aware monitoring.</td>
</tr>
<tr>
<td>Storage-level/File-system Defenses</td>
<td>Can directly observe overwrite patterns, block changes, file versioning behavior, and abnormal access bursts; useful for limiting damage and supporting recovery.</td>
<td>Often assumes ransomware performs aggressive overwrite-heavy encryption. Selective encryption, partial corruption, delayed access, or backup targeting can bypass these assumptions. Some methods require kernel, firmware, or storage-stack changes.</td>
<td>Damage containment vs. system complexity; prevention/recovery support vs. portability; lower semantic visibility vs. strong proximity to protected data.</td>
<td>Backup protection, storage appliances, enterprise file servers, high-value data repositories.</td>
</tr>
<tr>
<td>Backup/Recovery-based Defenses</td>
<td>Essential for resilience after compromise; can restore service even when detection fails.</td>
<td>Often assumes backups remain intact, reachable, recent, and untampered. Modern ransomware targets backups, snapshots, and recovery workflows; exfiltration-centric attacks still cause extortion pressure even after restoration.</td>
<td>Recovery assurance vs. storage/management cost; resilience vs. delayed response; continuity vs. inability to prevent theft or initial disruption.</td>
<td>Business continuity planning, disaster recovery, critical infrastructure, regulated environments.</td>
</tr>
<tr>
<td>Deception-based Defenses</td>
<td>Can expose ransomware through interaction with decoys, bait files, honey shares, or controlled traps.</td>
<td>Effectiveness depends on realistic placement and attacker interaction. Sophisticated ransomware may detect decoys, defer execution, or use environment checks to avoid triggering traps.</td>
<td>Low-cost signaling vs. brittleness; early warning vs. incomplete coverage; simplicity vs. maintenance overhead.</td>
<td>Layered defense, early warning systems, environments where decoy placement is manageable.</td>
</tr>
<tr>
<td>Memory-based/Forensic Detection</td>
<td>Can reveal fileless activity, unpacked payloads, injected code, and volatile indicators invisible to static analysis.</td>
<td>Requires sufficient visibility into transient memory artifacts and often continuous or frequent acquisition. Fast execution, anti-forensics, and scale constraints reduce practicality in live environments.</td>
<td>Deep visibility vs. acquisition overhead; forensic richness vs. limited real-time scalability.</td>
<td>Incident response, forensic triage, memory-focused malware analysis.</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Ransomware Prevention, Mitigation, and Recovery-Focused Research Works</title>
<p>This section systematically classifies and categorizes existing research on ransomware prevention, mitigation, and recovery strategies. For each category, we review representative approaches, provide a critical analysis of their underlying techniques and assumptions, and discuss key limitations and open research issues that remain unresolved.</p>
<sec id="s4_2_1">
<label>4.2.1</label>
<title>Research Works Focusing on Storage-Level/Hardware-Assisted Ransomware Defenses</title>
<p>This subsection focuses on storage-level and hardware-assisted defenses against ransomware. These approaches operate below the application and operating-system layers and aim to prevent or limit data loss while enabling efficient recovery. Typical techniques leverage capabilities of solid-state drives (SSDs), block devices, storage firmware, hypervisors, or trusted hardware to detect malicious write patterns, isolate ransomware activity, and support rapid data restoration.</p>
<p>A substantial body of work explores embedding ransomware detection directly within storage devices, particularly SSDs, to detect malicious write patterns and enable rapid recovery. Min et al. [<xref ref-type="bibr" rid="ref-125">125</xref>] introduce Amoeba, an SSD architecture that incorporates a hardware accelerator to identify ransomware-infected pages and maintain fine-grained backup control to reduce storage overhead. Amoeba incurs negligible overhead and significantly outperforms the state-of-the-art SSD, FlashGuard, in both performance and space efficiency. Similarly, Baek et al. [<xref ref-type="bibr" rid="ref-126">126</xref>,<xref ref-type="bibr" rid="ref-127">127</xref>] propose SSD-Insider and its enhanced version SSD-Insider&#x002B;&#x002B;, which leverage invariant behavioral features derived solely from block I/O headers to detect ransomware at the firmware level and exploit NAND flash&#x2019;s delayed deletion property for instant, and lossless recovery. Paik et al. [<xref ref-type="bibr" rid="ref-128">128</xref>] further demonstrate that ransomware-induced access patterns can be detected through specialized buffer management policies within flash-based storage devices. While these SSD-integrated approaches benefit from low latency and independence from the host OS, they rely on modifications to storage firmware or architecture, which may limit portability across commodity hardware platforms.</p>
<p>Other works explore host-level and memory-storage coordination mechanisms to prevent encrypted data from being committed to persistent storage. Elkhail et al. [<xref ref-type="bibr" rid="ref-129">129</xref>] observe that encrypted data typically passes through the OS page cache before being written to disk and propose a runtime defense that intercepts this synchronization process to prevent malicious data from reaching permanent storage; Evaluated against over a thousand ransomware samples, including advanced variants using multi-threading and boot-sector attacks, the system reliably restores affected files while incurring minimal performance overhead. In contrast, Ma et al. [<xref ref-type="bibr" rid="ref-130">130</xref>] introduce RansomTag, a hypervisor-based framework that bridges semantic gaps between storage devices and higher-level system context using a tag-based interface. This design enables accurate detection and fine-grained version recovery of overwritten or deleted files while maintaining modest backup overhead. Compared with firmware-centric SSD solutions, these approaches provide greater deployment flexibility and richer contextual information, though they introduce additional complexity in memory management and virtualization layers.</p>
<p>Recent research also investigates cloud storage environments and hardware-level telemetry as alternative defense layers. Wang et al. [<xref ref-type="bibr" rid="ref-131">131</xref>] propose DeftPunk, a ransomware detection and recovery system designed for cloud block storage, combining a two-layer I/O classifier with snapshot-based recovery mechanisms to minimize data loss in multi-tenant environments. Hill et al. [<xref ref-type="bibr" rid="ref-132">132</xref>] demonstrate that ransomware activity can be detected through hardware performance counters collected from non-virtualized systems, showing that a small subset of hardware-level features can enable rapid detection with high accuracy. Zhu et al. [<xref ref-type="bibr" rid="ref-133">133</xref>] further extend storage-level defenses through their SrFTL system, which integrates semantic awareness into the flash translation layer of SSDs and leverages modified flash translation layer (FTL) with a trusted enclave to perform secure detection and recovery operations; evaluation shows SrFTL outperforms existing FTL-based solutions. Together, these approaches illustrate a shift toward cross-layer defenses that combine storage semantics, hardware telemetry, and trusted execution environments. However, their effectiveness often depends on specialized hardware support, system-level modifications, or close integration with storage infrastructure.</p>
<p><bold>Open Issues:</bold> Storage- and hardware-level defenses often require modifications to firmware or system architecture, limiting deployability across heterogeneous environments. Many approaches assume write-heavy encryption behavior, which can be bypassed by ransomwares by selective or partial encryption strategies. Additionally, semantic gaps between OS, hypervisor, and storage layers hinder coordinated detection and response, particularly in multi-tenant cloud settings. These challenges correspond to <bold>C6</bold> (deployment) and <bold>C7</bold> (cross-layer integration).</p>
</sec>
<sec id="s4_2_2">
<label>4.2.2</label>
<title>Decoy, Honeypot, and Deception-Based Defenses</title>
<p>Deception-based ransomware defenses adopt a &#x201C;lure-and-contain&#x201D; strategy, using decoy files, honeyfolders, or deceptive environments to trigger early detection and limit damage. Unlike ML or behavioral approaches that infer malicious intent, these methods rely on <italic>direct attacker interaction</italic> with crafted artifacts, providing highly interpretable signals but with limited coverage.</p>
<p>Early works (e.g., [<xref ref-type="bibr" rid="ref-134">134</xref>,<xref ref-type="bibr" rid="ref-135">135</xref>]) demonstrate that simple decoy files can effectively expose ransomware through abnormal access patterns or blocking behavior. These methods are lightweight and enable rapid containment, but their effectiveness depends heavily on decoy placement and assumes that ransomware will interact with them.</p>
<p>Subsequent approaches improve robustness through adaptive and multi-functional deception. Systems such as RTrap and Ranflood [<xref ref-type="bibr" rid="ref-136">136</xref>,<xref ref-type="bibr" rid="ref-137">137</xref>] extend decoy strategies with data-driven placement of decoy files, deliberately flooding targeted disk locations with decoy files to slow ransomware progress, moving target files, while other techniques exploit system features (e.g., alternate data streams) to mislead encryption targets. Compared to basic honeypots, these methods enhance coverage and mitigation capability, but introduce higher storage and management overhead.</p>
<p>More recent work moves toward <italic>active deception</italic>, where attackers are not only detected but actively disrupted. Frameworks such as ranDecepter [<xref ref-type="bibr" rid="ref-138">138</xref>], a real-time system that isolates ransomware in a deceptive environment and feeds the ransomware with counterfeit encryption data, increasing attacker cost and delaying impact. Compared to passive approaches, these systems improve resilience but require tighter system integration and careful configuration.</p>
<p>Overall, deception-based defenses exhibit a key trade-off: <italic>precision vs. coverage</italic>. They provide low false positives and interpretable detection signals, but rely on attacker interaction and can be bypassed by ransomware that detects or avoids decoys. Consequently, they are most effective as complementary mechanisms within a broader defense-in-depth strategy rather than standalone solutions.</p>
<p><bold>Open Issues:</bold> Effectiveness depends on realistic decoy placement and configuration, which sophisticated ransomware can not evade. Large-scale deployment introduces management overhead, and limited integration with behavioral or learning-based systems reduces overall robustness. These challenges correspond to <bold>C2</bold> (adversarial adaptation) and <bold>C6</bold> (deployment constraints).</p>
</sec>
<sec id="s4_2_3">
<label>4.2.3</label>
<title>Reverse Engineering and Decryption-Based Ransomware Analysis</title>
<p>Reverse engineering and cryptographic analysis focus on <italic>understanding and breaking ransomware implementations</italic> to enable data recovery, rather than detecting attacks in real time. Compared to behavioral or ML-based methods, these approaches provide deeper insight into malware logic and encryption mechanisms, but are largely <italic>reactive and family-specific</italic>.</p>
<p>Empirical studies (e.g., [<xref ref-type="bibr" rid="ref-139">139</xref>]) show that many existing decryption tools fail in practice, highlighting a gap between claimed and actual recovery effectiveness. In contrast, targeted reverse engineering efforts (e.g., [<xref ref-type="bibr" rid="ref-140">140</xref>]) demonstrate that detailed analysis of specific ransomware families can yield effective decryption solutions, and present tools for reverse-engineering. This contrast underscores a key trade-off: <italic>broad applicability vs. practical effectiveness</italic>.</p>
<p>Another line of work exploits implementation flaws in ransomware cryptography (e.g., [<xref ref-type="bibr" rid="ref-141">141</xref>,<xref ref-type="bibr" rid="ref-142">142</xref>]). These studies show that even ransomware using strong cryptographic primitives can be broken if key-generation or randomness mechanisms are flawed. However, such success depends on the presence of subtle vulnerabilities, making these approaches opportunistic rather than generally applicable.</p>
<p>More recent work integrates reverse engineering with automated detection (e.g., [<xref ref-type="bibr" rid="ref-143">143</xref>]), by extracting features through reverse engineering for static analysis and converts executable binaries into images for deep learning-based classification to support scalable ML pipelines. Compared to pure decryption approaches, these methods improve scalability and generalization, but sacrifice the ability to directly recover data.</p>
<p>Overall, these approaches reveal a fundamental trade-off: <italic>depth vs. generalizability</italic>. Reverse engineering provides strong insight and potential recovery for specific families, but does not scale across evolving ransomware variants. Unlike detection-based methods, they operate post-compromise and depend heavily on implementation weaknesses, limiting their role to complementary forensic and recovery support.</p>
<p><bold>Open Issues:</bold> Effectiveness is limited by strong cryptography and advanced obfuscation, while most solutions remain family-specific and difficult to generalize. Automated analysis lacks scalability against rapidly evolving ransomware. These challenges correspond to <bold>C10</bold> (evolving threats) and <bold>C5</bold> (scalability).</p>
</sec>
<sec id="s4_2_4">
<label>4.2.4</label>
<title>Data Recovery via Backup Integrity and Entropy-Based Restoration</title>
<p>Recovery-focused approaches aim to restore data after compromise, primarily through <italic>entropy-based identification of encrypted files</italic> and <italic>protection of backup integrity</italic>. Unlike detection methods, these approaches are inherently <italic>reactive</italic>, emphasizing resilience rather than prevention.</p>
<p>Entropy-based techniques (e.g., [<xref ref-type="bibr" rid="ref-144">144</xref>,<xref ref-type="bibr" rid="ref-145">145</xref>]) identify encrypted files by detecting statistical randomness and support recovery by locating clean backup versions. While these methods are lightweight and effective for bulk encryption, their reliability depends on distinguishing encrypted data from compressed content and may degrade under selective or partial encryption. Thus, they trade <italic>simplicity and speed</italic> for reduced robustness.</p>
<p>In contrast, backup-integrity&#x2013;focused approaches (e.g., [<xref ref-type="bibr" rid="ref-146">146</xref>]) target the protection of recovery mechanisms themselves by detecting attempts to delete or corrupt backup artifacts. Compared to entropy-based methods, they provide stronger <italic>resilience guarantees</italic> by preserving recovery points, but do not directly identify encrypted data or prevent initial damage.</p>
<p>Overall, these approaches highlight a key distinction: <italic>file-level recovery vs. infrastructure-level protection</italic>. Entropy-based methods facilitate restoration after encryption, while backup-integrity mechanisms ensure that recovery remains possible even under adversarial interference. However, both rely on a critical assumption that backups are intact and accessible, which is increasingly violated by modern ransomware employing backup targeting and data exfiltration.</p>
<p><bold>Open Issues:</bold> Effectiveness of recovery is limited by compromised backups, false positives in entropy-based detection, and evasion via selective encryption. Additionally, poor integration with detection systems and lack of support for partial or semantic recovery reduce practical utility. These challenges correspond to <bold>C8</bold> (recovery and resilience) and <bold>C7</bold> (cross-layer coordination).</p>
</sec>
<sec id="s4_2_5">
<label>4.2.5</label>
<title>Human Factors, Organizational, and Policy Responses</title>
<p>Ransomware response is not purely technical; it is shaped by <italic>economic incentives, human behavior, and policy constraints</italic>. Existing work can be broadly grouped into <italic>economic/strategic analyses</italic>, <italic>organizational and behavioral studies</italic>, and <italic>policy and governance frameworks</italic>, each offering complementary but incomplete perspectives.</p>
<p>Economic and strategic studies (e.g., [<xref ref-type="bibr" rid="ref-147">147</xref>&#x2013;<xref ref-type="bibr" rid="ref-149">149</xref>]) highlight that ransom decisions are driven by cost-benefit trade-offs under uncertainty, where organizations weigh operational disruption, financial loss, and reputational impact. Game-theoretic models (e.g., [<xref ref-type="bibr" rid="ref-150">150</xref>,<xref ref-type="bibr" rid="ref-151">151</xref>]) further show that attacker-victim interactions are shaped by information asymmetry and strategic signaling, especially in double-extortion scenarios. While these approaches provide strong analytical insight, they often simplify real-world constraints and organizational complexity.</p>
<p>In contrast, organizational and behavioral studies (e.g., [<xref ref-type="bibr" rid="ref-152">152</xref>&#x2013;<xref ref-type="bibr" rid="ref-154">154</xref>]) emphasize practical response challenges, including user susceptibility, communication failures, and incident coordination. These works show that effective defense requires <italic>socio-technical integration</italic>, combining technical controls with user awareness and response planning. However, their findings are often context-specific and less generalizable.</p>
<p>Policy and governance research (e.g., [<xref ref-type="bibr" rid="ref-155">155</xref>&#x2013;<xref ref-type="bibr" rid="ref-158">158</xref>]) focuses on risk management, regulatory coordination, and cyber insurance. Compared to technical defenses, these approaches address systemic issues such as incentives and preparedness, but introduce trade-offs: for example, cyber insurance can improve resilience while potentially encouraging ransom payments.</p>
<p>Overall, the comparison reveals a central issue: <italic>analytical optimality vs. real-world practicality</italic>. Economic models provide decision frameworks, behavioral studies capture organizational realities, and policy approaches shape incentives, but none of these is useful as a stand alone approach. Effective ransomware response requires integrating these perspectives with technical defenses in a unified framework.</p>
<p><bold>Open Issues:</bold> Decision-making remains highly uncertain, with limited guidance on ransom payment and negotiation. Misaligned incentives (e.g., insurance and payment dynamics) may encourage attackers, while Small and Medium Enterprises (SMEs) often lack resources for effective response. These challenges correspond to <bold>C9</bold> (economic and policy factors).</p>
<p><xref ref-type="fig" rid="fig-3">Fig. 3</xref> illustrates a cross-layer ransomware defense architecture in which telemetry from host, network, storage, and organizational layers is analyzed both locally and jointly. Behavioral analytics, ML/DL-based scoring, and deception- or storage-oriented mechanisms feed a central correlation engine that interacts with SIEM/EDR/NDR components and an automated response orchestrator. This design reflects a defense-in-depth philosophy: host-level monitoring supports early execution-stage detection, network-level analytics improve visibility into C&#x0026;C and exfiltration, storage-level defenses help contain encryption damage, and recovery mechanisms provide resilience when prevention fails. The feedback loop is critical for long-term robustness, since ransomware tactics evolve rapidly and require continuous model updates, rule refinement, and policy adaptation.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Cross-layer ransomware defense architecture showing how host, network, storage, and organizational defenses interact through shared analytics, correlation, response orchestration, and feedback-driven adaptation.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="JCS_82741-fig-3.tif"/>
</fig>
<p>On the other hand, <xref ref-type="fig" rid="fig-4">Fig. 4</xref> presents a cross-layer view of ransomware defense, integrating technical, economic, and human/policy dimensions into a unified response framework. At the top layer, technical defenses&#x2013;such as advanced detection mechanisms, deception detection strategies, hardware-assisted protection, and backup/recovery systems&#x2013;provide the core capability for identifying and mitigating attacks. However, these mechanisms alone are insufficient, as reflected in the middle layer, where economic constraints and human/policy factors shape real-world decision-making. Organizations must balance cost-benefit considerations, cyber insurance incentives, user awareness, and regulatory requirements, often under uncertainty, as highlighted by the central &#x201C;decision dilemmas&#x201D; (e.g., whether to pay or resist). The bottom layer emphasizes that effective ransomware defense ultimately depends on coordinated response, combining incident management, risk mitigation, and continuous adaptation across all layers. The key insight is that ransomware defense is not purely a technical problem but a socio-technical challenge, where robust protection emerges only through tight integration of detection technologies, economic incentives, and human-centered policies.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Cross-layer view of ransomware defense, integrating technical, economic, and human/policy dimensions into a unified response framework.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="JCS_82741-fig-4.tif"/>
</fig>
</sec>
<sec id="s4_2_6">
<label>4.2.6</label>
<title>Game-Theoretic, Economic, and Policy Analysis of Ransomware</title>
<p>Ransomware can be viewed as an <italic>economic ecosystem</italic> driven by incentives, strategic interactions, and market structures. Existing work can be broadly grouped into <italic>economic analyses</italic>, <italic>game-theoretic models</italic>, <italic>ecosystem/market studies</italic>, and <italic>policy/governance perspectives</italic>, each capturing different facets of the ransomware economy.</p>
<p>Economic analyses (e.g., [<xref ref-type="bibr" rid="ref-159">159</xref>,<xref ref-type="bibr" rid="ref-160">160</xref>]) highlight that ransomware profitability is driven by weak organizational preparedness and the ability of attackers to optimize ransom pricing, including price discrimination across victims. These studies emphasize that ransomware persists because it is <italic>economically viable</italic>, but they often abstract away operational complexities.</p>
<p>Game-theoretic models (e.g., [<xref ref-type="bibr" rid="ref-161">161</xref>&#x2013;<xref ref-type="bibr" rid="ref-163">163</xref>]) formalize attacker-victim interactions, showing how decisions on payment, prevention, and negotiation depend on incentives, information asymmetry, and expected losses. Compared to empirical studies, they provide analytical insights into optimal strategies, but rely on simplifying assumptions that may not capture real-world uncertainty and multi-stage attack dynamics.</p>
<p>Ecosystem-level studies (e.g., [<xref ref-type="bibr" rid="ref-164">164</xref>&#x2013;<xref ref-type="bibr" rid="ref-167">167</xref>]) reveal that modern ransomware operates as a structured market, particularly through Ransomware-as-a-Service (RaaS) models, with affiliate-based operations, revenue sharing, and laundering mechanisms. These works provide realistic views of attacker operations, but are largely descriptive and less predictive.</p>
<p>Policy and governance research (e.g., [<xref ref-type="bibr" rid="ref-168">168</xref>&#x2013;<xref ref-type="bibr" rid="ref-170">170</xref>]) addresses regulatory responses, attribution challenges, and the role of institutions. Compared to technical defenses, these approaches target systemic incentives, but face difficulties due to limited visibility, evolving attacker identities, and enforcement challenges.</p>
<p>Overall, the comparison highlights a key tension: <italic>analytical insight vs. real-world complexity</italic>. Economic and game-theoretic models explain incentives, ecosystem studies capture operational realities, and policy approaches shape responses, but none alone provides a complete solution. Effective mitigation requires aligning incentives across technical, organizational, and regulatory layers.</p> 
<p><bold>Open Issues:</bold> Existing models rely on simplified assumptions and limited empirical data, particularly for ransom payments and negotiation dynamics. The rise of RaaS further complicates incentive structures and attribution. These challenges correspond to <bold>C9</bold> (economic factors).</p>
</sec>
<sec id="s4_2_7">
<label>4.2.7</label>
<title>Foundational, Taxonomy, and Benchmarking Studies</title>
<p>This body of work provides cross-cutting perspectives on ransomware, including <italic>evolution analysis, taxonomies, datasets, and benchmarking frameworks</italic>. Unlike detection-specific studies, these efforts aim to structure the problem space, enable reproducibility, and provide broader contextual understanding.</p>
<p>Early studies (e.g., [<xref ref-type="bibr" rid="ref-171">171</xref>&#x2013;<xref ref-type="bibr" rid="ref-175">175</xref>]) focus on the evolution of ransomware and its economic and technical drivers, highlighting why traditional defenses fail and emphasizing the need for specialized, proactive strategies. These works provide foundational insight but are largely descriptive and limited in methodological rigor.</p>
<p>Taxonomy-driven research (e.g., [<xref ref-type="bibr" rid="ref-176">176</xref>&#x2013;<xref ref-type="bibr" rid="ref-178">178</xref>]) introduces structured models of ransomware behavior and attack lifecycles. Compared to early descriptive studies, these frameworks enable systematic analysis and mapping of defenses, but often remain static and may not fully capture rapidly evolving attack strategies.</p>
<p>A complementary line of work focuses on datasets and experimental platforms (e.g., [<xref ref-type="bibr" rid="ref-179">179</xref>&#x2013;<xref ref-type="bibr" rid="ref-182">182</xref>]), providing benchmarks for evaluating detection methods. These contributions improve reproducibility and facilitate comparative evaluation, but their effectiveness is constrained by dataset realism and coverage of modern attack behaviors.</p>
<p>Other studies propose context-specific frameworks (e.g., [<xref ref-type="bibr" rid="ref-183">183</xref>&#x2013;<xref ref-type="bibr" rid="ref-185">185</xref>]) tailored to particular environments such as enterprise systems or IoT, highlighting the need for domain-aware defenses. Finally, meta-analyses (e.g., [<xref ref-type="bibr" rid="ref-186">186</xref>,<xref ref-type="bibr" rid="ref-187">187</xref>]) reveal research trends, notably the dominance of detection-focused approaches and the relative lack of work on proactive and predictive defenses.</p>
<p>Overall, the comparison highlights a key progression: <italic>descriptive analyses <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula> structured taxonomies <inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula> benchmark-driven evaluation</italic>. While these studies provide essential foundations and standardization, they remain limited by static models, outdated datasets, and insufficient alignment with evolving ransomware behaviors.</p>
<p><bold>Open Issues:</bold> Existing datasets fail to capture the complexity of modern attacks, particularly regarding scale and diversity. Without standardized evaluation frameworks or longitudinal benchmarks, it remains difficult to ensure reproducibility or conduct fair performance comparisons across the field.</p>
</sec>
<sec id="s4_2_8">
<label>4.2.8</label>
<title>Emerging Ransomware Threat Models and Novel Attack Vectors</title>
<p>Recent research shows that ransomware is evolving beyond traditional file-encryption attacks toward <italic>multi-stage, cross-layer, and non-traditional threat models</italic>. The threat landscape encompasses hardware-level vulnerabilities, web-based infection vectors, and fileless execution techniques. Additionally, modern campaigns frequently combine encryption with data exfiltration and multi-layered extortion strategies.</p>
<p>Hardware- and storage-level studies (e.g., [<xref ref-type="bibr" rid="ref-188">188</xref>,<xref ref-type="bibr" rid="ref-189">189</xref>]) demonstrate that ransomware can operate below the OS layer, exploiting hardware trojans or SSD internals. Compared to software-based attacks, these approaches are more stealthy and harder to detect, but require specialized attacker capabilities, highlighting a trade-off between <italic>attack stealth and feasibility</italic>.</p>
<p>In contrast, web- and automation-based attacks (e.g., [<xref ref-type="bibr" rid="ref-190">190</xref>,<xref ref-type="bibr" rid="ref-191">191</xref>]) exploit modern browser APIs and automation frameworks to encrypt data without traditional malware installation. These methods significantly expand the attack surface, trading <italic>ease of deployment for reduced persistence and control</italic>.</p>
<p>Other works redefine ransomware threat models to account for fileless, human-operated, and exfiltration-driven attacks (e.g., [<xref ref-type="bibr" rid="ref-192">192</xref>,<xref ref-type="bibr" rid="ref-193">193</xref>]). Compared to earlier models that focus on encryption behavior, these frameworks emphasize <italic>multi-stage attack chains and cross-layer coordination</italic>, highlighting the limitations of detection systems built on outdated assumptions.</p>
<p>Finally, domain-specific studies (e.g., [<xref ref-type="bibr" rid="ref-194">194</xref>]) show that ransomware increasingly targets critical infrastructure, where attacks involve prolonged dwell time and complex system interactions. These environments require <italic>sector-specific defenses and forensic capabilities</italic>, rather than generic detection approaches.</p>
<p>Overall, the comparison reveals a fundamental shift: <italic>from single-stage encryption attacks to adaptive, cross-layer, and hybrid threat models</italic>. While new attack vectors improve stealth and impact, they also expose gaps in existing defenses, which remain largely focused on traditional behavioral or file-based indicators.</p>
<p><bold>Open Issues:</bold> Modern ransomware combines exfiltration, fileless execution, and cross-layer techniques across cloud, browser, and hardware platforms. Existing defenses struggle to handle such hybrid, multi-stage attacks, highlighting the need for integrated and adaptive detection frameworks. These challenges correspond to <bold>C10</bold> (emerging threat models) and <bold>C7</bold> (cross-layer coordination).</p>
</sec>
<sec id="s4_2_9">
<label>4.2.9</label>
<title>Proactive Prevention via File Perturbation and OS Hardening</title>
<p>Proactive defenses aim to <italic>prevent encryption before it occurs</italic> by disrupting ransomware&#x2019;s ability to locate or access valuable data. Unlike detection-based methods, these approaches focus on <italic>attack surface manipulation</italic> rather than identifying malicious behavior.</p>
<p>File perturbation and moving-target strategies (e.g., [<xref ref-type="bibr" rid="ref-195">195</xref>&#x2013;<xref ref-type="bibr" rid="ref-197">197</xref>]) randomize file extensions, hide file locations, or dynamically alter system visibility to confuse ransomware during reconnaissance and encryption phases. Compared to reactive defenses, these methods can reduce attack success without requiring detection, but rely on the assumption that ransomware uses predictable file discovery mechanisms.</p>
<p>Overall, these approaches highlight a key trade-off: <italic>prevention vs. usability</italic>. While they can significantly disrupt ransomware workflows, they may introduce compatibility issues and user overhead, and can be bypassed by adaptive malware performing deeper file-system inspection.</p>
<p><bold>Open Issues:</bold> Effectiveness is limited by usability constraints and attacker adaptation. Real-world scalability remains underexplored, and integration with detection mechanisms is limited. These challenges correspond to <bold>C6</bold> (deployment constraints).</p>
</sec>
<sec id="s4_2_10">
<label>4.2.10</label>
<title>Healthcare/Operational Impact Studies of Ransomware Attacks</title>
<p>Several studies examine the real-world operational and clinical consequences of ransomware attacks on healthcare organizations. Zhao et al. [<xref ref-type="bibr" rid="ref-198">198</xref>] present an early case study of a ransomware incident affecting a trauma center, demonstrating how disruptions to hospital information systems can significantly impair clinical workflows and delay patient care. Expanding this perspective, Neprash et al. [<xref ref-type="bibr" rid="ref-199">199</xref>] conduct a large-scale cohort analysis of 374 ransomware incidents affecting healthcare delivery organizations between 2016 and 2021. Their study reveals that ransomware attacks more than doubled during this period and exposed the personal health information of nearly 42 million patients, with increasingly large healthcare systems becoming primary targets. Complementing these findings, Dameff et al. [<xref ref-type="bibr" rid="ref-200">200</xref>] analyze the indirect operational consequences of a prolonged ransomware attack by examining patient flow data from two nearby emergency departments that were not directly targeted. Their analysis shows significant increases in patient volume, ambulance arrivals, wait times, emergency service diversion, and delays in critical treatments such as stroke care; These studies provide empirical evidence that ransomware attacks can cause widespread operational disruption within healthcare systems, affecting not only targeted facilities but also surrounding medical institutions and ultimately impacting patient safety and quality of care.</p>
<p><bold>Open Issues:</bold> Empirical studies on ransomware impact in critical sectors remain limited, and the effects on operational continuity and patient outcomes are difficult to quantify. Inconsistent reporting and reliance on legacy infrastructure further complicate risk assessment and resilience planning. These limitations correspond to <bold>C1</bold> (data gaps) and <bold>C6</bold> (deployment challenges).</p>
<p><xref ref-type="table" rid="table-9">Table 9</xref> summarizes prevention-, mitigation-, and recovery-focused ransomware research, along with their corresponding defense/recovery mechanisms and representative references. On the other hand, <xref ref-type="table" rid="table-10">Table 10</xref> provides a multi-dimensional view of ransomware research across three critical dimensions: threat models, defense layers, and adversarial capabilities.</p>
<table-wrap id="table-9">
<label>Table 9</label>
<caption>
<title>Summary of prevention, mitigation, and recovery-focused ransomware research.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Category</th>
<th>Defense/Recovery Strategy</th>
<th>Representative References</th>
</tr>
</thead>
<tbody>
<tr>
<td>Storage-Level/Hardware- Assisted Defense</td>
<td>Prevent data loss and enable recovery using SSDs, block devices, firmware, or hypervisors</td>
<td>Min et al. [<xref ref-type="bibr" rid="ref-125">125</xref>] (2018); Baek et al. [<xref ref-type="bibr" rid="ref-126">126</xref>] (2018); Baek et al. [<xref ref-type="bibr" rid="ref-127">127</xref>] (2020); Paik et al. [<xref ref-type="bibr" rid="ref-128">128</xref>] (2018); Elkhail et al. [<xref ref-type="bibr" rid="ref-129">129</xref>] (2023); Elkhail et al. [<xref ref-type="bibr" rid="ref-130">130</xref>] (2023); Wang et al. [<xref ref-type="bibr" rid="ref-131">131</xref>] (2024); Hill et al. [<xref ref-type="bibr" rid="ref-132">132</xref>] (2024); Zhu et al. [<xref ref-type="bibr" rid="ref-133">133</xref>] (2025)</td>
</tr>
<tr>
<td>Decoy, Honeypot &#x0026; Deception-Based Defense</td>
<td>Lure and contain ransomware using decoy files, honeyfolders, and deceptive environments</td>
<td>Gomez-Hernandez et al. [<xref ref-type="bibr" rid="ref-134">134</xref>] (2018); Chakkaravarthy et al. [<xref ref-type="bibr" rid="ref-135">135</xref>] (2020); Ganfure et al. [<xref ref-type="bibr" rid="ref-136">136</xref>] (2023); Berardi et al. [<xref ref-type="bibr" rid="ref-137">137</xref>] (2023); Sajid et al. [<xref ref-type="bibr" rid="ref-138">138</xref>] (2025)</td>
</tr>
<tr>
<td>Reverse Engineering &#x0026; Decryption</td>
<td>Analyze encryption schemes and recover encrypted data</td>
<td>Filiz et al. [<xref ref-type="bibr" rid="ref-139">139</xref>] (2021); Yuste et al. [<xref ref-type="bibr" rid="ref-140">140</xref>] (2021); Kim et al. [<xref ref-type="bibr" rid="ref-141">141</xref>] (2022); Kim et al. [<xref ref-type="bibr" rid="ref-142">142</xref>] (2025); Almomani et al. [<xref ref-type="bibr" rid="ref-143">143</xref>] (2023); Hou et al. [<xref ref-type="bibr" rid="ref-146">146</xref>] (2025)</td>
</tr>
<tr>
<td>Backup, Key Management &#x0026; File Recovery</td>
<td>Recover encrypted data via secure backups, key escrow, or entropy-based restoration</td>
<td>Lee et al. [<xref ref-type="bibr" rid="ref-144">144</xref>] (2019); Davies et al. [<xref ref-type="bibr" rid="ref-145">145</xref>] (2021)</td>
</tr>
<tr>
<td>Human factors, Organizational &#x0026; Policy Responses</td>
<td>Ransom decision-making, negotiation strategies, insurance, and governance</td>
<td>Everett et al. [<xref ref-type="bibr" rid="ref-147">147</xref>] (2016); Mansfield-Devine et al. [<xref ref-type="bibr" rid="ref-148">148</xref>] (2016); Connolly et al. [<xref ref-type="bibr" rid="ref-149">149</xref>] (2022); Ryan et al. [<xref ref-type="bibr" rid="ref-150">150</xref>] (2022); Meurs et al. [<xref ref-type="bibr" rid="ref-151">151</xref>] (2024); Zhang-Kennedy et al. [<xref ref-type="bibr" rid="ref-152">152</xref>] (2018); Connolly et al. [<xref ref-type="bibr" rid="ref-153">153</xref>] (2019); Thomas et al. [<xref ref-type="bibr" rid="ref-154">154</xref>] (2018); Hayes et al. [<xref ref-type="bibr" rid="ref-155">155</xref>] (2021); Bekkers et al. [<xref ref-type="bibr" rid="ref-156">156</xref>] (2023); Mott et al. [<xref ref-type="bibr" rid="ref-157">157</xref>] (2023); Bajpai et al. [<xref ref-type="bibr" rid="ref-158">158</xref>] (2023)</td>
</tr>
<tr>
<td>Game-Theoretic, Economic &#x0026; Policy Analysis &#x0026; RaaS Analysis</td>
<td>Analyze ransomware business models, payments, and underground markets</td>
<td>Simmonds et al. [<xref ref-type="bibr" rid="ref-159">159</xref>] (2017); Hernandez-Castro et al. [<xref ref-type="bibr" rid="ref-160">160</xref>] (2020); Cartwright et al. [<xref ref-type="bibr" rid="ref-161">161</xref>] (2019); Zhang et al. [<xref ref-type="bibr" rid="ref-162">162</xref>] (2022); Li et al. [<xref ref-type="bibr" rid="ref-163">163</xref>] (2022); Meland et al. [<xref ref-type="bibr" rid="ref-164">164</xref>] (2020); Chauhan et al. [<xref ref-type="bibr" rid="ref-165">165</xref>] (2023); Oosthoek et al. [<xref ref-type="bibr" rid="ref-166">166</xref>] (2023); Phipps et al. [<xref ref-type="bibr" rid="ref-167">167</xref>] (2025); Delgado-Mohatar et al. [<xref ref-type="bibr" rid="ref-168">168</xref>]; Adams et al. [<xref ref-type="bibr" rid="ref-169">169</xref>] (2025); van der Horst et al. [<xref ref-type="bibr" rid="ref-170">170</xref>] (2025) (2020)</td>
</tr>
<tr>
<td>Taxonomies, Attack Evolution, Threat Landscape, and Datasets Dynamic Analysis Insights</td>
<td>Provide taxonomies, datasets, benchmarks, and meta-analyses</td>
<td>Brewer et al. [<xref ref-type="bibr" rid="ref-171">171</xref>] (2016); Furnell et al. [<xref ref-type="bibr" rid="ref-172">172</xref>] (2017); Srinivasan et al. [<xref ref-type="bibr" rid="ref-173">173</xref>] (2017); OKane et al. [<xref ref-type="bibr" rid="ref-174">174</xref>] (2018); Kharraz et al. [<xref ref-type="bibr" rid="ref-175">175</xref>] (2018); Dargahi et al. [<xref ref-type="bibr" rid="ref-176">176</xref>] (2019); Hull et al. [<xref ref-type="bibr" rid="ref-177">177</xref>] (2019); Keshavarzi et al. [<xref ref-type="bibr" rid="ref-178">178</xref>] (2020); Berrueta et al. [<xref ref-type="bibr" rid="ref-179">179</xref>] (2020); Hirano et al. [<xref ref-type="bibr" rid="ref-181">181</xref>]; Diamantopoulos et al. [<xref ref-type="bibr" rid="ref-182">182</xref>] (2024); Molina et al. [<xref ref-type="bibr" rid="ref-183">183</xref>] (2023); McDonald et al. [<xref ref-type="bibr" rid="ref-184">184</xref>] (2022); Humayun et al. [<xref ref-type="bibr" rid="ref-185">185</xref>] (2021); Razaulla et al. [<xref ref-type="bibr" rid="ref-186">186</xref>] (2023); Benmalek et al. [<xref ref-type="bibr" rid="ref-187">187</xref>] (2024)</td>
</tr>
<tr>
<td>Emerging Threat Models &#x0026; Novel Attack Vectors</td>
<td>Study browser-based, hardware, and next-generation ransomware threats</td>
<td>Almeida et al. [<xref ref-type="bibr" rid="ref-188">188</xref>] (2022); Reidys et al. [<xref ref-type="bibr" rid="ref-189">189</xref>] (2022); Oz et al. [<xref ref-type="bibr" rid="ref-190">190</xref>] (2023); Rana et al. [<xref ref-type="bibr" rid="ref-191">191</xref>] (2024); McIntosh et al. [<xref ref-type="bibr" rid="ref-192">192</xref>] (2023); Raj et al. [<xref ref-type="bibr" rid="ref-193">193</xref>] (2024); Chimmanee et al. [<xref ref-type="bibr" rid="ref-194">194</xref>] (2024)</td>
</tr>
<tr>
<td>Healthcare/Operational Impact Studies</td>
<td>Document real-world ransomware impacts on clinical operations and patient care metrics</td>
<td>Zhao et al. [<xref ref-type="bibr" rid="ref-198">198</xref>] (2018); Neprash et al. [<xref ref-type="bibr" rid="ref-199">199</xref>] (2022); Dameff et al. [<xref ref-type="bibr" rid="ref-200">200</xref>] (2023)</td>
</tr>
<tr>
<td>Proactive Host Defense (Moving Target/Hardening)</td>
<td>Prevent encryption success via proactive file/extension perturbations or OS hardening techniques</td>
<td>Lee et al. [<xref ref-type="bibr" rid="ref-195">195</xref>] (2019); Lee et al. [<xref ref-type="bibr" rid="ref-196">196</xref>] (2023); Khan et al. [<xref ref-type="bibr" rid="ref-197">197</xref>] (2023)</td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-10">
<label>Table 10</label>
<caption>
<title>Multi-dimensional taxonomy of ransomware research across threat models, defense layers, and adversarial capabilities.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Category</th>
<th>Threat Model Dimension</th>
<th>Defense Layer</th>
<th>Adversarial Capability Level</th>
</tr>
</thead>
<tbody>
<tr>
<td><bold>Signature/Static Detection</bold></td>
<td>Aggressive, known ransomware; predictable behavior</td>
<td>Host (file, API, binary)</td>
<td>Low&#x2014;Relies on known patterns; easily evaded via obfuscation/packing</td>
</tr>
<tr>
<td><bold>Behavioral/Runtime Detection</bold></td>
<td>Moderate to stealthy; observable runtime patterns (file I/O, entropy)</td>
<td>Host &#x002B; OS</td>
<td>Medium&#x2014;Evades via slow encryption, mimicry, or distributed execution</td>
</tr>
<tr>
<td><bold>ML/DL-based Detection</bold></td>
<td>Generalized (known &#x002B; unknown variants); data-driven threat modeling</td>
<td>Host &#x002B; Network &#x002B; Hybrid</td>
<td>Medium&#x2013;High&#x2014;Vulnerable to adversarial examples, drift, poisoning</td>
</tr>
<tr>
<td><bold>Semi-supervised/Zero-shot/ Drift-aware</bold></td>
<td>Unseen, evolving, and adaptive ransomware</td>
<td>Cross-layer (Host &#x002B; Data &#x002B; Model)</td>
<td>High&#x2014;Targets unknown threats but sensitive to distribution shift and data bias</td>
</tr>
<tr>
<td><bold>Network/SDN-based Detection</bold></td>
<td>Propagation, C&#x0026;C communication, lateral movement</td>
<td>Network/SDN</td>
<td>Medium&#x2013;High&#x2014;Limited by encryption, tunneling, and stealth channels</td>
</tr>
<tr>
<td><bold>Storage/Hardware-level Defenses</bold></td>
<td>Aggressive encryption and overwrite-heavy attacks</td>
<td>Storage/Firmware/ Hardware</td>
<td>Low&#x2013;Medium&#x2014;Bypassed by selective encryption, exfiltration, or logic-based attacks</td>
</tr>
<tr>
<td><bold>Deception/Honeypot-based</bold></td>
<td>Interaction-driven attacks (file discovery, scanning)</td>
<td>Host &#x002B; File system</td>
<td>Medium&#x2014;Evaded via decoy detection, fingerprinting, or avoidance strategies</td>
</tr>
<tr>
<td><bold>Proactive Prevention (MTD, OS hardening)</bold></td>
<td>Reconnaissance-driven attacks; predictable file targeting</td>
<td>Host &#x002B; OS</td>
<td>Medium&#x2013;High&#x2014;Bypassed via adaptive discovery or deeper inspection</td>
</tr>
<tr>
<td><bold>Recovery/Backup-based</bold></td>
<td>Post-compromise scenarios; encryption and data loss</td>
<td>Storage &#x002B; Cloud</td>
<td>Low&#x2014;Fails if backups are deleted, exfiltrated, or corrupted</td>
</tr>
<tr>
<td><bold>Reverse Engineering/Decryption</bold></td>
<td>Specific ransomware families with implementation flaws</td>
<td>Forensic/Post-attack</td>
<td>Low&#x2014;Works only for vulnerable implementations; not generalizable</td>
</tr>
<tr>
<td><bold>Blockchain/Payment Analysis</bold></td>
<td>Financial flows, ransom payments, attribution</td>
<td>Economic/Network</td>
<td>Medium&#x2013;High&#x2014;Limited by mixers, privacy coins, cross-chain laundering</td>
</tr>
<tr>
<td><bold>Human/Organizational/ Policy</bold></td>
<td>Decision-making, negotiation, socio-economic behavior</td>
<td>Human &#x002B; Policy layer</td>
<td>High&#x2014;Influenced by uncertainty, incentives, and incomplete information</td>
</tr>
<tr>
<td><bold>Emerging Threat Models (Hardware, Browser, CPS)</bold></td>
<td>Stealthy, cross-layer, multi-stage attacks (exfiltration, fileless, hybrid)</td>
<td>Cross-layer (Hardware &#x002B; Cloud &#x002B; CPS)</td>
<td>Very High&#x2014;Exploits system-wide blind spots and integration gaps</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s4_2_11">
<label>4.2.11</label>
<title>Miscellaneous Approaches for Ransomware Detection, Prevention, and Mitigation</title>
<p>This category includes diverse approaches that complement traditional detection and defense mechanisms, spanning forensic analysis, learning-based detection, and analytical modeling. These methods provide valuable auxiliary capabilities but are often specialized and less integrated into end-to-end defense frameworks.</p>
<p>Forensic and intelligence-driven approaches (e.g., [<xref ref-type="bibr" rid="ref-201">201</xref>,<xref ref-type="bibr" rid="ref-202">202</xref>]) focus on post-incident analysis, extracting artifacts such as ransom messages and identifying common attack patterns using frameworks like MITRE ATT&#x0026;CK. Compared to real-time detection methods, these approaches enhance attribution and situational awareness but are inherently reactive and do not prevent attacks. In contrast, system-level and learning-based techniques (e.g., [<xref ref-type="bibr" rid="ref-203">203</xref>,<xref ref-type="bibr" rid="ref-204">204</xref>]) emphasize efficient runtime detection using advanced models or low-level instrumentation (e.g., eBPF). These methods achieve strong detection performance with low overhead, but their effectiveness depends on environment-specific assumptions and deployment constraints.</p>
<p>Other works explore alternative analytical models, including statistical methods, adversarially robust heuristics, and epidemiological modeling (e.g., [<xref ref-type="bibr" rid="ref-145">145</xref>,<xref ref-type="bibr" rid="ref-205">205</xref>,<xref ref-type="bibr" rid="ref-206">206</xref>]). While these approaches broaden the analytical perspective and improve robustness in specific scenarios, they remain limited in generalizability and integration with broader defense systems.</p>
<p><bold>Open Issues:</bold> These approaches are often fragmented and rely on environment-specific assumptions, limiting scalability and generalization. Integration with threat intelligence, forensic pipelines, and standardized evaluation frameworks remains limited, highlighting challenges in <bold>C6</bold> (integration) and <bold>C7</bold> (cross-layer coordination).</p>
<p>Overall, the above subsection-specific limitations collectively map to the cross-cutting challenges (C1&#x2013;C10), providing a unified view of open research directions across the ransomware defense landscape.</p>
</sec>
<sec id="s4_2_12">
<label>4.2.12</label>
<title>Limitations of Existing Recovery Mechanisms</title>
<p>Compared to detection, ransomware recovery remains underexplored. Most existing approaches assume the availability of uncompromised backups, which is increasingly unrealistic as modern ransomware targets backup systems and incorporates data exfiltration.</p>
 <p><bold>Furthermore, recovery strategies often lack:</bold> (i) integration with detection systems, (ii) mechanisms for selective or partial recovery, (iii) consideration of data integrity and consistency, (iv) alignment with organizational response workflows. Future research should focus on adaptive recovery frameworks that combine secure backups, anomaly-aware restoration, and policy-driven response mechanisms.</p>
</sec>
<sec id="s4_2_13">
<label>4.2.13</label>
<title>Deployment Challenges in Real-World Environments</title>
<p>Despite promising results, many ransomware defense techniques face significant barriers to real-world deployment. These include:</p>
<p><bold>Performance overhead:</bold> Kernel-level monitoring and deep learning models introduce latency and resource consumption.</p>
<p><bold>Scalability:</bold> Solutions often fail to scale across cloud-native, multi-tenant, or distributed environments.</p>
<p><bold>Compatibility:</bold> Many approaches require modifications to OS, firmware, or applications, limiting adoption.</p>
<p><bold>Operational integration:</bold> Limited integration with SOC workflows, SIEM systems, and incident response pipelines.</p>
<p><bold>Privacy constraints:</bold> Monitoring approaches may conflict with regulatory requirements.</p>
<p>Addressing these challenges is essential for transitioning research prototypes into deployable solutions.</p>
</sec>
<sec id="s4_2_14">
<label>4.2.14</label>
<title>Challenges in Ensuring Adversarial Robustness</title>
<p>Ransomware detection systems are increasingly vulnerable to adversarial manipulation. Attackers can evade detection by mimicking benign behavior, injecting noise into feature space, or exploiting weaknesses in model training.</p>
<p><bold>Existing work often lacks:</bold> (i) standardized adversarial evaluation benchmarks, (ii) robustness analysis across different attack models, (iii) defenses against poisoning and model extraction attacks.</p>
<p>Future systems must incorporate adversarial training, invariant feature design, and continuous adaptation to evolving threat strategies.</p>
</sec>
<sec id="s4_2_15">
<label>4.2.15</label>
<title>Evaluation Challenges and Standardization</title>
<p>A major weakness in current ransomware research is the lack of standardized and realistic evaluation practices. Many studies rely on small, outdated, or highly curated datasets that do not reflect modern ransomware behaviors such as selective encryption, low-and-slow attacks, data exfiltration, fileless execution, and multi-stage extortion. As a result, reported performance is often difficult to compare across studies and may overestimate real-world effectiveness. This problem is compounded by inconsistent experimental settings, different feature extraction pipelines, and limited cross-dataset or longitudinal validation.</p>
<p>To address these issues, the community needs benchmark datasets that are continuously updated, diverse, and representative of multiple deployment contexts, including endpoints, cloud platforms, mobile devices, IoT/IIoT systems, and critical infrastructure. Such datasets should include benign workloads, realistic user behavior, recent ransomware families, and attack traces spanning pre-encryption, encryption, exfiltration, and recovery phases. Standard evaluation protocols are also needed to improve reproducibility and fairness. These should specify train/test dataset splits, temporal validation, cross-dataset testing, ablation studies, adversarial evaluation, and reporting of computational overhead and deployment assumptions.</p>
<p>Equally important is the use of metrics tailored to ransomware rather than relying solely on generic ML measures such as accuracy or F1-score. Since ransomware causes progressive harm over time, metrics such as <italic>time-to-detection</italic>, <italic>files protected before detection</italic>, <italic>damage prevented</italic>, <italic>recovery success rate</italic>, <italic>false alarm cost</italic>, and <italic>system overhead</italic> are often more informative than aggregate classification accuracy. Current evaluation practices are insufficient because they rarely capture operational impact, adversarial adaptation, or usability trade-offs, and they often ignore whether a method remains effective under realistic deployment constraints. Therefore, future work should move toward standardized, deployment-aware, and ransomware-specific evaluation frameworks that better reflect real-world defensive requirements.</p>
</sec>
<sec id="s4_2_16">
<label>4.2.16</label>
<title>Critical Insights and Lessons Learned from Research Works on Ransomware Prevention, Mitigation, and Recovery-Focused Research Works</title>
<p><bold>Critical Insights and Lessons Learned:</bold> Research on ransomware prevention, mitigation, and recovery reveals several important insights that highlight both progress and persistent limitations in current defense strategies.</p>
<p>First, no single defense mechanism is sufficient. Effective ransomware protection requires a <italic>multi-layered and defense-in-depth approach</italic> that combines prevention (e.g., access control, patching), detection (behavioral or ML-based), mitigation (network isolation, process termination), and recovery (backup and restoration). Studies consistently show that isolated solutions fail against modern, multi-stage ransomware attacks. Second, many prevention mechanisms rely on assumptions that are increasingly invalid. Techniques such as signature-based detection or pre-encryption behavioral monitoring assume predictable attack patterns, yet modern ransomware employs stealthy execution, obfuscation, and delayed or selective encryption to evade such defenses. This highlights a fundamental gap between research assumptions and real-world adversarial behavior.</p>
<p>Third, mitigation strategies are often reactive and depend on timely detection. Approaches such as process termination, SDN-based traffic blocking, or access revocation can limit damage, but their effectiveness diminishes significantly if detection is delayed. As a result, mitigation alone cannot guarantee protection, particularly in fast-moving or low-and-slow attack scenarios. Fourth, recovery remains a critical yet underdeveloped component. While backup-based recovery is widely adopted, many studies assume that backups are intact and readily accessible. In practice, modern ransomware targets backup systems and incorporates data exfiltration, making recovery incomplete or insufficient for addressing extortion risks.</p>
<p>Fifth, there is a growing shift from prevention-centric to resilience-oriented security models. Traditional approaches prioritized preventing attacks entirely, but recent research emphasizes the importance of rapid recovery, system resilience, and operational continuity in the face of inevitable breaches. Finally, a key lesson is the need for <italic>cross-layer and adaptive defense frameworks</italic>. Current approaches are fragmented across host, network, storage, and organizational layers, whereas ransomware operates across all these layers simultaneously. Future solutions must integrate detection, mitigation, recovery, and policy-level responses into unified, adaptive, and adversarially robust systems.</p>
</sec>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Research Works Published during the Years 2022&#x2013;2025, Not Discussed in This Paper</title>
<p>In this section, we provide references to additional relevant studies, including peer-reviewed conference papers, technical reports, and unrefereed preprints, that fall outside the primary scope of this survey and are therefore not discussed in detail. The inclusion of these works highlights the sustained and growing research activity in this area since 2022. In particular, several conference publications from 2022 onward [<xref ref-type="bibr" rid="ref-207">207</xref>&#x2013;<xref ref-type="bibr" rid="ref-215">215</xref>] reflect increasing academic interest and continued methodological development.</p>
<p>Furthermore, a large body of technical reports and preprints published since 2022 [<xref ref-type="bibr" rid="ref-216">216</xref>&#x2013;<xref ref-type="bibr" rid="ref-276">276</xref>] further demonstrates the breadth and momentum of ongoing research efforts. While many of these works are preliminary and have not yet undergone full peer review, they provide early insights into emerging directions and reinforce the observation that this research area remains active and rapidly evolving.</p>
</sec>
<sec id="s6">
<label>6</label>
<title>Summary of Open Issues and Research Directions</title>
<p>In this section, we summarize the key open issues associated with the ransomware detection, prevention, and mitigation techniques reviewed in this paper, and we further highlight critical challenges that remain unresolved across these areas. By synthesizing limitations observed in existing approaches, this section outlines promising directions for future research aimed at improving the robustness, scalability, and real-world effectiveness of ransomware defenses.</p>
<sec id="s6_1">
<label>6.1</label>
<title>Grand Challenges in Ransomware Defense</title>
<p>Despite extensive research across detection, prevention, mitigation, and recovery, ransomware defense continues to face several fundamental and unresolved challenges. A primary limitation lies in the <italic>disconnect between research and real-world deployment</italic>. Many proposed solutions are evaluated on curated or outdated datasets under simplified threat models, leading to inflated performance claims and limited generalization to evolving ransomware behaviors. At the same time, adversarial robustness remains insufficiently addressed, as modern ransomware increasingly employs stealthy execution, adaptive strategies, and evasion techniques that undermine both machine-learning&#x2013;based and behavioral detection systems.</p>
<p>A second major challenge is the <italic>lack of cross-layer integration</italic>. Existing defenses are often developed in isolation&#x2014;spanning host, network, storage, and application layers&#x2014;without standardized interfaces or coordinated response mechanisms. This fragmentation limits visibility into multi-stage attacks and reduces the overall effectiveness of otherwise strong point solutions. Furthermore, prevention and recovery mechanisms frequently rely on fragile assumptions, such as predictable encryption patterns or intact backups, which are increasingly violated by modern ransomware incorporating selective encryption, data exfiltration, and backup targeting.</p>
<p>Another critical issue is the <italic>trade-off between security, usability, and deployability</italic>. Lightweight and scalable solutions are needed for resource-constrained environments (e.g., IoT, edge, and cloud), yet many high-accuracy approaches require significant computational resources or system modifications. Similarly, proactive defenses such as file perturbation and deception mechanisms can impact usability and introduce operational complexity. These constraints are further exacerbated by the absence of standardized benchmarks, longitudinal datasets, and realistic evaluation frameworks that capture long-term attacker&#x2013;defender co-evolution.</p>
<p>Finally, ransomware is inherently a <italic>socio-technical problem</italic>, extending beyond purely technical defenses. Economic incentives, cyber-insurance dynamics, regulatory inconsistencies, and challenges in attribution and payment tracking all influence attacker behavior and victim response. Current research often treats these dimensions independently, resulting in fragmented solutions that fail to address the broader ecosystem.</p>
<p><bold>Key Insight:</bold> Addressing these grand challenges requires a shift toward <italic>integrated, cross-layer, and adversarially robust defense frameworks</italic> that combine technical mechanisms with economic, organizational, and policy considerations. Future solutions must emphasize realistic evaluation, adaptive learning, explainability, and seamless deployment to achieve sustainable and resilient ransomware.</p>
<p><xref ref-type="fig" rid="fig-5">Fig. 5</xref> illustrates the key cross-layer challenges in ransomware defense, highlighting that effective protection is constrained by multiple interdependent factors. Technical limitations such as data and benchmarking gaps, adversarial robustness, and cross-layer integration issues interact with system-level concerns including scalability and usability trade-offs. These challenges are further compounded by economic, policy, and human factors that shape real-world deployment and response strategies. The figure emphasizes that ransomware defense is not a single-layer problem but a <italic>multi-dimensional challenge</italic> requiring coordinated solutions across technical, operational, and socio-economic domains.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Grand challenges in ransomware defense: a cross-layer synthesis of technical, operational, and socio-economic limitations. Response framework.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="JCS_82741-fig-5.tif"/>
</fig>
<p><bold>Taxonomy Insights:</bold> <xref ref-type="table" rid="table-10">Table 10</xref> provides a multi-dimensional view of ransomware research across three critical dimensions: threat models, defense layers, and adversarial capabilities. A key observation is that low-level defenses (e.g., signature-based, storage-level) are effective against simple and aggressive attacks but fail under stealthy or adaptive threat models. In contrast, advanced approaches (e.g., ML/DL, zero-shot, and cross-layer defenses) target more sophisticated ransomware but introduce dependencies on data quality, system integration, and robustness against adversarial manipulation.</p>
<p>Another important insight is the increasing shift from single-layer defenses (host or network) toward <italic>cross-layer strategies</italic> that combine host, network, storage, and human factors. This shift is driven by the rise of high-capability adversaries who exploit multiple attack surfaces simultaneously. However, no single approach provides complete coverage, highlighting a fundamental gap between isolated defense mechanisms and real-world, multi-stage attack scenarios. Consequently, effective ransomware defense requires integrated, adaptive, and adversarially aware frameworks that align technical, economic, and organizational layers.</p>
<p><xref ref-type="table" rid="table-11">Table 11</xref> highlights that ransomware defense remains fundamentally challenged by the gap between controlled research assumptions and the complexity of real-world attack environments. Across detection paradigms, a recurring limitation is the reliance on static datasets, handcrafted features, or high-cost models that struggle with stealthy, adaptive, and adversarial ransomware behaviors. Similarly, system-level defenses&#x2013;ranging from storage and network mechanisms to deception and backup strategies&#x2013;often face deployability constraints, and scalability issues in heterogeneous and resource-constrained environments such as IoT and CPS. The table also underscores that non-technical dimensions, including economic incentives, human decision-making, and policy limitations, play a critical role in shaping ransomware resilience. Overall, these observations point to the need for unified, cross-layer, and adversarially robust defense frameworks, supported by realistic datasets, standardized benchmarks, and closer integration between technical, organizational, and economic perspectives.</p>
<table-wrap id="table-11">
<label>Table 11</label>
<caption>
<title>Refined summary of open issues in ransomware research.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Area</th>
<th>Key Limitations</th>
<th>Implications</th>
</tr>
</thead>
<tbody>
<tr>
<td>Behavioral Detection</td>
<td>Stealthy, delayed, or selective encryption weakens behavior-based assumptions; kernel/API monitoring incurs overhead; ML models remain vulnerable to adversarial manipulation; lack of realistic datasets and explainability.</td>
<td>Need lightweight monitoring, adversarially robust features, explainable detection models, and standardized real-world datasets.</td>
</tr>
<tr>
<td>Classical ML</td>
<td>Dependence on handcrafted features vulnerable to obfuscation; limited generalization due to curated datasets; dataset imbalance and concept drift; limited study of adversarial ML threats.</td>
<td>Need to emphasis on adaptive learning, robust feature engineering, adversarial resilience, and integration of XAI with human-in-the-loop validation.</td>
</tr>
<tr>
<td>Deep Learning</td>
<td>Requires large labeled datasets and high computational cost; vulnerable to adversarial examples and traffic manipulation; explanation fidelity remains uncertain.</td>
<td>Need development of lightweight architectures, robust training methods, trustworthy XAI, and privacy-preserving/federated learning frameworks.</td>
</tr>
<tr>
<td>Semi/Zero-shot Detection</td>
<td>Strong dependence on quality of unlabeled or synthetic data; difficulty capturing evolving ransomware semantics.</td>
<td>Need improved generative models, secure online learning, and long-term benchmarks for evolving threats.</td>
</tr>
<tr>
<td>Network/SDN Detection</td>
<td>Encrypted traffic reduces visibility; modern C&#x0026;C channels use P2P, blockchain, or cloud services; SDN integration complexity; high false positives.</td>
<td>Research on encrypted traffic analytics, scalable SDN orchestration, adversarially robust traffic analysis, and cross-layer correlation.</td>
</tr>
<tr>
<td>Mobile/Android Detection</td>
<td>Resource constraints limit monitoring; obfuscation and dynamic loading hinder analysis; privacy restrictions limit feature extraction.</td>
<td>Need energy-efficient detection, hybrid static-dynamic analysis, and privacy-preserving monitoring frameworks.</td>
</tr>
<tr>
<td>IoT/IIoT/CPS Environments</td>
<td>Strict resource and safety constraints; heterogeneous legacy systems; federated learning risks; limited protocol visibility.</td>
<td>Need to focus on lightweight models, secure federated learning, interoperability, and safety-aware defense mechanisms.</td>
</tr>
<tr>
<td>Adversarial Robustness</td>
<td>Ransomware can mimic benign behavior, distribute workloads, or poison training data; defenses introduce overhead.</td>
<td>Need standardized adversarial benchmarks, invariant behavioral features, and resilient detection architectures.</td>
</tr>
<tr>
<td>Blockchain Analysis</td>
<td>Mixers and privacy services hinder attribution; cross-chain transfers reduce visibility; lack of ground-truth data.</td>
<td>Need improved blockchain analytics, cross-chain tracing, better datasets, and collaboration with law enforcement.</td>
</tr>
<tr>
<td>Storage/Hardware Defenses</td>
<td>Require firmware/hardware changes; assume overwrite-heavy behavior; cross-layer semantic gaps; cloud overhead.</td>
<td>Need portable defenses, cross-layer architectures, and explainable hardware-level telemetry.</td>
</tr>
<tr>
<td>Deception-based Defense</td>
<td>Effectiveness depends on decoy placement; advanced ransomware can detect honeypots; deployment overhead.</td>
<td>Need to develop adaptive deception frameworks integrated with behavioral detection.</td>
</tr>
<tr>
<td>Reverse Engineering</td>
<td>Strong cryptography and heavy obfuscation complicate analysis; decryption often family-specific.</td>
<td>Need automated reverse-engineering tools and scalable malware analysis frameworks.</td>
</tr>
<tr>
<td>Backup/Recovery</td>
<td>Ransomware targets backups; entropy-based detection yields false positives; storage overhead; selective encryption evasion.</td>
<td>Need to use tamper-resistant backups, adaptive recovery strategies, and cross-platform restoration mechanisms.</td>
</tr>
<tr>
<td>Human/Organizational Factors</td>
<td>Decision-making under uncertainty; misaligned incentives from ransom payments; limited SME preparedness.</td>
<td>Need improved governance, incident-response policies, and coordinated international strategies.</td>
</tr>
<tr>
<td>Economic Modeling</td>
<td>Simplified assumptions; limited empirical data; complex RaaS ecosystems.</td>
<td>Need better datasets, refined economic models, and policy-driven disruption strategies.</td>
</tr>
<tr>
<td>Datasets/Benchmarks</td>
<td>Lack of scale, realism, and diversity; absence of standardized evaluation; limited coverage of emerging systems.</td>
<td>Need to develop shared datasets, reproducible benchmarks, and unified evaluation frameworks.</td>
</tr>
<tr>
<td>Emerging Threats</td>
<td>Rise of fileless attacks, data exfiltration, and cross-layer ransomware targeting cloud and hardware.</td>
<td>Need integrated, multi-layer defense frameworks combining host, network, and cloud telemetry.</td>
</tr>
<tr>
<td>File Perturbation/OS Hardening</td>
<td>May affect usability; attackers can bypass via deeper inspection; limited real-world evaluation.</td>
<td>Need scalable deployment strategies integrated with detection and access control.</td>
</tr>
<tr>
<td>Miscellaneous Techniques</td>
<td>Reliance on environment-specific assumptions; heuristic approaches are evasion-prone; limited integration.</td>
<td>Need unified architectures combining detection, forensics, and predictive analytics.</td>
</tr>
<tr>
<td>Healthcare Impact</td>
<td>Limited empirical data; inconsistent reporting; difficulty quantifying patient impact.</td>
<td>Need longitudinal datasets, standardized reporting, and cyber-resilience frameworks for critical sectors.</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="table" rid="table-12">Table 12</xref> provides a higher-level, cross-cutting perspective on ransomware challenges, emphasizing systemic issues such as deployability, cross-layer coordination, assumption fragility, and economic or policy misalignment that span detection, prevention, mitigation, and recovery. In contrast to <xref ref-type="table" rid="table-11">Table 11</xref>, which organizes open issues in a fine-grained, technique- and domain-specific manner (e.g., ML, DL, IoT, blockchain, storage), this table abstracts these challenges into broader thematic categories that highlight fundamental limitations affecting the entire ransomware defense lifecycle. As a result, while <xref ref-type="table" rid="table-11">Table 11</xref> is more useful for analyzing specific technical gaps within individual approaches, this table better captures system-level, operational, and cross-disciplinary challenges, underscoring the need for integrated, adaptive, and policy-aware ransomware defense strategies.</p>
<table-wrap id="table-12">
<label>Table 12</label>
<caption>
<title>Summary of cross-cutting open issues in ransomware detection, prevention, mitigation, and recovery.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Open-Issue Theme</th>
<th>Key Limitations/Gaps</th>
<th>Implications for Practice and Research</th>
</tr>
</thead>
<tbody>
<tr>
<td>Deployability and Practical Adoption</td>
<td>Many approaches require substantial hardware/firmware/OS/browser changes, limiting retrofitting and portability across heterogeneous endpoints, cloud providers, and legacy systems; adoption is further complicated in multi-tenant and cross-VM settings.</td>
<td>Non-incremental solutions face high barriers to real-world adoption; defenses must be deployable, portable, and compatible with operational constraints.</td>
</tr>
<tr>
<td>Assumption Fragility and Adaptive Ransomware Behavior</td>
<td>Several mechanisms assume ransomwares are overwrite-heavy, support fast encryption and exhibit predictable access patterns; these assumptions are fragile against selective, slow, content-aware, logic-driven, or timing-adaptive ransomwares (e.g., partial encryption, directory traversal, staged behavior).</td>
<td>Defenses should be designed for strategic adversarial adaptation (not static behaviors), emphasizing robustness under adaptive and low-and-slow threat models.</td>
</tr>
<tr>
<td>Cross-Layer Coordination and Standardization Gaps</td>
<td>Coordination across OS, hypervisor, storage, network, and application layers remains ad hoc; there is limited standardization of interfaces, and shared semantics for prevention and recovery.</td>
<td>Fragmentation reduces end-to-end visibility and weakens otherwise strong solutions; standardized interfaces and cross-layer designs are needed.</td>
</tr>
<tr>
<td>Robustness Against Adversarial Evasion</td>
<td>Limited evaluation under adversarial settings; resilience to evasion tactics (e.g., decoy fingerprinting, entropy manipulation, trap avoidance, similarity-metric evasion, header poisoning) is under-explored.</td>
<td>Without adversarially informed design and testing, attackers can systematically degrade detection, prevention, and recovery mechanisms over time.</td>
</tr>
<tr>
<td>Deception and Decoy Management Challenges</td>
<td>Effectiveness of placing decoy elements in the systems depends on configuration and placement; at scale, decoys introduce operational overhead, maintenance complexity, and integration challenges with other defenses.</td>
<td>Deception alone is brittle; it must be integrated into automated, adaptive, and coordinated defense pipelines to remain effective at scale.</td>
</tr>
<tr>
<td>Explainability, Guarantees, and Trustworthiness</td>
<td>Few systems provide explainable decisions, formal security guarantees, or auditable recovery logic which is problematic for regulated environments and incident response where accountability is essential.</td>
<td>Lack of transparency impedes trust and adoption; explainability and assurance mechanisms are needed for enterprise and critical-infrastructure use.</td>
</tr>
<tr>
<td>Data, Benchmarks, and Evaluation Limitations</td>
<td>Datasets are often small, platform-specific, and quickly outdated; benchmarks rarely capture modern tactics (exfiltration, living-off-the-land, multi-stage extortion); longitudinal and real-world validation is limited.</td>
<td>Overfitting to outdated benchmarks undermines effectiveness claims; realistic, continuously updated benchmarks and field validation are required.</td>
</tr>
<tr>
<td>Usability, Performance, and Operational Trade-offs</td>
<td>Preventive actions (e.g., perturbation/renaming) may harm usability and compatibility; kernel- and model-intensive defenses can add latency, energy cost, and operational fragility.</td>
<td>Sustainable defenses must explicitly balance security benefits against performance, reliability, and user/administrator burden.</td>
</tr>
<tr>
<td>Recovery and Exfiltration-Centric Ransomware</td>
<td>Many defenses emphasize preventing encryption rather than addressing data theft, extortion pressure, and reputational harm; recovery often assumes intact backups and weakly integrates governance and response workflows.</td>
<td>Modern mitigation must treat exfiltration and extortion as first-class threats and integrate detection, response, governance, and recovery.</td>
</tr>
<tr>
<td>Economic, Legal, and Policy Misalignment</td>
<td>Ransom-payment guidance varies across jurisdictions; cyber-insurance and incentives may increase attacker profitability; attribution, smart contracts, and cross-chain laundering complicate enforcement and deterrence.</td>
<td>Technical mechanisms alone are insufficient; coordinated legal, economic, and policy frameworks are needed to reduce attacker incentives and impact.</td>
</tr>
<tr>
<td>Threat Intelligence Dependence and Timeliness</td>
<td>Many methods rely on high-quality threat intelligence or labeled data that lags emerging variants; bridging generic thresholds with organization-specific controls is unresolved.</td>
<td>Long-term resilience requires adaptive, intelligence-agnostic, and continuously learning systems with operationally grounded controls.</td>
</tr>
<tr>
<td>Long-Term Sustainability and Co-Evolution</td>
<td>Evaluations often use limited threat models and short time horizons, failing to capture attacker-defender co-evolution and sustained adaptation.</td>
<td>Durable defenses require continuous updating, adversarial robustness, standardized evaluation, and integration across technical and organizational domains.</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><bold>Robustness Insights:</bold> <xref ref-type="table" rid="table-13">Table 13</xref> reveals that many ransomware defense approaches rely on simplifying assumptions that are increasingly invalid under modern threat models. Behavioral and storage-based methods assume observable and aggressive encryption patterns, which are bypassed by stealthy, low-and-slow attacks. Learning-based approaches, including both classical ML and deep learning, suffer from limited generalization and are vulnerable to adversarial manipulation and distribution shift. Network-based techniques are constrained by reduced visibility due to encryption and covert communication channels, while deception-based defenses are brittle against adaptive attackers. Overall, no single approach provides robust protection across evolving ransomware strategies, highlighting the need for adversarially robust, cross-layer, and deployment-aware defense frameworks.</p>
<table-wrap id="table-13">
<label>Table 13</label>
<caption>
<title>Robustness analysis of ransomware detection and defense approaches.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Approach</th>
<th>Typical Assumptions</th>
<th>Failure under Evasion</th>
<th>Robustness Limitations</th>
</tr>
</thead>
<tbody>
<tr>
<td>Behavioral/Runtime Detection</td>
<td>Ransomware exhibits observable pre-encryption behaviors (e.g., rapid file writes, entropy increase).</td>
<td>Low-and-slow encryption, delayed execution, or selective file targeting can evade detection.</td>
<td>Over-reliance on short-term behavioral spikes; limited robustness to stealthy and staged attacks.</td>
</tr>
<tr>
<td>Signature-based Detection</td>
<td>Known ransomware patterns and signatures remain stable.</td>
<td>Polymorphism, packing, and code obfuscation bypass signature matching.</td>
<td>Completely ineffective against zero-day and rapidly evolving variants.</td>
</tr>
<tr>
<td>Classical ML-based Detection</td>
<td>Handcrafted features are stable and discriminative across datasets.</td>
<td>Feature manipulation, mimicry attacks, and adversarial perturbations degrade performance.</td>
<td>Poor generalization; vulnerable to evasion and concept drift.</td>
</tr>
<tr>
<td>Deep Learning-based Detection</td>
<td>Training data captures representative ransomware behavior; learned features generalize.</td>
<td>Adversarial examples, distribution shift, and unseen attack patterns reduce accuracy.</td>
<td>High sensitivity to data distribution; lack of interpretability limits trust and debugging.</td>
</tr>
<tr>
<td>Semi-supervised/Zero-shot Methods</td>
<td>Latent representations capture semantic similarity between known and unknown ransomware.</td>
<td>Novel ransomware with unseen behaviors or misleading feature embeddings evade detection.</td>
<td>Dependence on representation quality; weak guarantees under adversarial conditions.</td>
</tr>
<tr>
<td>Network-based Detection</td>
<td>Ransomware communication is observable via network traffic patterns.</td>
<td>Encrypted traffic, covert channels (e.g., DNS tunneling, HTTPS, P2P), and cloud-based C&#x0026;C hide signals.</td>
<td>Limited visibility; high false positives; weak correlation with host-level activity.</td>
</tr>
<tr>
<td>SDN-based Mitigation</td>
<td>Centralized control enables timely detection and response.</td>
<td>Delayed detection or misclassification leads to ineffective mitigation; attackers adapt traffic patterns.</td>
<td>Deployment complexity; reliance on accurate upstream detection.</td>
</tr>
<tr>
<td>Deception-based (Honeypots/Decoys)</td>
<td>Ransomware interacts with decoy files or systems.</td>
<td>Advanced ransomware detects and avoids decoys or delays interaction.</td>
<td>Brittle against adaptive attackers; effectiveness depends on placement and realism.</td>
</tr>
<tr>
<td>Storage-level/Backup-based Defense</td>
<td>Ransomware performs bulk overwrite encryption; backups remain intact.</td>
<td>Selective encryption, backup targeting, or stealthy corruption bypass protection.</td>
<td>Assumptions increasingly invalid; recovery fails if backups are compromised.</td>
</tr>
<tr>
<td>Memory-based Detection</td>
<td>Malicious artifacts are observable in volatile memory.</td>
<td>Memory evasion techniques (fileless malware, rapid execution) reduce detection window.</td>
<td>Requires continuous monitoring; high overhead; limited scalability.</td>
</tr>
<tr>
<td>Blockchain/Payment Analysis</td>
<td>Ransom payments can be traced via transaction patterns.</td>
<td>Mixers, tumblers, cross-chain transfers, and privacy coins obscure attribution.</td>
<td>Limited ability to link transactions to real-world actors; reactive rather than preventive.</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="fig" rid="fig-6">Fig. 6</xref> presents a taxonomy of the open issues in ransomware research detection, prevention, mitigation and recovery.</p>
<fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Taxonomy of open issues in ransomware detection, prevention, mitigation, and recovery.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="JCS_82741-fig-6.tif"/>
</fig>
<p><bold>Discussion:</bold> <xref ref-type="table" rid="table-14">Table 14</xref> highlights the mismatch between evolving ransomware capabilities and existing defense mechanisms. Many defenses are designed under static or simplified assumptions, whereas attackers increasingly employ adaptive, stealthy, and multi-stage strategies. The mapping emphasizes that effective ransomware defense requires adversarially robust, cross-layer, and deployment-aware solutions that integrate behavioral, system-level, and network-level insights.</p>
<table-wrap id="table-14">
<label>Table 14</label>
<caption>
<title>Threat model: mapping attack capabilities to vulnerable defenses and countermeasures.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Attack Capability</th>
<th>Vulnerable Defenses</th>
<th>Possible Countermeasures</th>
</tr>
</thead>
<tbody>
<tr>
<td>Stealthy/Low-and-Slow Encryption</td>
<td>Behavioral detection, storage-level anomaly detection</td>
<td>Long-term behavioral profiling; temporal pattern analysis; cross-file and cross-process correlation; anomaly detection over extended windows</td>
</tr>
<tr>
<td>Polymorphism and Code Obfuscation</td>
<td>Signature-based and static analysis approaches</td>
<td>Behavior-based detection; dynamic analysis; invariant feature extraction; unpacking and de-obfuscation techniques</td>
</tr>
<tr>
<td>Adversarial Feature Manipulation (Evasion Attacks)</td>
<td>ML/DL-based detection systems</td>
<td>Adversarial training; robust feature selection; ensemble models; detection of adversarial inputs</td>
</tr>
<tr>
<td>Data Poisoning Attacks</td>
<td>Learning-based systems (ML/DL, federated learning)</td>
<td>Secure data pipelines; anomaly detection on training data; robust aggregation (e.g., in FL); continual validation</td>
</tr>
<tr>
<td>Encrypted and Covert Communication (C&#x0026;C)</td>
<td>Network-based detection systems</td>
<td>Encrypted traffic analysis (metadata, flow features); DNS/traffic pattern analysis; cross-layer correlation with host behavior</td>
</tr>
<tr>
<td>Decoy/Honeypot Detection and Avoidance</td>
<td>Deception-based defenses</td>
<td>Adaptive and dynamic decoy placement; high-fidelity honeypots; integration with behavioral detection</td>
</tr>
<tr>
<td>Backup Targeting and Destruction</td>
<td>Backup and recovery-based defenses</td>
<td>Tamper-resistant backups; versioning; anomaly-based backup protection; distributed storage</td>
</tr>
<tr>
<td>Fileless and Memory-Resident Execution</td>
<td>Static analysis and file-based detection</td>
<td>Memory forensics; runtime monitoring; system call tracing; kernel-level visibility</td>
</tr>
<tr>
<td>Distributed/Multi-Stage Attacks</td>
<td>Single-layer detection approaches</td>
<td>Cross-layer detection (host &#x002B; network &#x002B; storage); attack chain correlation; SIEM integration</td>
</tr>
<tr>
<td>Use of Legitimate Tools (Living-off-the-Land)</td>
<td>Signature-based and rule-based detection</td>
<td>Behavioral baselining; context-aware anomaly detection; privilege and process monitoring</td>
</tr>
<tr>
<td>Use of Privacy Coins/Mixers (Financial Obfuscation)</td>
<td>Blockchain and transaction analysis</td>
<td>Cross-chain analytics; graph-based tracing; collaboration with financial intelligence and law enforcement</td>
</tr>
<tr>
<td>Cloud and Multi-Tenant Exploitation</td>
<td>Host-based and isolated detection systems</td>
<td>Cloud-native monitoring; tenant isolation; cross-VM detection; scalable orchestration and logging</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s6_2">
<label>6.2</label>
<title>Cross-Layer Synthesis and Integration Challenges</title>
<p>A key observation from this survey is that ransomware defense mechanisms are often developed in isolation across different layers, including host-based monitoring, network analysis, storage protection, and economic/policy interventions. However, modern ransomware attacks operate across these layers simultaneously.</p>
<p>For example, data exfiltration precedes encryption, leveraging network channels, while persistence mechanisms exploit OS-level vulnerabilities, and ransom payment relies on cryptocurrency ecosystems. As a result, single-layer defenses are insufficient.</p>
<p><bold>Effective ransomware resilience requires:</bold> (i) integration of host and network telemetry, (ii) coordination between detection and recovery mechanisms, (iii) incorporation of threat intelligence and economic signals, (iv) alignment with policy and governance frameworks.</p>
<p>This cross-layer perspective remains underdeveloped in current research and represents a critical direction for future work.</p>
<p><xref ref-type="table" rid="table-15">Table 15</xref> presents a cross-layer view of ransomware defense by aligning each attack lifecycle stage with the corresponding detection stage, representative defense mechanisms, and evaluation metrics. The framework highlights that ransomware defense cannot rely on a single technique or layer. Early-stage controls such as filtering, sandboxing, and behavioral monitoring are important for preventing execution, whereas later-stage defenses such as storage monitoring, decoy mechanisms, and backup-based recovery are essential for damage containment and resilience. The table also emphasizes that evaluation should be stage-aware: early detection methods should be judged by blocking rate and false alarms, while impact-stage defenses should be evaluated using ransomware-specific metrics such as time-to-detection, files preserved, damage prevented, and recovery success.</p>
<table-wrap id="table-15">
<label>Table 15</label>
<caption>
<title>Cross-layer framework mapping attack lifecycle to detection, defense, and evaluation for unified ransomware analysis.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Attack Lifecycle Stage</th>
<th>Detection Stage</th>
<th>Representative Defense Mechanisms</th>
<th>Relevant Evaluation Metrics</th>
</tr>
</thead>
<tbody>
<tr>
<td>Initial Access/Delivery</td>
<td>Pre-compromise or early compromise</td>
<td>Email/web filtering, attachment scanning, URL reputation, sandboxing, user-awareness controls, patching, access control</td>
<td>Detection rate, false positive rate, malware blocking rate, time-to-alert, user disruption cost</td>
</tr>
<tr>
<td>Execution/Payload Launch</td>
<td>Early execution</td>
<td>Static analysis, behavioral monitoring, process/API-call tracing, memory inspection, script control, privilege monitoring</td>
<td>True positive rate, false negative rate, time-to-detection, CPU/memory overhead, alert precision</td>
</tr>
<tr>
<td>Persistence/Privilege Escalation</td>
<td>Post-execution, pre-encryption</td>
<td>Endpoint detection and response, registry/startup monitoring, kernel hooks, credential protection, anomaly detection on privileged actions</td>
<td>Detection latency, persistence-blocking rate, false alarms, system overhead</td>
</tr>
<tr>
<td>Discovery/Lateral Movement</td>
<td>Pre-impact expansion</td>
<td>Network traffic analysis, SDN/NDR monitoring, authentication anomaly detection, traffic inspection, segmentation, zero-trust controls</td>
<td>Lateral-movement detection rate, false positive rate, response latency, containment success</td>
</tr>
<tr>
<td>Command-and-Control/Key Exchange</td>
<td>Pre-encryption coordination</td>
<td>DNS/flow analytics, encrypted traffic analysis, blockchain/CTI correlation, domain/IP reputation, sinkholing, egress control</td>
<td>C&#x0026;C detection rate, flow-level precision/recall, time-to-block, cross-layer correlation accuracy</td>
</tr>
<tr>
<td>Encryption/File Modification</td>
<td>Impact stage</td>
<td>File-system monitoring, entropy/change-rate analysis, decoy files, storage-level defenses, process termination, I/O throttling</td>
<td>Time-to-detection, files protected before detection, damage prevented, false termination rate, storage overhead</td>
</tr>
<tr>
<td>Exfiltration/Double Extortion</td>
<td>Impact and post-impact</td>
<td>Data loss prevention, network exfiltration detection, access-pattern analysis, encryption-aware traffic inspection, policy-based blocking</td>
<td>Exfiltration detection rate, bytes/files protected, false positive rate, response time</td>
</tr>
<tr>
<td>Recovery/Restoration</td>
<td>Post-incident</td>
<td>Tamper-resistant backups, immutable snapshots, rollback, key recovery, incident response orchestration, forensic triage</td>
<td>Recovery success rate, recovery time objective (RTO), recovery point objective (RPO), data integrity preserved, downtime</td>
</tr>
<tr>
<td>Post-Incident Learning/Adaptation</td>
<td>Continuous improvement</td>
<td>Threat intelligence updates, model retraining, rule refinement, attack replay, adversarial testing, policy revision</td>
<td>Model drift resilience, adversarial robustness, update latency, reproducibility, operational effectiveness over time</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="fig" rid="fig-3">Fig. 3</xref> illustrates a cross-layer ransomware defense architecture in which telemetry from host, network, storage, and organizational layers is analyzed both locally and jointly and <xref ref-type="fig" rid="fig-4">Fig. 4</xref> presents a cross-layer view of ransomware defense, integrating technical, economic, and human/policy dimensions into a unified response framework.</p>
</sec>
</sec>
<sec id="s7">
<label>7</label>
<title>Conclusion</title>
<p>This survey reviewed the evolution of ransomware from simple file-encrypting malware to a complex, adaptive, and profit-driven socio-technical threat. Research has progressed from signature- and entropy-based methods to behavior-driven, ML/XAI-based, storage-level, and deception-oriented defenses, alongside increasing focus on recovery, economics, and policy. At the same time, ransomware has expanded across new attack surfaces&#x2013;including cloud, IoT, IIoT, healthcare, hardware-assisted, and cyber-physical environments&#x2013;while adopting increasingly sophisticated strategies such as data exfiltration, intermittent encryption, multi-stage extortion, and ransomware-as-a-service. Although recent advances in datasets, taxonomies, and benchmarking have improved reproducibility, much of the literature remains detection-centric and continues to rely on assumptions that only partially reflect real-world attacker behavior.</p>
<p>Despite substantial progress, several important challenges remain unresolved. Many existing defenses are narrowly scoped, difficult to deploy at scale, or vulnerable to adversarial evasion and adaptive attack strategies. Recovery and decryption mechanisms remain largely reactive and opportunistic, while proactive and storage-level defenses often face usability, interoperability, and scalability limitations. Furthermore, economic and game-theoretic analyses provide valuable insights into attacker incentives and ransom dynamics, yet many models lack realistic operational assumptions and empirical validation. A significant gap also persists between academic research and operational practice, particularly in areas such as incident response integration, attribution, policy enforcement, cross-layer coordination, and deployment in resource-constrained environments.</p>
<p>Looking forward, several short-term practical priorities deserve immediate attention. These include the development of standardized and continuously updated ransomware datasets and benchmarks, realistic evaluation methodologies that account for temporal drift and adversarial behavior, deployment-aware lightweight defenses for cloud and IoT environments, explainable detection systems suitable for SOC workflows, and faster recovery-oriented mechanisms capable of reducing time-to-detection and minimizing operational damage. Improving information sharing among academia, industry, and government agencies is also critical for enabling reproducible evaluation and coordinated response.</p>
<p>Beyond these immediate needs, longer-term research challenges require more fundamental advances. Future ransomware defense will likely depend on integrated, cross-layer, and adaptive frameworks that unify prevention, detection, containment, recovery, attribution, and policy mechanisms. Robustness against adversarial ML attacks, autonomous and AI-assisted ransomware, cross-platform attacks targeting hybrid cloud and cyber-physical infrastructures, and large-scale automated extortion ecosystems will become increasingly important research directions. In addition, emerging paradigms such as post-quantum cryptography, secure hardware-assisted defenses, privacy-preserving collaborative learning, and economically informed defense strategies are expected to play a significant role in next-generation ransomware resilience.</p>
<p>Overall, reducing the long-term impact and profitability of ransomware will require bridging the gap between theoretical research and operational deployment through realistic evaluation, interdisciplinary collaboration, standardized benchmarks, and policy-aware, human-centered defense design.</p>
</sec>
</body>
<back>
<ack>
<p>Not applicable.</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>The authors received no specific funding for this study.</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>Not applicable.</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>Not applicable.</p>
</sec>
<sec sec-type="COI-statement">
<title>Conflicts of Interest</title>
<p>The author declares no conflicts of interest.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Fernando</surname> <given-names>DW</given-names></string-name>, <string-name><surname>Komninos</surname> <given-names>N</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>T</given-names></string-name></person-group>. <article-title>A study on the evolution of ransomware detection using machine learning and deep learning techniques</article-title>. <source>IoT</source>. <year>2020</year>;<volume>1</volume>(<issue>2</issue>):<fpage>551</fpage>&#x2013;<lpage>604</lpage>. doi:<pub-id pub-id-type="doi">10.3390/iot1020030</pub-id>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>K</given-names></string-name>, <string-name><surname>Pang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>D</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Huang</surname> <given-names>D</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>C</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>A large-scale empirical analysis of ransomware activities in Bitcoin</article-title>. <source>ACM Trans Web</source>. <year>2021</year>;<volume>16</volume>(<issue>2</issue>):<fpage>1</fpage>&#x2013;<lpage>29</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3494557</pub-id>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Moussaileb</surname> <given-names>R</given-names></string-name>, <string-name><surname>Cuppens</surname> <given-names>N</given-names></string-name>, <string-name><surname>Lanet</surname> <given-names>J-L</given-names></string-name>, <string-name><surname>Le Bouder</surname> <given-names>H</given-names></string-name></person-group>. <article-title>A survey on windows-based ransomware taxonomy and detection mechanisms</article-title>. <source>ACM Comput Surv</source>. <year>2021</year>;<volume>54</volume>(<issue>6</issue>):<fpage>1</fpage>&#x2013;<lpage>36</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3453153</pub-id>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>McIntosh</surname> <given-names>T</given-names></string-name>, <string-name><surname>Kayes</surname> <given-names>ASM</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Ng</surname> <given-names>A</given-names></string-name>, <string-name><surname>Watters</surname> <given-names>P</given-names></string-name></person-group>. <article-title>Ransomware mitigation in the modern era: a comprehensive review, research challenges, and future directions</article-title>. <source>ACM Comput Surv</source>. <year>2021</year>;<volume>54</volume>(<issue>9</issue>):<fpage>1</fpage>&#x2013;<lpage>36</lpage>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Alqahtani</surname> <given-names>A</given-names></string-name>, <string-name><surname>Sheldon</surname> <given-names>FT</given-names></string-name></person-group>. <article-title>A survey of crypto ransomware attack detection methodologies: an evolving outlook</article-title>. <source>Sensors</source>. <year>2022</year>;<volume>22</volume>(<issue>5</issue>):<fpage>1837</fpage>. doi:<pub-id pub-id-type="doi">10.3390/s22051837</pub-id>; <pub-id pub-id-type="pmid">35270983</pub-id></mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Smith</surname> <given-names>D</given-names></string-name>, <string-name><surname>Khorsandroo</surname> <given-names>S</given-names></string-name>, <string-name><surname>Roy</surname> <given-names>K</given-names></string-name></person-group>. <article-title>Machine learning algorithms and frameworks in ransomware detection</article-title>. <source>IEEE Access</source>. <year>2022</year>;<volume>10</volume>:<fpage>117597</fpage>&#x2013;<lpage>610</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2022.3218779</pub-id>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Aldauiji</surname> <given-names>F</given-names></string-name>, <string-name><surname>Batarfi</surname> <given-names>O</given-names></string-name>, <string-name><surname>Bayousef</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Utilizing cyber threat hunting techniques to find ransomware attacks: a survey of the state of the art</article-title>. <source>IEEE Access</source>. <year>2022</year>;<volume>10</volume>:<fpage>61695</fpage>&#x2013;<lpage>706</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2022.3181278</pub-id>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Oz</surname> <given-names>H</given-names></string-name>, <string-name><surname>Aris</surname> <given-names>A</given-names></string-name>, <string-name><surname>Levi</surname> <given-names>A</given-names></string-name>, <string-name><surname>Uluagac</surname> <given-names>AS</given-names></string-name></person-group>. <article-title>A survey on ransomware: evolution, taxonomy, and defense solutions</article-title>. <source>ACM Comput Surv</source>. <year>2022</year>;<volume>54</volume>(<issue>11s</issue>):<fpage>1</fpage>&#x2013;<lpage>37</lpage>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ispahany</surname> <given-names>J</given-names></string-name>, <string-name><surname>Islam</surname> <given-names>MR</given-names></string-name>, <string-name><surname>Islam</surname> <given-names>MZ</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>MA</given-names></string-name></person-group>. <article-title>Ransomware detection using machine learning: a review, research limitations and future directions</article-title>. <source>IEEE Access</source>. <year>2024</year>;<volume>12</volume>(<issue>18</issue>):<fpage>68785</fpage>&#x2013;<lpage>813</lpage>. doi:<pub-id pub-id-type="doi">10.1002/cpe.5422</pub-id>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Alzahrani</surname> <given-names>S</given-names></string-name>, <string-name><surname>Xiao</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Asiri</surname> <given-names>S</given-names></string-name>, <string-name><surname>Zheng</surname> <given-names>J</given-names></string-name>, <string-name><surname>Li</surname> <given-names>T</given-names></string-name></person-group>. <article-title>A survey of ransomware detection methods</article-title>. <source>IEEE Access</source>. <year>2025</year>;<volume>13</volume>(<issue>2</issue>):<fpage>57943</fpage>&#x2013;<lpage>82</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2025.3556187</pub-id>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Anh</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Dynamic features of virusshare executables</article-title>. <source>UCI Mach Learn Repos</source>. <year>2017</year>. doi:<pub-id pub-id-type="doi">10.24432/C50P5P</pub-id>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Nappa</surname> <given-names>A</given-names></string-name>, <string-name><surname>Zubair Rafique</surname> <given-names>M</given-names></string-name>, <string-name><surname>Caballero</surname> <given-names>J</given-names></string-name></person-group>. <article-title>The MALICIA dataset: identification and analysis of drive-by download operations</article-title>. <source>Int J Inf Secur</source>. <year>2015</year>;<volume>14</volume>(<issue>1</issue>):<fpage>15</fpage>&#x2013;<lpage>33</lpage>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Anderson</surname> <given-names>HS</given-names></string-name>, <string-name><surname>Roth</surname> <given-names>P</given-names></string-name></person-group>. <article-title>EMBER: an open dataset for training static pe malware machine learning models</article-title>. <comment>arXiv:1804.04637. 2018</comment>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Carrier</surname> <given-names>T</given-names></string-name>, <string-name><surname>Victor</surname> <given-names>P</given-names></string-name>, <string-name><surname>Tekeoglu</surname> <given-names>A</given-names></string-name>, <string-name><surname>Lashkari</surname> <given-names>AH</given-names></string-name></person-group>. <article-title>Cic-malmem-2022 dataset</article-title>. <year>2022 [cited 2026 Jan 1]</year>. Available from: <ext-link ext-link-type="uri" xlink:href="https://www.unb.ca/cic/datasets/malmem-2022.html">https://www.unb.ca/cic/datasets/malmem-2022.html</ext-link>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Sharafaldin</surname> <given-names>I</given-names></string-name>, <string-name><surname>Lashkari</surname> <given-names>AH</given-names></string-name>, <string-name><surname>Ghorbani</surname> <given-names>AA</given-names></string-name></person-group>. <article-title>Cicids2017-dataset</article-title>. <year>2017 [cited 2026 Jan 1]</year>. Available from: <ext-link ext-link-type="uri" xlink:href="https://www.unb.ca/cic/datasets/ids-2017.html">https://www.unb.ca/cic/datasets/ids-2017.html</ext-link>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Sharafaldin</surname> <given-names>I</given-names></string-name>, <string-name><surname>Lashkari</surname> <given-names>AH</given-names></string-name>, <string-name><surname>Ghorbani</surname> <given-names>A</given-names></string-name></person-group>. <article-title>A realistic cyber defense dataset (CSE-CIC-IDS2018)</article-title>. <year>2017 [cited 2026 Jan 1]</year>. Available from: <ext-link ext-link-type="uri" xlink:href="https://www.kaggle.com/datasets/dhoogla/csecicids2018">https://www.kaggle.com/datasets/dhoogla/csecicids2018</ext-link>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Moustafa</surname> <given-names>N</given-names></string-name>, <string-name><surname>Slay</surname> <given-names>J</given-names></string-name></person-group>. <article-title>UNSW-NB15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set)</article-title>. In: <conf-name>Proceedings of the 2015 Military Communications and Information Systems Conference (MilCIS); 2015 Nov 10&#x2013;12; Canberra, Australia</conf-name>. p. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Garcia</surname> <given-names>S</given-names></string-name>, <string-name><surname>Parmisano</surname> <given-names>A</given-names></string-name>, <string-name><surname>Erquiaga</surname> <given-names>MJ</given-names></string-name></person-group>. <article-title>IoT-23: a labeled dataset with malicious and benign IoT network traffic</article-title>. <year>2020 [cited 2026 Jan 1]</year>. Available from: <ext-link ext-link-type="uri" xlink:href="https://www.kaggle.com/datasets/astralfate/iot23-dataset">https://www.kaggle.com/datasets/astralfate/iot23-dataset</ext-link>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Alsaedi</surname> <given-names>A</given-names></string-name>, <string-name><surname>Moustafa</surname> <given-names>N</given-names></string-name>, <string-name><surname>Tari</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Mahmood</surname> <given-names>AN</given-names></string-name>, <string-name><surname>Anwar</surname> <given-names>A</given-names></string-name></person-group>. <article-title>TON_IoT telemetry dataset: a new generation dataset of IoT and IIoT for data-driven intrusion detection systems</article-title>. <source>IEEE Access</source>. <year>2020</year>;<volume>8</volume>:<fpage>165130</fpage>&#x2013;<lpage>50</lpage>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Mathur</surname> <given-names>A</given-names></string-name></person-group>. <article-title>NATICUSdroid (android permissions) [dataset]</article-title>. <year>2021 [cited 2026 Jan 1]</year>. Available from: <ext-link ext-link-type="uri" xlink:href="https://www.kaggle.com/datasets/budhadityadutta/naticusdroid-android-permissions">https://www.kaggle.com/datasets/budhadityadutta/naticusdroid-android-permissions</ext-link>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Ribeiro</surname> <given-names>MT</given-names></string-name>, <string-name><surname>Singh</surname> <given-names>S</given-names></string-name>, <string-name><surname>Guestrin</surname> <given-names>C</given-names></string-name></person-group>. <article-title>&#x201C;Why should I trust you?&#x201D;: explaining the predictions of any classifier</article-title>. In: <conf-name>Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, KDD&#x2019;16; 2016 Aug 13&#x2013;17</conf-name>; <publisher-loc>San Francisco, CA, USA</publisher-loc>. p. <fpage>1135</fpage>&#x2013;<lpage>44</lpage>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Salzberg</surname> <given-names>SL</given-names></string-name></person-group>. <source>C4.5: programs for machine learning by j. ross quinlan</source>. <publisher-loc>Burlington, MA, USA</publisher-loc>: <publisher-name>Morgan Kaufmann Publishers, Inc.</publisher-name>; <year>1993</year>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Lundberg</surname> <given-names>SM</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>S-I</given-names></string-name></person-group>. <article-title>A unified approach to interpreting model predictions</article-title>. In: <conf-name>Proceedings of the 31st International Conference on Neural Information Processing Systems (NIPS 2017); 2017 Dec 4&#x2013;9</conf-name>; <publisher-loc>Long Beach, CA, USA</publisher-loc>. p. <fpage>4768</fpage>&#x2013;<lpage>77</lpage>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chawla</surname> <given-names>NV</given-names></string-name>, <string-name><surname>Bowyer</surname> <given-names>KW</given-names></string-name>, <string-name><surname>Hall</surname> <given-names>LO</given-names></string-name>, <string-name><surname>Kegelmeyer</surname> <given-names>WP</given-names></string-name></person-group>. <article-title>SMOTE: synthetic minority over-sampling technique</article-title>. <source>J Artif Intell Res</source>. <year>2002</year>;<volume>16</volume>:<fpage>321</fpage>&#x2013;<lpage>57</lpage>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>IBM</collab></person-group>. <article-title>What is explainable AI? [cited 2023 Sep 1]</article-title>. Available from: <ext-link ext-link-type="uri" xlink:href="https://www.ibm.com/topics/explainable-ai">https://www.ibm.com/topics/explainable-ai</ext-link>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Scaife</surname> <given-names>N</given-names></string-name>, <string-name><surname>Carter</surname> <given-names>H</given-names></string-name>, <string-name><surname>Traynor</surname> <given-names>P</given-names></string-name>, <string-name><surname>Butler</surname> <given-names>KRB</given-names></string-name></person-group>. <article-title>Cryptolock (and drop it): stopping ransomware attacks on user data</article-title>. In: <conf-name>Proceedings of 2016 IEEE 36th International Conference on Distributed Computing Systems (ICDCS); 2016 Jun 27&#x2013;30</conf-name>; <publisher-loc>Nara, Japan</publisher-loc>. p. <fpage>303</fpage>&#x2013;<lpage>12</lpage>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Kharaz</surname> <given-names>A</given-names></string-name>, <string-name><surname>Arshad</surname> <given-names>S</given-names></string-name>, <string-name><surname>Mulliner</surname> <given-names>C</given-names></string-name>, <string-name><surname>Robertson</surname> <given-names>W</given-names></string-name>, <string-name><surname>Kirda</surname> <given-names>E</given-names></string-name></person-group>. <article-title>UNVEIL: a large-scale, automated approach to detecting ransomware</article-title>. In: <conf-name>Proceedings of 25th USENIX Security Symposium (USENIX Security 16); 2016 Aug 10&#x2013;12</conf-name>; <publisher-loc>Austin, TX, USA</publisher-loc>. p. <fpage>757</fpage>&#x2013;<lpage>72</lpage>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Chen</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Bridges</surname> <given-names>RA</given-names></string-name></person-group>. <article-title>Automated behavioral analysis of malware: a case study of wannacry ransomware</article-title>. In: <conf-name>Proceedings of 2017 16th IEEE International Conference on machine learning and applications (ICMLA); 2017 Dec 18&#x2013;21</conf-name>; <publisher-loc>Cancun, Mexico</publisher-loc>. p. <fpage>454</fpage>&#x2013;<lpage>60</lpage>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Homayoun</surname> <given-names>S</given-names></string-name>, <string-name><surname>Dehghantanha</surname> <given-names>A</given-names></string-name>, <string-name><surname>Ahmadzadeh</surname> <given-names>M</given-names></string-name>, <string-name><surname>Hashemi</surname> <given-names>S</given-names></string-name>, <string-name><surname>Khayami</surname> <given-names>R</given-names></string-name></person-group>. <article-title>Know abnormal, find evil: frequent pattern mining for ransomware threat hunting and intelligence</article-title>. <source>IEEE Trans Emerg Top Comput</source>. <year>2017</year>;<volume>8</volume>(<issue>2</issue>):<fpage>341</fpage>&#x2013;<lpage>51</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tetc.2017.2756908</pub-id>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hampton</surname> <given-names>N</given-names></string-name>, <string-name><surname>Baig</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Zeadally</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Ransomware behavioural analysis on windows platforms</article-title>. <source>J Inf Secur Appl</source>. <year>2018</year>;<volume>40</volume>(<issue>2</issue>):<fpage>44</fpage>&#x2013;<lpage>51</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.jisa.2018.02.008</pub-id>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kok</surname> <given-names>SH</given-names></string-name>, <string-name><surname>Abdullah</surname> <given-names>A</given-names></string-name>, <string-name><surname>Jhanjhi</surname> <given-names>NZ</given-names></string-name>, <string-name><surname>Supramaniam</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Prevention of crypto-ransomware using a pre-encryption detection algorithm</article-title>. <source>Computers</source>. <year>2019</year>;<volume>8</volume>(<issue>4</issue>):<fpage>79</fpage>. doi:<pub-id pub-id-type="doi">10.3390/computers8040079</pub-id>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kok</surname> <given-names>SH</given-names></string-name>, <string-name><surname>Abdullah</surname> <given-names>A</given-names></string-name>, <string-name><surname>Jhanjhi</surname> <given-names>NZ</given-names></string-name></person-group>. <article-title>Early detection of crypto-ransomware using pre-encryption detection algorithm</article-title>. <source>J King Saud Univ&#x2014;Comput Inf Sci</source>. <year>2022</year>;<volume>34</volume>(<issue>5</issue>):<fpage>1984</fpage>&#x2013;<lpage>99</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.jksuci.2020.06.012</pub-id>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hwang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>J</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>S</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>K</given-names></string-name></person-group>. <article-title>Two-stage ransomware detection using dynamic analysis and machine learning techniques</article-title>. <source>Wirel Pers Commun</source>. <year>2020</year>;<volume>112</volume>(<issue>4</issue>):<fpage>2597</fpage>&#x2013;<lpage>609</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s11277-020-07166-9</pub-id>.</mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ullah</surname> <given-names>F</given-names></string-name>, <string-name><surname>Javaid</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Salam</surname> <given-names>A</given-names></string-name>, <string-name><surname>Ahmad</surname> <given-names>M</given-names></string-name>, <string-name><surname>Sarwar</surname> <given-names>N</given-names></string-name>, <string-name><surname>Shah</surname> <given-names>D</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Modified decision tree technique for ransomware detection at runtime through API calls</article-title>. <source>Sci Program</source>. <year>2020</year>;<volume>2020</volume>(<issue>1</issue>):<fpage>8845833</fpage>. doi:<pub-id pub-id-type="doi">10.1155/2020/8845833</pub-id>.</mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Molina</surname> <given-names>RMA</given-names></string-name>, <string-name><surname>Torabi</surname> <given-names>S</given-names></string-name>, <string-name><surname>Sarieddine</surname> <given-names>K</given-names></string-name>, <string-name><surname>Bou-Harb</surname> <given-names>E</given-names></string-name>, <string-name><surname>Bouguila</surname> <given-names>N</given-names></string-name>, <string-name><surname>Assi</surname> <given-names>C</given-names></string-name></person-group>. <article-title>On ransomware family attribution using pre-attack paranoia activities</article-title>. <source>IEEE Trans Netw Serv Manag</source>. <year>2021</year>;<volume>19</volume>(<issue>1</issue>):<fpage>19</fpage>&#x2013;<lpage>36</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tnsm.2021.3112056</pub-id>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Herrera-Silva</surname> <given-names>JA</given-names></string-name>, <string-name><surname>Hern&#x00E1;ndez-&#x00C1;lvarez</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Dynamic feature dataset for ransomware detection using machine learning algorithms</article-title>. <source>Sensors</source>. <year>2023</year>;<volume>23</volume>(<issue>3</issue>):<fpage>1053</fpage>. doi:<pub-id pub-id-type="doi">10.3390/s23031053</pub-id>; <pub-id pub-id-type="pmid">36772092</pub-id></mixed-citation></ref>
<ref id="ref-37"><label>[37]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Javaheri</surname> <given-names>D</given-names></string-name>, <string-name><surname>Hosseinzadeh</surname> <given-names>M</given-names></string-name>, <string-name><surname>Rahmani</surname> <given-names>AM</given-names></string-name></person-group>. <article-title>Detection and elimination of spyware and ransomware by intercepting kernel-level system routines</article-title>. <source>IEEE Access</source>. <year>2018</year>;<volume>6</volume>:<fpage>78321</fpage>&#x2013;<lpage>32</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2018.2884964</pub-id>.</mixed-citation></ref>
<ref id="ref-38"><label>[38]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>L</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>A</given-names></string-name>, <string-name><surname>Cai</surname> <given-names>L</given-names></string-name>, <string-name><surname>Meng</surname> <given-names> D</given-names></string-name></person-group>. <article-title>Ranker: early ransomware detection through kernel-level behavioral analysis</article-title>. <source>IEEE Trans Inf Forensics Secur</source>. <year>2024</year>;<volume>19</volume>(<issue>11</issue>):<fpage>6113</fpage>&#x2013;<lpage>27</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tifs.2024.3410511</pub-id>.</mixed-citation></ref>
<ref id="ref-39"><label>[39]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tang</surname> <given-names>F</given-names></string-name>, <string-name><surname>Ma</surname> <given-names>B</given-names></string-name>, <string-name><surname>Li</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>F</given-names></string-name>, <string-name><surname>Su</surname> <given-names>J</given-names></string-name>, <string-name><surname>Ma</surname> <given-names>J</given-names></string-name></person-group>. <article-title>RansomSpector: an introspection-based approach to detect crypto ransomware</article-title>. <source>Comput Secur</source>. <year>2020</year>;<volume>97</volume>(<issue>5</issue>):<fpage>101997</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2020.101997</pub-id>.</mixed-citation></ref>
<ref id="ref-40"><label>[40]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>McIntosh</surname> <given-names>T</given-names></string-name>, <string-name><surname>Kayes</surname> <given-names>ASM</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>YP</given-names></string-name>, <string-name><surname>Ng</surname> <given-names>A</given-names></string-name>, <string-name><surname>Watters</surname> <given-names>P</given-names></string-name></person-group>. <article-title>Dynamic user-centric access control for detection of ransomware attacks</article-title>. <source>Comput Secur</source>. <year>2021</year>;<volume>111</volume>(<issue>6</issue>):<fpage>102461</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2021.102461</pub-id>.</mixed-citation></ref>
<ref id="ref-41"><label>[41]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Al Sabeh</surname> <given-names>A</given-names></string-name>, <string-name><surname>Safa</surname> <given-names>H</given-names></string-name>, <string-name><surname>Bou-Harb</surname> <given-names>E</given-names></string-name>, <string-name><surname>Crichigno</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Exploiting ransomware paranoia for execution prevention</article-title>. In: <conf-name>Proceedings of 2020 IEEE International Conference on Communications (ICC); 2020 Jun 7&#x2013;11</conf-name>; <publisher-loc>Dublin, Ireland</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-42"><label>[42]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ramesh</surname> <given-names>G</given-names></string-name>, <string-name><surname>Menen</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Automated dynamic approach for detecting ransomware using finite-state machine</article-title>. <source>Decis Support Syst</source>. <year>2020</year>;<volume>138</volume>(<issue>6</issue>):<fpage>113400</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.dss.2020.113400</pub-id>.</mixed-citation></ref>
<ref id="ref-43"><label>[43]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Abbasi</surname> <given-names>MS</given-names></string-name>, <string-name><surname>Al-Sahaf</surname> <given-names>H</given-names></string-name>, <string-name><surname>Mansoori</surname> <given-names>M</given-names></string-name>, <string-name><surname>Welch</surname> <given-names>I</given-names></string-name></person-group>. <article-title>Behavior-based ransomware classification: a particle swarm optimization wrapper-based approach for feature selection</article-title>. <source>Appl Soft Comput</source>. <year>2022</year>;<volume>121</volume>:<fpage>108744</fpage>.</mixed-citation></ref>
<ref id="ref-44"><label>[44]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ayub</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Siraj</surname> <given-names>A</given-names></string-name>, <string-name><surname>Filar</surname> <given-names>B</given-names></string-name>, <string-name><surname>Gupta</surname> <given-names>M</given-names></string-name></person-group>. <article-title>RWArmor: a static-informed dynamic analysis approach for early detection of cryptographic windows ransomware</article-title>. <source>Int J Inf Secur</source>. <year>2024</year>;<volume>23</volume>(<issue>1</issue>):<fpage>533</fpage>&#x2013;<lpage>56</lpage>.</mixed-citation></ref>
<ref id="ref-45"><label>[45]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Hou</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Guo</surname> <given-names>L</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>C</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Yin</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Li</surname> <given-names>S</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>An empirical study of data disruption by ransomware attacks</article-title>. In: <conf-name>Proceedings of the IEEE/ACM 46th International Conference on Software Engineering, ICSE&#x2019;24; 2024 Apr 14&#x2013;20; Lisbon, Portugal</conf-name>.</mixed-citation></ref>
<ref id="ref-46"><label>[46]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Marcinkowski</surname> <given-names>B</given-names></string-name>, <string-name><surname>Goschorska</surname> <given-names>M</given-names></string-name>, <string-name><surname>Wile&#x0144;ska</surname> <given-names>N</given-names></string-name>, <string-name><surname>Siuta</surname> <given-names>J</given-names></string-name>, <string-name><surname>Kajdanowicz</surname> <given-names>T</given-names></string-name></person-group>. <article-title>MIRAD: a method for interpretable ransomware attack detection</article-title>. <source>IEEE Access</source>. <year>2024</year>;<volume>12</volume>:<fpage>133810</fpage>&#x2013;<lpage>20</lpage>.</mixed-citation></ref>
<ref id="ref-47"><label>[47]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>S</given-names></string-name>, <string-name><surname>Dong</surname> <given-names>F</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>H</given-names></string-name></person-group>. <article-title>CanCal: towards real-time and lightweight ransomware detection and response in industrial environments</article-title>. In: <conf-name>Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, CCS&#x2019;24; 2024 Oct 14&#x2013;18; Salt Lake City, UT, USA</conf-name>. p. <fpage>2326</fpage>&#x2013;<lpage>40</lpage>.</mixed-citation></ref>
<ref id="ref-48"><label>[48]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Xiao</surname> <given-names>X</given-names></string-name>, <string-name><surname>Mercaldo</surname> <given-names>F</given-names></string-name>, <string-name><surname>Ni</surname> <given-names>S</given-names></string-name>, <string-name><surname>Martinelli</surname> <given-names>F</given-names></string-name>, <string-name><surname>Sangaiah</surname> <given-names>AK</given-names></string-name></person-group>. <article-title>Classification of ransomware families with machine learning based on N-gram of opcodes</article-title>. <source>Future Gener Comput Syst</source>. <year>2019</year>;<volume>90</volume>(<issue>3</issue>):<fpage>211</fpage>&#x2013;<lpage>21</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.future.2018.07.052</pub-id>.</mixed-citation></ref>
<ref id="ref-49"><label>[49]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Su</surname> <given-names>D</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>W</given-names></string-name></person-group>. <article-title>Detecting android locker-ransomware on Chinese social networks</article-title>. <source>IEEE Access</source>. <year>2018</year>;<volume>7</volume>:<fpage>20381</fpage>&#x2013;<lpage>93</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2018.2888568</pub-id>.</mixed-citation></ref>
<ref id="ref-50"><label>[50]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cohen</surname> <given-names>A</given-names></string-name>, <string-name><surname>Nissim</surname> <given-names>N</given-names></string-name></person-group>. <article-title>Trusted detection of ransomware in a private cloud using machine learning methods leveraging meta-features from volatile memory</article-title>. <source>Expert Syst Appl</source>. <year>2018</year>;<volume>102</volume>(<issue>5</issue>):<fpage>158</fpage>&#x2013;<lpage>78</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.eswa.2018.02.039</pub-id>.</mixed-citation></ref>
<ref id="ref-51"><label>[51]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Aljabri</surname> <given-names>M</given-names></string-name>, <string-name><surname>Alhaidari</surname> <given-names>F</given-names></string-name>, <string-name><surname>Albuainain</surname> <given-names>A</given-names></string-name>, <string-name><surname>Alrashidi</surname> <given-names>S</given-names></string-name>, <string-name><surname>Alansari</surname> <given-names>J</given-names></string-name>, <string-name><surname>Alqahtani</surname> <given-names>W</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Ransomware detection based on machine learning using memory features</article-title>. <source>Egypt Inform J</source>. <year>2024</year>;<volume>25</volume>(<issue>12</issue>):<fpage>100445</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.eij.2024.100445</pub-id>.</mixed-citation></ref>
<ref id="ref-52"><label>[52]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ahmed</surname> <given-names>YA</given-names></string-name>, <string-name><surname>Ko&#x00E7;er</surname> <given-names>B</given-names></string-name>, <string-name><surname>Huda</surname> <given-names>S</given-names></string-name>, <string-name><surname>Al-Rimy</surname> <given-names>BAS</given-names></string-name>, <string-name><surname>Hassan</surname> <given-names>MM</given-names></string-name></person-group>. <article-title>A system call refinement-based enhanced minimum redundancy maximum relevance method for ransomware early detection</article-title>. <source>J Netw Comput Appl</source>. <year>2020</year>;<volume>167</volume>(<issue>5</issue>):<fpage>102753</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.jnca.2020.102753</pub-id>.</mixed-citation></ref>
<ref id="ref-53"><label>[53]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Khan</surname> <given-names>F</given-names></string-name>, <string-name><surname>Ncube</surname> <given-names>C</given-names></string-name>, <string-name><surname>Ramasamy</surname> <given-names>LK</given-names></string-name>, <string-name><surname>Kadry</surname> <given-names>S</given-names></string-name>, <string-name><surname>Nam</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>A digital DNA sequencing engine for ransomware detection using machine learning</article-title>. <source>IEEE Access</source>. <year>2020</year>;<volume>8</volume>:<fpage>119710</fpage>&#x2013;<lpage>9</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2020.3003785</pub-id>.</mixed-citation></ref>
<ref id="ref-54"><label>[54]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Arabo</surname> <given-names>A</given-names></string-name>, <string-name><surname>Dijoux</surname> <given-names>R</given-names></string-name>, <string-name><surname>Poulain</surname> <given-names>T</given-names></string-name>, <string-name><surname>Chevalier</surname> <given-names>G</given-names></string-name></person-group>. <article-title>Detecting ransomware using process behavior analysis</article-title>. <source>Procedia Comput Sci</source>. <year>2020</year>;<volume>168</volume>(<issue>14</issue>):<fpage>289</fpage>&#x2013;<lpage>96</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.procs.2020.02.249</pub-id>.</mixed-citation></ref>
<ref id="ref-55"><label>[55]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Jain</surname> <given-names>S</given-names></string-name>, <string-name><surname>Gera</surname> <given-names>T</given-names></string-name>, <string-name><surname>Gill</surname> <given-names>R</given-names></string-name>, <string-name><surname>Bhardwaj</surname> <given-names>V</given-names></string-name></person-group>. <article-title>CrossF-Droid: integrating filter, wrapper, and regularization methods for enhanced predictive modeling to analyze android ransomware</article-title>. <source>IEEE Access</source>. <year>2025</year>;<volume>13</volume>(<issue>3</issue>):<fpage>190075</fpage>&#x2013;<lpage>92</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2025.3624238</pub-id>.</mixed-citation></ref>
<ref id="ref-56"><label>[56]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Fernandez Maimo</surname> <given-names>L</given-names></string-name>, <string-name><surname>Huertas Celdran</surname> <given-names>A</given-names></string-name>, <string-name><surname>Perales Gomez</surname> <given-names>AL</given-names></string-name>, <string-name><surname>Garcia Clemente</surname> <given-names>FJ</given-names></string-name>, <string-name><surname>Weimer</surname> <given-names>J</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>I</given-names></string-name></person-group>. <article-title>Intelligent and dynamic ransomware spread detection and mitigation in integrated clinical environments</article-title>. <source>Sensors</source>. <year>2019</year>;<volume>19</volume>(<issue>5</issue>):<fpage>1114</fpage>. doi:<pub-id pub-id-type="doi">10.3390/s19051114</pub-id>; <pub-id pub-id-type="pmid">30841592</pub-id></mixed-citation></ref>
<ref id="ref-57"><label>[57]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Poudyal</surname> <given-names>S</given-names></string-name>, <string-name><surname>Dasgupta</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Analysis of crypto-ransomware using ML-based multi-level profiling</article-title>. <source>IEEE Access</source>. <year>2021</year>;<volume>9</volume>:<fpage>122532</fpage>&#x2013;<lpage>47</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2021.3109260</pub-id>.</mixed-citation></ref>
<ref id="ref-58"><label>[58]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Iqbal</surname> <given-names>MJ</given-names></string-name>, <string-name><surname>Aurangzeb</surname> <given-names>S</given-names></string-name>, <string-name><surname>Aleem</surname> <given-names>M</given-names></string-name>, <string-name><surname>Srivastava</surname> <given-names>G</given-names></string-name>, <string-name><surname>Lin</surname> <given-names>J</given-names></string-name></person-group>. <article-title>RThreatDroid: a ransomware detection approach to secure IoT based healthcare systems</article-title>. <source>IEEE Trans Netw Sci Eng</source>. <year>2022</year>;<volume>10</volume>(<issue>5</issue>):<fpage>2574</fpage>&#x2013;<lpage>83</lpage>.</mixed-citation></ref>
<ref id="ref-59"><label>[59]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ba&#x2019;abbad</surname> <given-names>I</given-names></string-name>, <string-name><surname>Batarfi</surname> <given-names>O</given-names></string-name></person-group>. <article-title>Proactive ransomware detection using extremely fast decision tree (EFDT) algorithm: a case study</article-title>. <source>Computers</source>. <year>2023</year>;<volume>12</volume>(<issue>6</issue>):<fpage>121</fpage>. doi:<pub-id pub-id-type="doi">10.3390/computers12060121</pub-id>.</mixed-citation></ref>
<ref id="ref-60"><label>[60]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Jemal</surname> <given-names>M</given-names></string-name>, <string-name><surname>Lo</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Detection of ransomware attack using deep learning</article-title>. In: <conf-name>Proceedings of the 2023 IEEE Conference on Dependable and Secure Computing (DSC); 2023 Nov 7&#x2013;9</conf-name>; <publisher-loc>Tampa, FL, USA</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>9</lpage>.</mixed-citation></ref>
<ref id="ref-61"><label>[61]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Dib</surname> <given-names>O</given-names></string-name>, <string-name><surname>Nan</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Machine learning-based ransomware classification of Bitcoin transactions</article-title>. <source>J King Saud Univ Comput Inf Sci</source>. <year>2024</year>;<volume>36</volume>(<issue>1</issue>):<fpage>101925</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.jksuci.2024.101925</pub-id>.</mixed-citation></ref>
<ref id="ref-62"><label>[62]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rios-Ochoa</surname> <given-names>E</given-names></string-name>, <string-name><surname>P&#x00E9;rez-D&#x00ED;az</surname> <given-names>JA</given-names></string-name>, <string-name><surname>Garc&#x00ED;a-Ceja</surname> <given-names>E</given-names></string-name>, <string-name><surname>Rodr&#x00ED;guez-Hern&#x00E1;ndez</surname> <given-names>G</given-names></string-name></person-group>. <article-title>Ransomware family attribution with ML: a comprehensive evaluation of datasets quality, models comparison, and a simulated deployment</article-title>. <source>IEEE Access</source>. <year>2025</year>;<volume>13</volume>:<fpage>108108</fpage>&#x2013;<lpage>26</lpage>.</mixed-citation></ref>
<ref id="ref-63"><label>[63]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Homayoun</surname> <given-names>S</given-names></string-name>, <string-name><surname>Dehghantanha</surname> <given-names>A</given-names></string-name>, <string-name><surname>Ahmadzadeh</surname> <given-names>M</given-names></string-name>, <string-name><surname>Hashemi</surname> <given-names>S</given-names></string-name>, <string-name><surname>Khayami</surname> <given-names>R</given-names></string-name>, <string-name><surname>Choo</surname> <given-names>K</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>DRTHIS: deep ransomware threat hunting and intelligence system at the fog layer</article-title>. <source>Future Gener Comput Syst</source>. <year>2019</year>;<volume>90</volume>:<fpage>94</fpage>&#x2013;<lpage>104</lpage>.</mixed-citation></ref>
<ref id="ref-64"><label>[64]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cen</surname> <given-names>M</given-names></string-name>, <string-name><surname>Jiang</surname> <given-names>F</given-names></string-name>, <string-name><surname>Doss</surname> <given-names>R</given-names></string-name></person-group>. <article-title>RansoGuard: a RNN-based framework leveraging pre-attack sensitive APIs for early ransomware detection</article-title>. <source>Comput Secur</source>. <year>2025</year>;<volume>150</volume>:<fpage>104293</fpage>.</mixed-citation></ref>
<ref id="ref-65"><label>[65]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ispahany</surname> <given-names>J</given-names></string-name>, <string-name><surname>Islam</surname> <given-names>MR</given-names></string-name>, <string-name><surname>Arif Khan</surname> <given-names>M</given-names></string-name>, <string-name><surname>Islam</surname> <given-names>MZ</given-names></string-name></person-group>. <article-title>iCNN-LSTM&#x002B;: a batch-based incremental ransomware detection system using sysmon</article-title>. <source>IEEE Access</source>. <year>2025</year>;<volume>13</volume>:<fpage>87978</fpage>&#x2013;<lpage>98</lpage>.</mixed-citation></ref>
<ref id="ref-66"><label>[66]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>B</given-names></string-name>, <string-name><surname>Xiao</surname> <given-names>W</given-names></string-name>, <string-name><surname>Xiao</surname> <given-names>X</given-names></string-name>, <string-name><surname>Sangaiah</surname> <given-names>AK</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Ransomware classification using patch-based CNN and self-attention network on embedded N-grams of opcodes</article-title>. <source>Future Gener Comput Syst</source>. <year>2020</year>;<volume>110</volume>(<issue>4</issue>):<fpage>708</fpage>&#x2013;<lpage>20</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.future.2019.09.025</pub-id>.</mixed-citation></ref>
<ref id="ref-67"><label>[67]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lachtar</surname> <given-names>N</given-names></string-name>, <string-name><surname>Ibdah</surname> <given-names>D</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>H</given-names></string-name>, <string-name><surname>Bacha</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Ransomshield: a visualization approach to defending mobile systems against ransomware</article-title>. <source>ACM Trans Priv Secur</source>. <year>2023</year>;<volume>26</volume>(<issue>3</issue>):<fpage>1</fpage>&#x2013;<lpage>30</lpage>.</mixed-citation></ref>
<ref id="ref-68"><label>[68]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Karbab</surname> <given-names>EB</given-names></string-name>, <string-name><surname>Debbabi</surname> <given-names>M</given-names></string-name>, <string-name><surname>Derhab</surname> <given-names>A</given-names></string-name></person-group>. <article-title>SwiftR: cross-platform ransomware fingerprinting using hierarchical neural networks on hybrid features</article-title>. <source>Expert Syst Appl</source>. <year>2023</year>;<volume>225</volume>:<fpage>120017</fpage>.</mixed-citation></ref>
<ref id="ref-69"><label>[69]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zhu</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Dual generative adversarial networks based unknown encryption ransomware attack detection</article-title>. <source>IEEE Access</source>. <year>2021</year>;<volume>10</volume>:<fpage>900</fpage>&#x2013;<lpage>13</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2021.3128024</pub-id>.</mixed-citation></ref>
<ref id="ref-70"><label>[70]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Gazzan</surname> <given-names>M</given-names></string-name>, <string-name><surname>Sheldon</surname> <given-names>FT</given-names></string-name></person-group>. <article-title>An enhanced Minimax loss function technique in generative adversarial network for ransomware behavior prediction</article-title>. <source>Future Internet</source>. <year>2023</year>;<volume>15</volume>(<issue>10</issue>):<fpage>318</fpage>. doi:<pub-id pub-id-type="doi">10.3390/fi15100318</pub-id>.</mixed-citation></ref>
<ref id="ref-71"><label>[71]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Jang-Jaccard</surname> <given-names>J</given-names></string-name>, <string-name><surname>Singh</surname> <given-names>A</given-names></string-name>, <string-name><surname>Welch</surname> <given-names>I</given-names></string-name>, <string-name><surname>Al-Sahaf</surname> <given-names>H</given-names></string-name>, <string-name><surname>Camtepe</surname> <given-names>S</given-names></string-name></person-group>. <article-title>A few-shot meta-learning based siamese neural network using entropy features for ransomware classification</article-title>. <source>Comput Secur</source>. <year>2022</year>;<volume>117</volume>(<issue>7</issue>):<fpage>102691</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2022.102691</pub-id>.</mixed-citation></ref>
<ref id="ref-72"><label>[72]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ganfure</surname> <given-names>GO</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>C-F</given-names></string-name>, <string-name><surname>Chang</surname> <given-names>Y-H</given-names></string-name>, <string-name><surname>Shih</surname> <given-names>W-H</given-names></string-name></person-group>. <article-title>Deepware: imaging performance counters with deep learning to detect ransomware</article-title>. <source>IEEE Trans Comput</source>. <year>2022</year>;<volume>72</volume>(<issue>3</issue>):<fpage>600</fpage>&#x2013;<lpage>13</lpage>.</mixed-citation></ref>
<ref id="ref-73"><label>[73]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Thummapudi</surname> <given-names>K</given-names></string-name>, <string-name><surname>Lama</surname> <given-names>P</given-names></string-name>, <string-name><surname>Boppana</surname> <given-names>RV</given-names></string-name></person-group>. <article-title>Detection of ransomware attacks using processor and disk usage data</article-title>. <source>IEEE Access</source>. <year>2023</year>;<volume>11</volume>:<fpage>51395</fpage>&#x2013;<lpage>407</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2023.3279819</pub-id>.</mixed-citation></ref>
<ref id="ref-74"><label>[74]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lan</surname> <given-names>K</given-names></string-name>, <string-name><surname>Li</surname> <given-names>G</given-names></string-name>, <string-name><surname>Huang</surname> <given-names>W</given-names></string-name>, <string-name><surname>Li</surname> <given-names>J</given-names></string-name></person-group>. <article-title>HFL-RD: heterogeneous federated learning-empowered ransomware detection via APIs and traffic features</article-title>. <source>IEEE Trans Netw Serv Manag</source>. <year>2025</year>;<volume>22</volume>(<issue>5</issue>):<fpage>4096</fpage>&#x2013;<lpage>111</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tnsm.2025.3574716</pub-id>.</mixed-citation></ref>
<ref id="ref-75"><label>[75]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hossain</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Hasan</surname> <given-names>T</given-names></string-name>, <string-name><surname>Ahmed</surname> <given-names>F</given-names></string-name>, <string-name><surname>Cheragee</surname> <given-names>SH</given-names></string-name>, <string-name><surname>Kanchan</surname> <given-names>MH</given-names></string-name>, <string-name><surname>Haque</surname> <given-names>MA</given-names></string-name></person-group>. <article-title>Towards superior android ransomware detection: an ensemble machine learning perspective</article-title>. <source>Cyber Secur Appl</source>. <year>2025</year>;<volume>3</volume>:<fpage>100076</fpage>.</mixed-citation></ref>
<ref id="ref-76"><label>[76]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Gulmez</surname> <given-names>S</given-names></string-name>, <string-name><surname>Kakisim</surname> <given-names>AG</given-names></string-name>, <string-name><surname>Sogukpinar</surname> <given-names>I</given-names></string-name></person-group>. <article-title>XRan: explainable deep learning-based ransomware detection using dynamic analysis</article-title>. <source>Comput Secur</source>. <year>2024</year>;<volume>139</volume>:<fpage>103703</fpage>.</mixed-citation></ref>
<ref id="ref-77"><label>[77]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kabuye</surname> <given-names>H</given-names></string-name>, <string-name><surname>Issac</surname> <given-names>B</given-names></string-name>, <string-name><surname>Yumlembam</surname> <given-names>R</given-names></string-name>, <string-name><surname>Neera</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Explainable and uncertainty aware AI-based ransomware detection</article-title>. <source>IEEE Access</source>. <year>2025</year>;<volume>13</volume>(<issue>3</issue>):<fpage>106573</fpage>&#x2013;<lpage>89</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2025.3581424</pub-id>.</mixed-citation></ref>
<ref id="ref-78"><label>[78]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sharmeen</surname> <given-names>S</given-names></string-name>, <string-name><surname>Ahmed</surname> <given-names>YA</given-names></string-name>, <string-name><surname>Huda</surname> <given-names>S</given-names></string-name>, <string-name><surname>Ko&#x00E7;er</surname> <given-names>B</given-names></string-name>, <string-name><surname>Hassan</surname> <given-names>MM</given-names></string-name></person-group>. <article-title>Avoiding future digital extortion through robust protection against ransomware threats using deep learning based adaptive approaches</article-title>. <source>IEEE Access</source>. <year>2020</year>;<volume>8</volume>:<fpage>24522</fpage>&#x2013;<lpage>34</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2020.2970466</pub-id>.</mixed-citation></ref>
<ref id="ref-79"><label>[79]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Urooj</surname> <given-names>U</given-names></string-name>, <string-name><surname>Al-Rimy</surname> <given-names>BAS</given-names></string-name>, <string-name><surname>Zainal</surname> <given-names>AB</given-names></string-name>, <string-name><surname>Saeed</surname> <given-names>F</given-names></string-name>, <string-name><surname>Abdelmaboud</surname> <given-names>A</given-names></string-name>, <string-name><surname>Nagmeldin</surname> <given-names>W</given-names></string-name></person-group>. <article-title>Addressing behavioral drift in ransomware early detection through weighted generative adversarial networks</article-title>. <source>IEEE Access</source>. <year>2023</year>;<volume>12</volume>:<fpage>3910</fpage>&#x2013;<lpage>25</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2023.3348451</pub-id>.</mixed-citation></ref>
<ref id="ref-80"><label>[80]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Al-Rimy</surname> <given-names>BAS</given-names></string-name>, <string-name><surname>Maarof</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Alazab</surname> <given-names>M</given-names></string-name>, <string-name><surname>Alsolami</surname> <given-names>F</given-names></string-name>, <string-name><surname>Shaid</surname> <given-names>SZM</given-names></string-name>, <string-name><surname>Ghaleb</surname> <given-names>FA</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>A pseudo feedback-based annotated TF-IDF technique for dynamic crypto-ransomware pre-encryption boundary delineation and features extraction</article-title>. <source>IEEE Access</source>. <year>2020</year>;<volume>8</volume>:<fpage>140586</fpage>&#x2013;<lpage>98</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2020.3012674</pub-id>.</mixed-citation></ref>
<ref id="ref-81"><label>[81]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Al-Rimy</surname> <given-names>BAS</given-names></string-name>, <string-name><surname>Maarof</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Alazab</surname> <given-names>M</given-names></string-name>, <string-name><surname>Shaid</surname> <given-names>SZM</given-names></string-name>, <string-name><surname>Ghaleb</surname> <given-names>FA</given-names></string-name>, <string-name><surname>Almalawi</surname> <given-names>A</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Redundancy coefficient gradual up-weighting-based mutual information feature selection technique for crypto-ransomware early detection</article-title>. <source>Future Gener Comput Syst</source>. <year>2021</year>;<volume>115</volume>(<issue>5</issue>):<fpage>641</fpage>&#x2013;<lpage>58</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.future.2020.10.002</pub-id>.</mixed-citation></ref>
<ref id="ref-82"><label>[82]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cen</surname> <given-names>M</given-names></string-name>, <string-name><surname>Deng</surname> <given-names>X</given-names></string-name>, <string-name><surname>Jiang</surname> <given-names>F</given-names></string-name>, <string-name><surname>Doss</surname> <given-names>R</given-names></string-name></person-group>. <article-title>Zero-Ran Sniff: a zero-day ransomware early detection method based on zero-shot learning</article-title>. <source>Comput Secur</source>. <year>2024</year>;<volume>142</volume>:<fpage>103849</fpage>.</mixed-citation></ref>
<ref id="ref-83"><label>[83]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Fernando</surname> <given-names>DW</given-names></string-name>, <string-name><surname>Komninos</surname> <given-names>N</given-names></string-name></person-group>. <article-title>FeSAD ransomware detection framework with machine learning using adaption to concept drift</article-title>. <source>Comput Secur</source>. <year>2024</year>;<volume>137</volume>(<issue>7</issue>):<fpage>103629</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2023.103629</pub-id>.</mixed-citation></ref>
<ref id="ref-84"><label>[84]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cabaj</surname> <given-names>K</given-names></string-name>, <string-name><surname>Mazurczyk</surname> <given-names>W</given-names></string-name></person-group>. <article-title>Using software-defined networking for ransomware mitigation: the case of CryptoWall</article-title>. <source>IEEE Netw</source>. <year>2016</year>;<volume>30</volume>(<issue>6</issue>):<fpage>14</fpage>&#x2013;<lpage>20</lpage>. doi:<pub-id pub-id-type="doi">10.1109/mnet.2016.1600110nm</pub-id>.</mixed-citation></ref>
<ref id="ref-85"><label>[85]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cabaj</surname> <given-names>K</given-names></string-name>, <string-name><surname>Gregorczyk</surname> <given-names>M</given-names></string-name>, <string-name><surname>Mazurczyk</surname> <given-names>W</given-names></string-name></person-group>. <article-title>Software-defined networking-based crypto ransomware detection using HTTP traffic characteristics</article-title>. <source>Comput Electr Eng</source>. <year>2018</year>;<volume>66</volume>(<issue>1</issue>):<fpage>353</fpage>&#x2013;<lpage>68</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.compeleceng.2017.10.012</pub-id>.</mixed-citation></ref>
<ref id="ref-86"><label>[86]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Akbanov</surname> <given-names>M</given-names></string-name>, <string-name><surname>Vassilakis</surname> <given-names>VG</given-names></string-name>, <string-name><surname>Logothetis</surname> <given-names>MD</given-names></string-name></person-group>. <article-title>Ransomware detection and mitigation using software-defined networking: the case of WannaCry</article-title>. <source>Comput Electr Eng</source>. <year>2019</year>;<volume>76</volume>(<issue>3</issue>):<fpage>111</fpage>&#x2013;<lpage>21</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.compeleceng.2019.03.012</pub-id>.</mixed-citation></ref>
<ref id="ref-87"><label>[87]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Morato</surname> <given-names>D</given-names></string-name>, <string-name><surname>Berrueta</surname> <given-names>E</given-names></string-name>, <string-name><surname>Maga&#x00F1;a</surname> <given-names>E</given-names></string-name>, <string-name><surname>Izal</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Ransomware early detection by the analysis of file sharing traffic</article-title>. <source>J Netw Comput Appl</source>. <year>2018</year>;<volume>124</volume>(<issue>4</issue>):<fpage>14</fpage>&#x2013;<lpage>32</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.jnca.2018.09.013</pub-id>.</mixed-citation></ref>
<ref id="ref-88"><label>[88]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Almashhadani</surname> <given-names>AO</given-names></string-name>, <string-name><surname>Kaiiali</surname> <given-names>M</given-names></string-name>, <string-name><surname>Sezer</surname> <given-names>S</given-names></string-name>, <string-name><surname>O&#x2019;Kane</surname> <given-names>P</given-names></string-name></person-group>. <article-title>A multi-classifier network-based crypto ransomware detection system: a case study of locky ransomware</article-title>. <source>IEEE Access</source>. <year>2019</year>;<volume>7</volume>:<fpage>47053</fpage>&#x2013;<lpage>67</lpage>.</mixed-citation></ref>
<ref id="ref-89"><label>[89]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Liu</surname> <given-names>T-M</given-names></string-name>, <string-name><surname>Kao</surname> <given-names>D-Y</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>Y-Y</given-names></string-name></person-group>. <article-title>Loocipher ransomware detection using lightweight packet characteristics</article-title>. <source>Procedia Comput Sci</source>. <year>2020</year>;<volume>176</volume>(<issue>2</issue>):<fpage>1677</fpage>&#x2013;<lpage>83</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.procs.2020.09.192</pub-id>.</mixed-citation></ref>
<ref id="ref-90"><label>[90]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hernandez-Jaimes</surname> <given-names>ML</given-names></string-name>, <string-name><surname>Mart&#x00ED;nez-Cruz</surname> <given-names>A</given-names></string-name>, <string-name><surname>Ram&#x00ED;rez-Gutierrez</surname> <given-names>KA</given-names></string-name>, <string-name><surname>Guevara-Mart&#x00ED;nez</surname> <given-names>E</given-names></string-name></person-group>. <article-title>Enhancing machine learning approach based on nilsimsa fingerprinting for ransomware detection in IoMT</article-title>. <source>IEEE Access</source>. <year>2024</year>;<volume>12</volume>(<issue>2</issue>):<fpage>153886</fpage>&#x2013;<lpage>97</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2024.3480889</pub-id>.</mixed-citation></ref>
<ref id="ref-91"><label>[91]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Pletinckx</surname> <given-names>S</given-names></string-name>, <string-name><surname>Trap</surname> <given-names>C</given-names></string-name>, <string-name><surname>Doerr</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Malware coordination using the blockchain: an analysis of the cerber ransomware</article-title>. In: <conf-name>Proceedings of 2018 IEEE Conference on Communications and Network Security (CNS); 2018 May 30&#x2013;Jun 1</conf-name>; <publisher-loc>Beijing, China</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>9</lpage>.</mixed-citation></ref>
<ref id="ref-92"><label>[92]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Rios</surname> <given-names>ALG</given-names></string-name>, <string-name><surname>Trajkovi&#x0107;</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Machine learning for detecting the WestRock ransomware attack using BGP routing records</article-title>. <source>IEEE Commun Mag</source>. <year>2022</year>;<volume>61</volume>(<issue>3</issue>):<fpage>20</fpage>&#x2013;<lpage>6</lpage>. doi:<pub-id pub-id-type="doi">10.1109/mcom.001.2200215</pub-id>.</mixed-citation></ref>
<ref id="ref-93"><label>[93]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Song</surname> <given-names>S</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>B</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>S</given-names></string-name></person-group>. <article-title>The effective ransomware prevention technique using process monitoring on android platform</article-title>. <source>Mob Inf Syst</source>. <year>2016</year>;<volume>2016</volume>(<issue>1</issue>):<fpage>2946735</fpage>. doi:<pub-id pub-id-type="doi">10.1155/2016/2946735</pub-id>.</mixed-citation></ref>
<ref id="ref-94"><label>[94]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chen</surname> <given-names>J</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>C</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>K</given-names></string-name>, <string-name><surname>Du</surname> <given-names>R</given-names></string-name>, <string-name><surname>Ahn</surname> <given-names>G-J</given-names></string-name></person-group>. <article-title>Uncovering the face of android ransomware: characterization and real-time detection</article-title>. <source>IEEE Trans Inf Forensics Secur</source>. <year>2017</year>;<volume>13</volume>(<issue>5</issue>):<fpage>1286</fpage>&#x2013;<lpage>300</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tifs.2017.2787905</pub-id>.</mixed-citation></ref>
<ref id="ref-95"><label>[95]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Faghihi</surname> <given-names>F</given-names></string-name>, <string-name><surname>Zulkernine</surname> <given-names>M</given-names></string-name></person-group>. <article-title>RansomCare: data-centric detection and mitigation against smartphone crypto-ransomware</article-title>. <source>Comput Netw</source>. <year>2021</year>;<volume>191</volume>:<fpage>108011</fpage>.</mixed-citation></ref>
<ref id="ref-96"><label>[96]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chew</surname> <given-names>C</given-names></string-name>, <string-name><surname>Kumar</surname> <given-names>V</given-names></string-name>, <string-name><surname>Patros</surname> <given-names>P</given-names></string-name>, <string-name><surname>Malik</surname> <given-names>R</given-names></string-name></person-group>. <article-title>Real-time system call-based ransomware detection</article-title>. <source>Int J Inf Secur</source>. <year>2024</year>;<volume>23</volume>(<issue>3</issue>):<fpage>1839</fpage>&#x2013;<lpage>58</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s10207-024-00819-x</pub-id>.</mixed-citation></ref>
<ref id="ref-97"><label>[97]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ma</surname> <given-names>B</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>L</given-names></string-name>, <string-name><surname>Liao</surname> <given-names>C</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Li</surname> <given-names>J</given-names></string-name>, <string-name><surname>Ma</surname> <given-names>J</given-names></string-name></person-group>. <article-title>RansomSentry: Runtime detection of android ransomware with compiler-based instrumentation</article-title>. <source>IEEE Trans Dependable Secur Comput</source>. <year>2025</year>;<volume>22</volume>(<issue>4</issue>):<fpage>3354</fpage>&#x2013;<lpage>70</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tdsc.2025.3529119</pub-id>.</mixed-citation></ref>
<ref id="ref-98"><label>[98]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Scalas</surname> <given-names>M</given-names></string-name>, <string-name><surname>Maiorca</surname> <given-names>D</given-names></string-name>, <string-name><surname>Mercaldo</surname> <given-names>F</given-names></string-name>, <string-name><surname>Visaggio</surname> <given-names>CA</given-names></string-name>, <string-name><surname>Martinelli</surname> <given-names>F</given-names></string-name>, <string-name><surname>Giacinto</surname> <given-names>G</given-names></string-name></person-group>. <article-title>On the effectiveness of system API-related information for Android ransomware detection</article-title>. <source>Comput Secur</source>. <year>2019</year>;<volume>86</volume>(<issue>7</issue>):<fpage>168</fpage>&#x2013;<lpage>82</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2019.06.004</pub-id>.</mixed-citation></ref>
<ref id="ref-99"><label>[99]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Alsoghyer</surname> <given-names>S</given-names></string-name>, <string-name><surname>Almomani</surname> <given-names>I</given-names></string-name></person-group>. <article-title>Ransomware detection system for Android applications</article-title>. <source>Electronics</source>. <year>2019</year>;<volume>8</volume>(<issue>8</issue>):<fpage>868</fpage>. doi:<pub-id pub-id-type="doi">10.3390/electronics8080868</pub-id>.</mixed-citation></ref>
<ref id="ref-100"><label>[100]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Singh</surname> <given-names>N</given-names></string-name>, <string-name><surname>Tripathy</surname> <given-names>S</given-names></string-name></person-group>. <article-title>It&#x2019;s too late if exfiltrate: early stage android ransomware detection</article-title>. <source>Comput Secur</source>. <year>2024</year>;<volume>141</volume>:<fpage>103819</fpage>.</mixed-citation></ref>
<ref id="ref-101"><label>[101]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ahmed</surname> <given-names>U</given-names></string-name>, <string-name><surname>Lin</surname> <given-names>J</given-names></string-name>, <string-name><surname>Srivastava</surname> <given-names>G</given-names></string-name></person-group>. <article-title>Mitigating adversarial evasion attacks of ransomware using ensemble learning</article-title>. <source>Comput Electr Eng</source>. <year>2022</year>;<volume>100</volume>(<issue>3</issue>):<fpage>107903</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.compeleceng.2022.107903</pub-id>.</mixed-citation></ref>
<ref id="ref-102"><label>[102]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hossain</surname> <given-names>MS</given-names></string-name>, <string-name><surname>Hasan</surname> <given-names>N</given-names></string-name>, <string-name><surname>Samad</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Shakhawat</surname> <given-names>HM</given-names></string-name>, <string-name><surname>Karmoker</surname> <given-names>J</given-names></string-name>, <string-name><surname>Ahmed</surname> <given-names>F</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Android ransomware detection from traffic analysis using metaheuristic feature selection</article-title>. <source>IEEE Access</source>. <year>2022</year>;<volume>10</volume>:<fpage>128754</fpage>&#x2013;<lpage>63</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2022.3227579</pub-id>.</mixed-citation></ref>
<ref id="ref-103"><label>[103]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Albin Ahmed</surname> <given-names>A</given-names></string-name>, <string-name><surname>Shaahid</surname> <given-names>A</given-names></string-name>, <string-name><surname>Alnasser</surname> <given-names>F</given-names></string-name>, <string-name><surname>Alfaddagh</surname> <given-names>S</given-names></string-name>, <string-name><surname>Binagag</surname> <given-names>S</given-names></string-name>, <string-name><surname>Alqahtani</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Android ransomware detection using supervised machine learning techniques based on traffic analysis</article-title>. <source>Sensors</source>. <year>2023</year>;<volume>24</volume>(<issue>1</issue>):<fpage>189</fpage>. doi:<pub-id pub-id-type="doi">10.3390/s24010189</pub-id>; <pub-id pub-id-type="pmid">38203051</pub-id></mixed-citation></ref>
<ref id="ref-104"><label>[104]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Jeremiah</surname> <given-names>SR</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>H</given-names></string-name>, <string-name><surname>Gritzalis</surname> <given-names>S</given-names></string-name>, <string-name><surname>Park</surname> <given-names>JH</given-names></string-name></person-group>. <article-title>Leveraging application permissions and network traffic attributes for android ransomware detection</article-title>. <source>J Netw Comput Appl</source>. <year>2024</year>;<volume>230</volume>:<fpage>103950</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.jnca.2024.103950</pub-id>.</mixed-citation></ref>
<ref id="ref-105"><label>[105]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cimitile</surname> <given-names>A</given-names></string-name>, <string-name><surname>Mercaldo</surname> <given-names>F</given-names></string-name>, <string-name><surname>Nardone</surname> <given-names>V</given-names></string-name>, <string-name><surname>Santone</surname> <given-names>A</given-names></string-name>, <string-name><surname>Visaggio</surname> <given-names>CA</given-names></string-name></person-group>. <article-title>Talos: no more ransomware victims with formal methods</article-title>. <source>Int J Inf Secur</source>. <year>2018</year>;<volume>17</volume>(<issue>6</issue>):<fpage>719</fpage>&#x2013;<lpage>38</lpage>.</mixed-citation></ref>
<ref id="ref-106"><label>[106]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Elkhail</surname> <given-names>AA</given-names></string-name>, <string-name><surname>Bacha</surname> <given-names>A</given-names></string-name>, <string-name><surname>Malik</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Sniper: countering locker ransomware attacks through natural language processing</article-title>. <source>IEEE Trans Dependable Secur Comput</source>. <year>2025</year>;<volume>22</volume>(<issue>4</issue>):<fpage>4160</fpage>&#x2013;<lpage>75</lpage>.</mixed-citation></ref>
<ref id="ref-107"><label>[107]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Al-Hawawreh</surname> <given-names>M</given-names></string-name>, <string-name><surname>Den Hartog</surname> <given-names>F</given-names></string-name>, <string-name><surname>Sitnikova</surname> <given-names>E</given-names></string-name></person-group>. <article-title>Targeted ransomware: a new cyber threat to edge system of brownfield industrial Internet of Things</article-title>. <source>IEEE Internet Things J</source>. <year>2019</year>;<volume>6</volume>(<issue>4</issue>):<fpage>7137</fpage>&#x2013;<lpage>51</lpage>.</mixed-citation></ref>
<ref id="ref-108"><label>[108]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Celdr&#x00E1;n</surname> <given-names>AH</given-names></string-name>, <string-name><surname>S&#x00E1;nchez</surname> <given-names>PMS</given-names></string-name>, <string-name><surname>Von der Assen</surname> <given-names>J</given-names></string-name>, <string-name><surname>Shushack</surname> <given-names>D</given-names></string-name>, <string-name><surname>G&#x00F3;mez</surname> <given-names>&#x00C1;LP</given-names></string-name>, <string-name><surname>Bovet</surname> <given-names>G</given-names></string-name>, <etal>et al</etal></person-group>. <source>Behavioral fingerprinting to detect ransomware in resource-constrained devices</source>. <source>Comput Secur</source>. <year>2023</year>;<volume>135</volume>:<fpage>103510</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2023.103510</pub-id>.</mixed-citation></ref>
<ref id="ref-109"><label>[109]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Al-Hawawreh</surname> <given-names>M</given-names></string-name>, <string-name><surname>Sitnikova</surname> <given-names>E</given-names></string-name>, <string-name><surname>Aboutorab</surname> <given-names>N</given-names></string-name></person-group>. <article-title>Asynchronous peer-to-peer federated capability-based targeted ransomware detection model for industrial IoT</article-title>. <source>IEEE Access</source>. <year>2021</year>;<volume>9</volume>:<fpage>148738</fpage>&#x2013;<lpage>55</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2021.3124634</pub-id>.</mixed-citation></ref>
<ref id="ref-110"><label>[110]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tariq</surname> <given-names>U</given-names></string-name>, <string-name><surname>Ullah</surname> <given-names>I</given-names></string-name>, <string-name><surname>Yousuf Uddin</surname> <given-names>M</given-names></string-name>, <string-name><surname>Kwon</surname> <given-names>SJ</given-names></string-name></person-group>. <article-title>An effective self-configurable ransomware prevention technique for IoMT</article-title>. <source>Sensors</source>. <year>2022</year>;<volume>22</volume>(<issue>21</issue>):<fpage>8516</fpage>. doi:<pub-id pub-id-type="doi">10.3390/s22218516</pub-id>; <pub-id pub-id-type="pmid">36366214</pub-id></mixed-citation></ref>
<ref id="ref-111"><label>[111]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wazid</surname> <given-names>M</given-names></string-name>, <string-name><surname>Das</surname> <given-names>AK</given-names></string-name>, <string-name><surname>Shetty</surname> <given-names>S</given-names></string-name></person-group>. <article-title>BSFR-SH: blockchain-enabled security framework against ransomware attacks for smart healthcare</article-title>. <source>IEEE Trans Consum Electron</source>. <year>2022</year>;<volume>69</volume>(<issue>1</issue>):<fpage>18</fpage>&#x2013;<lpage>28</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tce.2022.3208795</pub-id>.</mixed-citation></ref>
<ref id="ref-112"><label>[112]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Malik</surname> <given-names>AW</given-names></string-name>, <string-name><surname>Anwar</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Rahman</surname> <given-names>AU</given-names></string-name></person-group>. <article-title>A novel framework for studying the business impact of ransomware on connected vehicles</article-title>. <source>IEEE Internet Things J</source>. <year>2022</year>;<volume>10</volume>(<issue>10</issue>):<fpage>8348</fpage>&#x2013;<lpage>56</lpage>. doi:<pub-id pub-id-type="doi">10.1109/jiot.2022.3209687</pub-id>.</mixed-citation></ref>
<ref id="ref-113"><label>[113]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Beaman</surname> <given-names>C</given-names></string-name>, <string-name><surname>Barkworth</surname> <given-names>A</given-names></string-name>, <string-name><surname>Akande</surname> <given-names>TD</given-names></string-name>, <string-name><surname>Hakak</surname> <given-names>S</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>MK</given-names></string-name></person-group>. <article-title>Ransomware: recent advances, analysis, challenges and future research directions</article-title>. <source>Comput Secur</source>. <year>2021</year>;<volume>111</volume>:<fpage>102490</fpage>; <pub-id pub-id-type="pmid">34602684</pub-id></mixed-citation></ref>
<ref id="ref-114"><label>[114]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>De Gaspari</surname> <given-names>F</given-names></string-name>, <string-name><surname>Hitaj</surname> <given-names>D</given-names></string-name>, <string-name><surname>Pagnotta</surname> <given-names>G</given-names></string-name>, <string-name><surname>De Carli</surname> <given-names>L</given-names></string-name>, <string-name><surname>Mancini</surname> <given-names>LV</given-names></string-name></person-group>. <article-title>Evading behavioral classifiers: a comprehensive analysis on evading ransomware detection techniques</article-title>. <source>Neural Comput Appl</source>. <year>2022</year>;<volume>34</volume>(<issue>14</issue>):<fpage>12077</fpage>&#x2013;<lpage>96</lpage>.</mixed-citation></ref>
<ref id="ref-115"><label>[115]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>von der Assen</surname> <given-names>J</given-names></string-name>, <string-name><surname>Celdr&#x00E1;n</surname> <given-names>AH</given-names></string-name>, <string-name><surname>Luechinger</surname> <given-names>J</given-names></string-name>, <string-name><surname>S&#x00E1;nchez</surname> <given-names>PMS</given-names></string-name>, <string-name><surname>Bovet</surname> <given-names>G</given-names></string-name>, <string-name><surname>P&#x00E9;rez</surname> <given-names>GM</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>RansomAI: AI-powered ransomware for stealthy encryption</article-title>. In: <conf-name>Proceedings of 2023 IEEE Global Communications Conference; 2023 Dec 8&#x2013;12</conf-name>; <publisher-loc>Kuala Lumpur, Malaysia</publisher-loc>. p. <fpage>2578</fpage>&#x2013;<lpage>83</lpage>.</mixed-citation></ref>
<ref id="ref-116"><label>[116]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Zhou</surname> <given-names>C</given-names></string-name>, <string-name><surname>Guo</surname> <given-names>L</given-names></string-name>, <string-name><surname>Hou</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Ma</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>M</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Limits of I/O based ransomware detection: an imitation based attack</article-title>. In: <conf-name>Proceedings of 2023 IEEE Symposium on Security and Privacy (SP); 2023 May 21&#x2013;25</conf-name>; <publisher-loc>San Francisco, CA, USA</publisher-loc>. p. <fpage>2584</fpage>&#x2013;<lpage>601</lpage>.</mixed-citation></ref>
<ref id="ref-117"><label>[117]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Zhao</surname> <given-names>L</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Yuan</surname> <given-names>F</given-names></string-name>, <string-name><surname>Hou</surname> <given-names>R</given-names></string-name></person-group>. <article-title>ERW-Radar: an adaptive detection system against evasive ransomware by contextual behavior detection and fine-grained content analysis</article-title>. In: <conf-name>Proceedings of NDSS; 2025 Feb 24&#x2013;28</conf-name>; <publisher-loc>San Diego, CA, USA</publisher-loc>.</mixed-citation></ref>
<ref id="ref-118"><label>[118]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Guo</surname> <given-names>L</given-names></string-name>, <string-name><surname>Hou</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>C</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Jiang</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Ransomware detection through temporal correlation between encryption and I/O behavior</article-title>. <source>Proc ACM Softw Eng</source>. <year>2025</year>;<volume>2</volume>(<issue>FSE</issue>):<fpage>197</fpage>&#x2013;<lpage>218</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3715725</pub-id>.</mixed-citation></ref>
<ref id="ref-119"><label>[119]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Hitaj</surname> <given-names>D</given-names></string-name>, <string-name><surname>Pagnotta</surname> <given-names>G</given-names></string-name>, <string-name><surname>De Gaspari</surname> <given-names>F</given-names></string-name>, <string-name><surname>De Carli</surname> <given-names>L</given-names></string-name>, <string-name><surname>Minerva</surname> <given-names>MLV</given-names></string-name></person-group>. <article-title>A file-based ransomware detector</article-title>. In: <conf-name>Proceedings of the 20th ACM Asia Conference on Computer and Communications Security, SEC&#x2019;25; 2025 Aug 25&#x2013;29</conf-name>; <publisher-loc>Hanoi, Vietnam</publisher-loc>. p. <fpage>576</fpage>&#x2013;<lpage>90</lpage>.</mixed-citation></ref>
<ref id="ref-120"><label>[120]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Conti</surname> <given-names>M</given-names></string-name>, <string-name><surname>Gangwal</surname> <given-names>A</given-names></string-name>, <string-name><surname>Ruj</surname> <given-names>S</given-names></string-name></person-group>. <article-title>On the economic significance of ransomware campaigns: a Bitcoin transactions perspective</article-title>. <source>Comput Secur</source>. <year>2018</year>;<volume>79</volume>(<issue>1</issue>):<fpage>162</fpage>&#x2013;<lpage>89</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2018.08.008</pub-id>.</mixed-citation></ref>
<ref id="ref-121"><label>[121]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Huang</surname> <given-names>D</given-names></string-name>, <string-name><surname>Aliapoulios</surname> <given-names>MM</given-names></string-name>, <string-name><surname>Li</surname> <given-names>VG</given-names></string-name>, <string-name><surname>Invernizzi</surname> <given-names>L</given-names></string-name>, <string-name><surname>Bursztein</surname> <given-names>E</given-names></string-name>, <string-name><surname>McRoberts</surname> <given-names>K</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Tracking ransomware end-to-end</article-title>. In: <conf-name>Proceedings of 2018 IEEE Symposium on Security and Privacy (SP); 2018 May 21&#x2013;23</conf-name>; <publisher-loc>San Francisco, CA, USA</publisher-loc>. p. <fpage>618</fpage>&#x2013;<lpage>31</lpage>.</mixed-citation></ref>
<ref id="ref-122"><label>[122]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Paquet-Clouston</surname> <given-names>M</given-names></string-name>, <string-name><surname>Haslhofer</surname> <given-names>B</given-names></string-name>, <string-name><surname>Dupont</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Ransomware payments in the Bitcoin ecosystem</article-title>. <source>J Cybersecur</source>. <year>2019</year>;<volume>5</volume>(<issue>1</issue>):<fpage>tyz003</fpage>. doi:<pub-id pub-id-type="doi">10.1093/cybsec/tyz003</pub-id>.</mixed-citation></ref>
<ref id="ref-123"><label>[123]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>K</given-names></string-name>, <string-name><surname>Tong</surname> <given-names>M</given-names></string-name>, <string-name><surname>Pang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Han</surname> <given-names>W</given-names></string-name></person-group>. <article-title>XRAD: ransomware address detection method based on Bitcoin transaction relationships</article-title>. <source>ACM Trans Web</source>. <year>2024</year>;<volume>18</volume>(<issue>4</issue>):<fpage>1</fpage>&#x2013;<lpage>33</lpage>.</mixed-citation></ref>
<ref id="ref-124"><label>[124]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Sarabi</surname> <given-names>A</given-names></string-name>, <string-name><surname>Huang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>C</given-names></string-name>, <string-name><surname>Karir</surname> <given-names>T</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>M</given-names></string-name></person-group>. <article-title>The ransomware decade: the creation of a fine-grained dataset and a longitudinal study</article-title>. In: <conf-name>Proceedings of 34th USENIX Security Symposium (USENIX Security 25); 2025 Aug 13&#x2013;15</conf-name>; <publisher-loc>Berkeley, CA, USA</publisher-loc>. p. <fpage>4799</fpage>&#x2013;<lpage>818</lpage>.</mixed-citation></ref>
<ref id="ref-125"><label>[125]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Min</surname> <given-names>D</given-names></string-name>, <string-name><surname>Park</surname> <given-names>D</given-names></string-name>, <string-name><surname>Ahn</surname> <given-names>J</given-names></string-name>, <string-name><surname>Walker</surname> <given-names>R</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>J</given-names></string-name>, <string-name><surname>Park</surname> <given-names>S</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Amoeba: an autonomous backup and recovery SSD for ransomware attack defense</article-title>. <source>IEEE Comput Archit Lett</source>. <year>2018</year>;<volume>17</volume>(<issue>2</issue>):<fpage>245</fpage>&#x2013;<lpage>8</lpage>.</mixed-citation></ref>
<ref id="ref-126"><label>[126]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Baek</surname> <given-names>S</given-names></string-name>, <string-name><surname>Jung</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Mohaisen</surname> <given-names>A</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>S</given-names></string-name>, <string-name><surname>Nyang</surname> <given-names>D</given-names></string-name></person-group>. <article-title>SSD-insider: internal defense of solid-state drive against ransomware with perfect data recovery</article-title>. In: <conf-name>Proceedings of 2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS); 2018 Jul 2&#x2013;5</conf-name>; <publisher-loc>Vienna, Austria</publisher-loc>. p. <fpage>875</fpage>&#x2013;<lpage>84</lpage>.</mixed-citation></ref>
<ref id="ref-127"><label>[127]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Baek</surname> <given-names>S</given-names></string-name>, <string-name><surname>Jung</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Mohaisen</surname> <given-names>D</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>S</given-names></string-name>, <string-name><surname>Nyang</surname> <given-names>D</given-names></string-name></person-group>. <article-title>SSD-assisted ransomware detection and data recovery techniques</article-title>. <source>IEEE Trans Comput</source>. <year>2020</year>;<volume>70</volume>(<issue>10</issue>):<fpage>1762</fpage>&#x2013;<lpage>76</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tc.2020.3011214</pub-id>.</mixed-citation></ref>
<ref id="ref-128"><label>[128]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Paik</surname> <given-names>J-Y</given-names></string-name>, <string-name><surname>Choi</surname> <given-names>J-H</given-names></string-name>, <string-name><surname>Jin</surname> <given-names>R</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Cho</surname> <given-names>E-S</given-names></string-name></person-group>. <article-title>A storage-level detection mechanism against crypto-ransomware</article-title>. In: <conf-name>Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security; 2018 Oct 15&#x2013;19</conf-name>; <publisher-loc>Toronto, Canada</publisher-loc>. p. <fpage>2258</fpage>&#x2013;<lpage>60</lpage>.</mixed-citation></ref>
<ref id="ref-129"><label>[129]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Elkhail</surname> <given-names>AA</given-names></string-name>, <string-name><surname>Lachtar</surname> <given-names>N</given-names></string-name>, <string-name><surname>Ibdah</surname> <given-names>D</given-names></string-name>, <string-name><surname>Aslam</surname> <given-names>R</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>H</given-names></string-name>, <string-name><surname>Bacha</surname> <given-names>A</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Seamlessly safeguarding data against ransomware attacks</article-title>. <source>IEEE Trans Dependable Secur Comput</source>. <year>2023</year>;<volume>20</volume>(<issue>1</issue>):<fpage>1</fpage>&#x2013;<lpage>16</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tdsc.2022.3214781</pub-id>.</mixed-citation></ref>
<ref id="ref-130"><label>[130]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Ma</surname> <given-names>B</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Li</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>F</given-names></string-name>, <string-name><surname>Shen</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>Y</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Travelling the hypervisor and SSD: a tag-based approach against crypto ransomware with fine-grained data recovery</article-title>. In: <conf-name>Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, CCS&#x2019;23; 2023 Nov 26&#x2013;30</conf-name>; <publisher-loc>Copenhagen, Denmark</publisher-loc>. p. <fpage>341</fpage>&#x2013;<lpage>55</lpage>.</mixed-citation></ref>
<ref id="ref-131"><label>[131]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Song</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>E</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>H</given-names></string-name>, <string-name><surname>Tong</surname> <given-names>G</given-names></string-name>, <string-name><surname>Sun</surname> <given-names>S</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Ransom access memories: achieving practical ransomware protection in cloud with DeftPunk</article-title>. In: <conf-name>Proceedings of 18th USENIX Symposium on Operating Systems Design and Implementation (OSDI 24); 2024 Jul 10&#x2013;12</conf-name>; <publisher-loc>Clara, CA, USA</publisher-loc>. p. <fpage>687</fpage>&#x2013;<lpage>702</lpage>.</mixed-citation></ref>
<ref id="ref-132"><label>[132]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hill</surname> <given-names>JE</given-names></string-name>, <string-name><surname>Walker</surname> <given-names>TO</given-names></string-name>, <string-name><surname>Blanco</surname> <given-names>JA</given-names></string-name>, <string-name><surname>Ives</surname> <given-names>RW</given-names></string-name>, <string-name><surname>Rakvic</surname> <given-names>R</given-names></string-name>, <string-name><surname>Jacob</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Ransomware classification using hardware performance counters on a non-virtualized system</article-title>. <source>IEEE Access</source>. <year>2024</year>;<volume>12</volume>(<issue>4</issue>):<fpage>63865</fpage>&#x2013;<lpage>84</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2024.3395491</pub-id>.</mixed-citation></ref>
<ref id="ref-133"><label>[133]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhu</surname> <given-names>W</given-names></string-name>, <string-name><surname>Hernandez</surname> <given-names>G</given-names></string-name>, <string-name><surname>Garcia</surname> <given-names>W</given-names></string-name>, <string-name><surname>Tian</surname> <given-names>D</given-names></string-name>, <string-name><surname>Rampazzi</surname> <given-names>S</given-names></string-name>, <string-name><surname>Butler</surname> <given-names>KRB</given-names></string-name></person-group>. <article-title>SrFTL: leveraging storage semantics for effective ransomware defense in flash-based SSDs</article-title>. <source>ACM Trans Storage</source>. <year>2025</year>;<volume>21</volume>(<issue>4</issue>):<fpage>1</fpage>&#x2013;<lpage>42</lpage>.</mixed-citation></ref>
<ref id="ref-134"><label>[134]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>G&#x00F3;mez-Hern&#x00E1;ndez</surname> <given-names>JA</given-names></string-name>, <string-name><surname>&#x00C1;lvarez-Gonz&#x00E1;lez</surname> <given-names>L</given-names></string-name>, <string-name><surname>Garc&#x00ED;a-Teodoro</surname> <given-names>P</given-names></string-name></person-group>. <article-title>R-Locker: thwarting ransomware action through a honeyfile-based approach</article-title>. <source>Comput Secur</source>. <year>2018</year>;<volume>73</volume>:<fpage>389</fpage>&#x2013;<lpage>98</lpage>.</mixed-citation></ref>
<ref id="ref-135"><label>[135]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sibi Chakkaravarthy</surname> <given-names>S</given-names></string-name>, <string-name><surname>Sangeetha</surname> <given-names>D</given-names></string-name>, <string-name><surname>Cruz</surname> <given-names>MV</given-names></string-name>, <string-name><surname>Vaidehi</surname> <given-names>V</given-names></string-name>, <string-name><surname>Raman</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Design of intrusion detection honeypot using social leopard algorithm to detect IoT ransomware attacks</article-title>. <source>IEEE Access</source>. <year>2020</year>;<volume>8</volume>:<fpage>169944</fpage>&#x2013;<lpage>56</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2020.3023764</pub-id>.</mixed-citation></ref>
<ref id="ref-136"><label>[136]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ganfure</surname> <given-names>GO</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>C-F</given-names></string-name>, <string-name><surname>Chang</surname> <given-names>Y-H</given-names></string-name>, <string-name><surname>Shih</surname> <given-names>W-K</given-names></string-name></person-group>. <article-title>Rtrap: trapping and containing ransomware with machine learning</article-title>. <source>IEEE Trans Inf Forensics Secur</source>. <year>2023</year>;<volume>18</volume>:<fpage>1433</fpage>&#x2013;<lpage>48</lpage>.</mixed-citation></ref>
<ref id="ref-137"><label>[137]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Berardi</surname> <given-names>D</given-names></string-name>, <string-name><surname>Giallorenzo</surname> <given-names>S</given-names></string-name>, <string-name><surname>Melis</surname> <given-names>A</given-names></string-name>, <string-name><surname>Melloni</surname> <given-names>S</given-names></string-name>, <string-name><surname>Onori</surname> <given-names>L</given-names></string-name>, <string-name><surname>Prandini</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Data flooding against ransomware: concepts and implementations</article-title>. <source>Comput Secur</source>. <year>2023</year>;<volume>131</volume>:<fpage>103295</fpage>.</mixed-citation></ref>
<ref id="ref-138"><label>[138]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Sajid</surname> <given-names>MSI</given-names></string-name>, <string-name><surname>Wei</surname> <given-names>J</given-names></string-name>, <string-name><surname>Al-Shaer</surname> <given-names>E</given-names></string-name></person-group>. <article-title>ranDecepter: real-time identification and deterrence of ransomware attacks</article-title>. In: <conf-name>Proceedings of 2025 IEEE Conference on Communications and Network Security (CNS); 2025 Sep 8&#x2013;11</conf-name>; <publisher-loc>Avignon, France</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>9</lpage>.</mixed-citation></ref>
<ref id="ref-139"><label>[139]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Filiz</surname> <given-names>B</given-names></string-name>, <string-name><surname>Arief</surname> <given-names>B</given-names></string-name>, <string-name><surname>Cetin</surname> <given-names>O</given-names></string-name>, <string-name><surname>Hernandez-Castro</surname> <given-names>J</given-names></string-name></person-group>. <article-title>On the effectiveness of ransomware decryption tools</article-title>. <source>Comput Secur</source>. <year>2021</year>;<volume>111</volume>(<issue>3</issue>):<fpage>102469</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2021.102469</pub-id>.</mixed-citation></ref>
<ref id="ref-140"><label>[140]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yuste</surname> <given-names>J</given-names></string-name>, <string-name><surname>Pastrana</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Avaddon ransomware: an in-depth analysis and decryption of infected systems</article-title>. <source>Comput Secur</source>. <year>2021</year>;<volume>109</volume>:<fpage>102388</fpage>.</mixed-citation></ref>
<ref id="ref-141"><label>[141]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kim</surname> <given-names>G</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>S</given-names></string-name>, <string-name><surname>Kang</surname> <given-names>S</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>J</given-names></string-name></person-group>. <article-title>A method for decrypting data infected with Hive ransomware</article-title>. <source>J Inf Secur Appl</source>. <year>2022</year>;<volume>71</volume>(<issue>1</issue>):<fpage>103387</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.jisa.2022.103387</pub-id>.</mixed-citation></ref>
<ref id="ref-142"><label>[142]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kim</surname> <given-names>G</given-names></string-name>, <string-name><surname>Kang</surname> <given-names>S</given-names></string-name>, <string-name><surname>Baek</surname> <given-names>S</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>K</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>J</given-names></string-name></person-group>. <article-title>How to decrypt files encrypted by Rhysida ransomware without the attacker&#x2019;s private key</article-title>. <source>J Inf Secur Appl</source>. <year>2025</year>;<volume>151</volume>(<issue>10</issue>):<fpage>104340</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2025.104340</pub-id>.</mixed-citation></ref>
<ref id="ref-143"><label>[143]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Almomani</surname> <given-names>I</given-names></string-name>, <string-name><surname>Alkhayer</surname> <given-names>A</given-names></string-name>, <string-name><surname>El-Shafai</surname> <given-names>W</given-names></string-name></person-group>. <article-title>E2E-RDS: efficient end-to-end ransomware detection system based on static-based ML and vision-based DL approaches</article-title>. <source>Sensors</source>. <year>2023</year>;<volume>23</volume>(<issue>9</issue>):<fpage>4467</fpage>; <pub-id pub-id-type="pmid">37177671</pub-id></mixed-citation></ref>
<ref id="ref-144"><label>[144]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lee</surname> <given-names>K</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>S</given-names></string-name>, <string-name><surname>Yim</surname> <given-names>K</given-names></string-name></person-group>. <article-title>Machine learning based file entropy analysis for ransomware detection in backup systems</article-title>. <source>IEEE Access</source>. <year>2019</year>;<volume>7</volume>:<fpage>110205</fpage>&#x2013;<lpage>15</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2019.2931136</pub-id>.</mixed-citation></ref>
<ref id="ref-145"><label>[145]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Davies</surname> <given-names>SR</given-names></string-name>, <string-name><surname>Macfarlane</surname> <given-names>R</given-names></string-name>, <string-name><surname>Buchanan</surname> <given-names>WJ</given-names></string-name></person-group>. <article-title>Differential area analysis for ransomware attack detection within mixed file datasets</article-title>. <source>Comput Secur</source>. <year>2021</year>;<volume>108</volume>(<issue>8</issue>):<fpage>102377</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2021.102377</pub-id>.</mixed-citation></ref>
<ref id="ref-146"><label>[146]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hou</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Guo</surname> <given-names>L</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>C</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>W</given-names></string-name>, <string-name><surname>Sun</surname> <given-names>C</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Preventing disruption of system backup against ransomware attacks</article-title>. <source>Proc ACM Softw Eng</source>. <year>2025</year>;<volume>2</volume>(<issue>ISSTA</issue>):<fpage>229</fpage>&#x2013;<lpage>49</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3728880</pub-id>.</mixed-citation></ref>
<ref id="ref-147"><label>[147]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Everett</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Ransomware: to pay or not to pay?</article-title> <source>Comput Fraud Secur</source>. <year>2016</year>;<volume>2016</volume>(<issue>4</issue>):<fpage>8</fpage>&#x2013;<lpage>12</lpage>. doi:<pub-id pub-id-type="doi">10.1016/s1361-3723(16)30036-7</pub-id>.</mixed-citation></ref>
<ref id="ref-148"><label>[148]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Mansfield-Devine</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Ransomware: taking businesses hostage</article-title>. <source>Netw Secur</source>. <year>2016</year>;<volume>2016</volume>(<issue>10</issue>):<fpage>8</fpage>&#x2013;<lpage>17</lpage>. doi:<pub-id pub-id-type="doi">10.1016/s1353-4858(16)30096-4</pub-id>.</mixed-citation></ref>
<ref id="ref-149"><label>[149]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Connolly</surname> <given-names>AY</given-names></string-name>, <string-name><surname>Borrion</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Reducing ransomware crime: analysis of victims&#x2019; payment decisions</article-title>. <source>Comput Secur</source>. <year>2022</year>;<volume>119</volume>:<fpage>102760</fpage>.</mixed-citation></ref>
<ref id="ref-150"><label>[150]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ryan</surname> <given-names>P</given-names></string-name>, <string-name><surname>Fokker</surname> <given-names>J</given-names></string-name>, <string-name><surname>Healy</surname> <given-names>S</given-names></string-name>, <string-name><surname>Amann</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Dynamics of targeted ransomware negotiation</article-title>. <source>IEEE Access</source>. <year>2022</year>;<volume>10</volume>:<fpage>32836</fpage>&#x2013;<lpage>44</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2022.3160748</pub-id>.</mixed-citation></ref>
<ref id="ref-151"><label>[151]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Meurs</surname> <given-names>T</given-names></string-name>, <string-name><surname>Cartwright</surname> <given-names>E</given-names></string-name>, <string-name><surname>Cartwright</surname> <given-names>A</given-names></string-name>, <string-name><surname>Junger</surname> <given-names>M</given-names></string-name>, <string-name><surname>Abhishta</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Deception in double extortion ransomware attacks: an analysis of profitability and credibility</article-title>. <source>Comput Secur</source>. <year>2024</year>;<volume>138</volume>:<fpage>103670</fpage>.</mixed-citation></ref>
<ref id="ref-152"><label>[152]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Zhang-Kennedy</surname> <given-names>L</given-names></string-name>, <string-name><surname>Assal</surname> <given-names>H</given-names></string-name>, <string-name><surname>Rocheleau</surname> <given-names>J</given-names></string-name>, <string-name><surname>Mohamed</surname> <given-names>R</given-names></string-name>, <string-name><surname>Baig</surname> <given-names>K</given-names></string-name>, <string-name><surname>Chiasson</surname> <given-names>S</given-names></string-name></person-group>. <article-title>The aftermath of a crypto-ransomware attack at a large academic institution</article-title>. In: <conf-name>Proceedings of 27th USENIX Security Symposium (USENIX Security 18), SEC&#x2019;18; 2018 Aug 15&#x2013;17</conf-name>; <publisher-loc>Baltimore, MD, USA</publisher-loc>. p. <fpage>1061</fpage>&#x2013;<lpage>78</lpage>.</mixed-citation></ref>
<ref id="ref-153"><label>[153]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Connolly</surname> <given-names>LY</given-names></string-name>, <string-name><surname>Wall</surname> <given-names>DS</given-names></string-name></person-group>. <article-title>The rise of crypto-ransomware in a changing cybercrime landscape: taxonomising countermeasures</article-title>. <source>Comput Secur</source>. <year>2019</year>;<volume>87</volume>(<issue>5</issue>):<fpage>101568</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2019.101568</pub-id>.</mixed-citation></ref>
<ref id="ref-154"><label>[154]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Thomas</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Individual cyber security: empowering employees to resist spear phishing to prevent identity theft and ransomware attacks</article-title>. <source>Int J Bus Manag</source>. <year>2018</year>;<volume>12</volume>(<issue>3</issue>):<fpage>1</fpage>&#x2013;<lpage>23</lpage>.</mixed-citation></ref>
<ref id="ref-155"><label>[155]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hayes</surname> <given-names>K</given-names></string-name></person-group>. <article-title>Ransomware: a growing geopolitical threat</article-title>. <source>Netw Secur</source>. <year>2021</year>;<volume>2021</volume>(<issue>8</issue>):<fpage>11</fpage>&#x2013;<lpage>3</lpage>.</mixed-citation></ref>
<ref id="ref-156"><label>[156]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bekkers</surname> <given-names>L</given-names></string-name>, <string-name><surname>van&#x2019;t Hoff-De Goede</surname> <given-names>S</given-names></string-name>, <string-name><surname>Misana-ter Huurne</surname> <given-names>E</given-names></string-name>, <string-name><surname>van Houten</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Spithoven</surname> <given-names>R</given-names></string-name>, <string-name><surname>Leukfeldt</surname> <given-names>ER</given-names></string-name></person-group>. <article-title>Protecting your business against ransomware attacks? Explaining the motivations of entrepreneurs to take future protective measures against cybercrimes using an extended protection motivation theory model</article-title>. <source>Comput Secur</source>. <year>2023</year>;<volume>127</volume>(<issue>2</issue>):<fpage>103099</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2023.103099</pub-id>.</mixed-citation></ref>
<ref id="ref-157"><label>[157]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Mott</surname> <given-names>G</given-names></string-name>, <string-name><surname>Turner</surname> <given-names>S</given-names></string-name>, <string-name><surname>Nurse</surname> <given-names>JRC</given-names></string-name>, <string-name><surname>Mac Coll</surname> <given-names>J</given-names></string-name>, <string-name><surname>Sullivan</surname> <given-names>J</given-names></string-name>, <string-name><surname>Cartwright</surname> <given-names>A</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Between a rock and a hard (ening) place: cyber insurance in the ransomware era</article-title>. <source>Comput Secur</source>. <year>2023</year>;<volume>128</volume>:<fpage>103162</fpage>.</mixed-citation></ref>
<ref id="ref-158"><label>[158]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bajpai</surname> <given-names>P</given-names></string-name>, <string-name><surname>Enbody</surname> <given-names>R</given-names></string-name></person-group>. <article-title>Know thy ransomware response: a detailed framework for devising effective ransomware response strategies</article-title>. <source>Digit Threat Res Pract</source>. <year>2023</year>;<volume>4</volume>(<issue>4</issue>):<fpage>1</fpage>&#x2013;<lpage>19</lpage>.</mixed-citation></ref>
<ref id="ref-159"><label>[159]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Simmonds</surname> <given-names>M</given-names></string-name></person-group>. <article-title>How businesses can navigate the growing tide of ransomware attacks</article-title>. <source>Comput Fraud Secur</source>. <year>2017</year>;<volume>2017</volume>(<issue>3</issue>):<fpage>9</fpage>&#x2013;<lpage>12</lpage>. doi:<pub-id pub-id-type="doi">10.1016/s1361-3723(17)30023-4</pub-id>.</mixed-citation></ref>
<ref id="ref-160"><label>[160]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hernandez-Castro</surname> <given-names>J</given-names></string-name>, <string-name><surname>Cartwright</surname> <given-names>A</given-names></string-name>, <string-name><surname>Cartwright</surname> <given-names>E</given-names></string-name></person-group>. <article-title>An economic analysis of ransomware and its welfare consequences</article-title>. <source>R Soc Open Sci</source>. <year>2020</year>;<volume>7</volume>(<issue>3</issue>):<fpage>190023</fpage>. doi:<pub-id pub-id-type="doi">10.1098/rsos.190023</pub-id>; <pub-id pub-id-type="pmid">32269778</pub-id></mixed-citation></ref>
<ref id="ref-161"><label>[161]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cartwright</surname> <given-names>E</given-names></string-name>, <string-name><surname>Hernandez Castro</surname> <given-names>J</given-names></string-name>, <string-name><surname>Cartwright</surname> <given-names>A</given-names></string-name></person-group>. <article-title>To pay or not: game theoretic models of ransomware</article-title>. <source>J Cybersecur</source>. <year>2019</year>;<volume>5</volume>(<issue>1</issue>):<fpage>tyz009</fpage>.</mixed-citation></ref>
<ref id="ref-162"><label>[162]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>C</given-names></string-name>, <string-name><surname>Luo</surname> <given-names>F</given-names></string-name>, <string-name><surname>Ranzi</surname> <given-names>G</given-names></string-name></person-group>. <article-title>Multistage game theoretical approach for ransomware attack and defense</article-title>. <source>IEEE Trans Serv Comput</source>. <year>2022</year>;<volume>16</volume>(<issue>4</issue>):<fpage>2800</fpage>&#x2013;<lpage>11</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tsc.2022.3220736</pub-id>.</mixed-citation></ref>
<ref id="ref-163"><label>[163]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Liao</surname> <given-names>Q</given-names></string-name></person-group>. <article-title>Preventive portfolio against data-selling ransomware&#x2014;A game theory of encryption and deception</article-title>. <source>Comput Secur</source>. <year>2022</year>;<volume>116</volume>(<issue>2</issue>):<fpage>102644</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2022.102644</pub-id>.</mixed-citation></ref>
<ref id="ref-164"><label>[164]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Meland</surname> <given-names>PH</given-names></string-name>, <string-name><surname>Bayoumy</surname> <given-names>YFF</given-names></string-name>, <string-name><surname>Sindre</surname> <given-names>G</given-names></string-name></person-group>. <article-title>The Ransomware-as-a-Service economy within the darknet</article-title>. <source>Comput Secur</source>. <year>2020</year>;<volume>92</volume>(<issue>2</issue>):<fpage>101762</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2020.101762</pub-id>.</mixed-citation></ref>
<ref id="ref-165"><label>[165]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chauhan</surname> <given-names>PS</given-names></string-name>, <string-name><surname>Kshetri</surname> <given-names>N</given-names></string-name></person-group>. <article-title>Ransomware as a service kit: a novel cybercrime strategy to monetize victims&#x2019; data</article-title>. <source>Computer</source>. <year>2023</year>;<volume>56</volume>(<issue>10</issue>):<fpage>102</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-166"><label>[166]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Oosthoek</surname> <given-names>K</given-names></string-name>, <string-name><surname>Cable</surname> <given-names>J</given-names></string-name>, <string-name><surname>Smaragdakis</surname> <given-names>G</given-names></string-name></person-group>. <article-title>A tale of two markets: investigating the ransomware payments economy</article-title>. <source>Commun ACM</source>. <year>2023</year>;<volume>66</volume>(<issue>8</issue>):<fpage>74</fpage>&#x2013;<lpage>83</lpage>.</mixed-citation></ref>
<ref id="ref-167"><label>[167]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Phipps</surname> <given-names>A</given-names></string-name>, <string-name><surname>Nurse</surname> <given-names>JRC</given-names></string-name></person-group>. <article-title>Inside ransomware groups: an analysis of their origins, structures, and dynamics</article-title>. <source>Comput Secur</source>. <year>2026</year>;<volume>160</volume>:<fpage>104705</fpage>.</mixed-citation></ref>
<ref id="ref-168"><label>[168]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Delgado-Mohatar</surname> <given-names>O</given-names></string-name>, <string-name><surname>Sierra-C&#x00E1;mara</surname> <given-names>JM</given-names></string-name>, <string-name><surname>Anguiano</surname> <given-names>E</given-names></string-name></person-group>. <article-title>Blockchain-based semi-autonomous ransomware</article-title>. <source>Future Gener Comput Syst</source>. <year>2020</year>;<volume>112</volume>(<issue>6</issue>):<fpage>589</fpage>&#x2013;<lpage>603</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.future.2020.02.037</pub-id>.</mixed-citation></ref>
<ref id="ref-169"><label>[169]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Adams</surname> <given-names>M</given-names></string-name>, <string-name><surname>Moore</surname> <given-names>T</given-names></string-name></person-group>. <article-title>How informative are cybersecurity risk disclosures? Empirical analysis of firms targeted by ransomware</article-title>. <source>Comput Secur</source>. <year>2025</year>;<volume>159</volume>(<issue>5799</issue>):<fpage>104626</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2025.104626</pub-id>.</mixed-citation></ref>
<ref id="ref-170"><label>[170]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>van der Horst</surname> <given-names>M</given-names></string-name>, <string-name><surname>Kho</surname> <given-names>R</given-names></string-name>, <string-name><surname>Gadyatskaya</surname> <given-names>O</given-names></string-name>, <string-name><surname>Mollema</surname> <given-names>M</given-names></string-name>, <string-name><surname>Van Eeten</surname> <given-names>M</given-names></string-name>, <string-name><surname>Zhauniarovich</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>High stakes, low certainty: evaluating the efficacy of high-level indicators of compromise in ransomware attribution</article-title>. In: <conf-name>Proceedings of the 34th USENIX Security Symposium (USENIX Sec), SEC&#x2019;25; 2025 Aug 13&#x2013;15</conf-name>; <publisher-loc>Seattle, WA, USA</publisher-loc>.</mixed-citation></ref>
<ref id="ref-171"><label>[171]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Brewer</surname> <given-names>R</given-names></string-name></person-group>. <article-title>Ransomware attacks: detection, prevention and cure</article-title>. <source>Netw Secur</source>. <year>2016</year>;<volume>2016</volume>(<issue>9</issue>):<fpage>5</fpage>&#x2013;<lpage>9</lpage>.</mixed-citation></ref>
<ref id="ref-172"><label>[172]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Furnell</surname> <given-names>S</given-names></string-name>, <string-name><surname>Emm</surname> <given-names>D</given-names></string-name></person-group>. <article-title>The ABC of ransomware protection</article-title>. <source>Comput Fraud Secur</source>. <year>2017</year>;<volume>2017</volume>(<issue>10</issue>):<fpage>5</fpage>&#x2013;<lpage>11</lpage>. doi:<pub-id pub-id-type="doi">10.1016/s1361-3723(17)30089-1</pub-id>.</mixed-citation></ref>
<ref id="ref-173"><label>[173]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Srinivasan</surname> <given-names>CR</given-names></string-name></person-group>. <article-title>Hobby hackers to billion-dollar industry: the evolution of ransomware</article-title>. <source>Comput Fraud Secur</source>. <year>2017</year>;<volume>2017</volume>(<issue>11</issue>):<fpage>7</fpage>&#x2013;<lpage>9</lpage>.</mixed-citation></ref>
<ref id="ref-174"><label>[174]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>O&#x2019;Kane</surname> <given-names>P</given-names></string-name>, <string-name><surname>Sezer</surname> <given-names>S</given-names></string-name>, <string-name><surname>Carlin</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Evolution of ransomware</article-title>. <source>IET Netw</source>. <year>2018</year>;<volume>7</volume>(<issue>5</issue>):<fpage>321</fpage>&#x2013;<lpage>7</lpage>. doi:<pub-id pub-id-type="doi">10.1049/iet-net.2017.0207</pub-id>.</mixed-citation></ref>
<ref id="ref-175"><label>[175]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kharraz</surname> <given-names>A</given-names></string-name>, <string-name><surname>Robertson</surname> <given-names>W</given-names></string-name>, <string-name><surname>Kirda</surname> <given-names>E</given-names></string-name></person-group>. <article-title>Protecting against ransomware: a new line of research or restating classic ideas?</article-title> <source>IEEE Secur Priv</source>. <year>2018</year>;<volume>16</volume>(<issue>3</issue>):<fpage>103</fpage>&#x2013;<lpage>7</lpage>.</mixed-citation></ref>
<ref id="ref-176"><label>[176]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Dargahi</surname> <given-names>T</given-names></string-name>, <string-name><surname>Dehghantanha</surname> <given-names>A</given-names></string-name>, <string-name><surname>Bahrami</surname> <given-names>PN</given-names></string-name>, <string-name><surname>Conti</surname> <given-names>M</given-names></string-name>, <string-name><surname>Bianchi</surname> <given-names>G</given-names></string-name>, <string-name><surname>Benedetto</surname> <given-names>L</given-names></string-name></person-group>. <article-title>A Cyber-Kill-Chain based taxonomy of crypto-ransomware features</article-title>. <source>J Comput Virol Hacking Tech</source>. <year>2019</year>;<volume>15</volume>(<issue>4</issue>):<fpage>277</fpage>&#x2013;<lpage>305</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s11416-019-00338-7</pub-id>.</mixed-citation></ref>
<ref id="ref-177"><label>[177]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hull</surname> <given-names>G</given-names></string-name>, <string-name><surname>John</surname> <given-names>H</given-names></string-name>, <string-name><surname>Arief</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Ransomware deployment methods and analysis: views from a predictive model and human responses</article-title>. <source>Crime Sci</source>. <year>2019</year>;<volume>8</volume>(<issue>1</issue>):<fpage>1</fpage>&#x2013;<lpage>22</lpage>.</mixed-citation></ref>
<ref id="ref-178"><label>[178]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Keshavarzi</surname> <given-names>M</given-names></string-name>, <string-name><surname>Ghaffary</surname> <given-names>HR</given-names></string-name></person-group>. <article-title>I2CE3: a dedicated and separated attack chain for ransomware offenses as the most infamous cyber extortion</article-title>. <source>Comput Sci Rev</source>. <year>2020</year>;<volume>36</volume>:<fpage>100233</fpage>.</mixed-citation></ref>
<ref id="ref-179"><label>[179]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Berrueta</surname> <given-names>E</given-names></string-name>, <string-name><surname>Morato</surname> <given-names>D</given-names></string-name>, <string-name><surname>Maga&#x00F1;a</surname> <given-names>E</given-names></string-name>, <string-name><surname>Izal</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Open repository for the evaluation of ransomware detection tools</article-title>. <source>IEEE Access</source>. <year>2020</year>;<volume>8</volume>:<fpage>65658</fpage>&#x2013;<lpage>69</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2020.2984187</pub-id>.</mixed-citation></ref>
<ref id="ref-180"><label>[180]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hirano</surname> <given-names>M</given-names></string-name>, <string-name><surname>Hodota</surname> <given-names>R</given-names></string-name>, <string-name><surname>Kobayashi</surname> <given-names>R</given-names></string-name></person-group>. <article-title>RanSAP: an open dataset of ransomware storage access patterns for training machine learning models</article-title>. <source>Forensic Sci Int Digit Investig</source>. <year>2022</year>;<volume>40</volume>:<fpage>301314</fpage>.</mixed-citation></ref>
<ref id="ref-181"><label>[181]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hirano</surname> <given-names>M</given-names></string-name>, <string-name><surname>Kobayashi</surname> <given-names>R</given-names></string-name></person-group>. <article-title>RanSMAP: open dataset of ransomware storage and memory access patterns for creating deep learning based ransomware detectors</article-title>. <source>Comput Secur</source>. <year>2025</year>;<volume>150</volume>:<fpage>104202</fpage>.</mixed-citation></ref>
<ref id="ref-182"><label>[182]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Diamantopoulos</surname> <given-names>D</given-names></string-name>, <string-name><surname>Pletka</surname> <given-names>R</given-names></string-name>, <string-name><surname>Sarafijanovic</surname> <given-names>S</given-names></string-name>, <string-name><surname>Narasimha Reddy</surname> <given-names>AL</given-names></string-name>, <string-name><surname>Pozidis</surname> <given-names>H</given-names></string-name></person-group>. <article-title>WannaLaugh: a configurable ransomware emulator&#x2014;learning to mimic malicious storage traces</article-title>. In: <conf-name>Proceedings of the 17th ACM International Systems and Storage Conference, SYSTOR&#x2019;24; 2024 Sep 23&#x2013;24</conf-name>; <publisher-loc>Virtual</publisher-loc>. p. <fpage>118</fpage>&#x2013;<lpage>31</lpage>.</mixed-citation></ref>
<ref id="ref-183"><label>[183]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Molina</surname> <given-names>RMA</given-names></string-name>, <string-name><surname>Bou-Harb</surname> <given-names>E</given-names></string-name>, <string-name><surname>Torabi</surname> <given-names>S</given-names></string-name>, <string-name><surname>Assi</surname> <given-names>C</given-names></string-name></person-group>. <article-title>RPM: ransomware prevention and mitigation using operating systems&#x2019; sensing tactics</article-title>. In: <conf-name>Proceedings of 2023-IEEE International Conference on Communications (ICC); 2023 May 28&#x2013;Jun 1</conf-name>; <publisher-loc>Rome, Italy</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-184"><label>[184]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>McDonald</surname> <given-names>G</given-names></string-name>, <string-name><surname>Papadopoulos</surname> <given-names>P</given-names></string-name>, <string-name><surname>Pitropakis</surname> <given-names>N</given-names></string-name>, <string-name><surname>Ahmad</surname> <given-names>J</given-names></string-name>, <string-name><surname>Buchanan</surname> <given-names>WJ</given-names></string-name></person-group>. <article-title>Ransomware: analysing the impact on Windows active directory domain services</article-title>. <source>Sensors</source>. <year>2022</year>;<volume>22</volume>(<issue>3</issue>):<fpage>953</fpage>; <pub-id pub-id-type="pmid">35161699</pub-id></mixed-citation></ref>
<ref id="ref-185"><label>[185]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Humayun</surname> <given-names>M</given-names></string-name>, <string-name><surname>Jhanjhi</surname> <given-names>NZ</given-names></string-name>, <string-name><surname>Alsayat</surname> <given-names>A</given-names></string-name>, <string-name><surname>Ponnusamy</surname> <given-names>V</given-names></string-name></person-group>. <article-title>Internet of things and ransomware: evolution, mitigation and prevention</article-title>. <source>Egypt Inform J</source>. <year>2021</year>;<volume>22</volume>(<issue>1</issue>):<fpage>105</fpage>&#x2013;<lpage>17</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.eij.2020.05.003</pub-id>.</mixed-citation></ref>
<ref id="ref-186"><label>[186]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Razaulla</surname> <given-names>S</given-names></string-name>, <string-name><surname>Fachkha</surname> <given-names>C</given-names></string-name>, <string-name><surname>Markarian</surname> <given-names>C</given-names></string-name>, <string-name><surname>Gawanmeh</surname> <given-names>A</given-names></string-name>, <string-name><surname>Mansoor</surname> <given-names>W</given-names></string-name>, <string-name><surname>Fung</surname> <given-names>BCM</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>The age of ransomware: a survey on the evolution, taxonomy, and research directions</article-title>. <source>IEEE Access</source>. <year>2023</year>;<volume>11</volume>:<fpage>40698</fpage>&#x2013;<lpage>723</lpage>.</mixed-citation></ref>
<ref id="ref-187"><label>[187]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Benmalek</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Ransomware on cyber-physical systems: taxonomies, case studies, security gaps, and open challenges</article-title>. <source>Internet Things Cyber Phys Syst</source>. <year>2024</year>;<volume>4</volume>:<fpage>186</fpage>&#x2013;<lpage>202</lpage>.</mixed-citation></ref>
<ref id="ref-188"><label>[188]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Almeida</surname> <given-names>F</given-names></string-name>, <string-name><surname>Imran</surname> <given-names>M</given-names></string-name>, <string-name><surname>Raik</surname> <given-names>J</given-names></string-name>, <string-name><surname>Pagliarini</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Ransomware attack as hardware trojan: a feasibility and demonstration study</article-title>. <source>IEEE Access</source>. <year>2022</year>;<volume>10</volume>:<fpage>44827</fpage>&#x2013;<lpage>39</lpage>.</mixed-citation></ref>
<ref id="ref-189"><label>[189]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Reidys</surname> <given-names>B</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>P</given-names></string-name>, <string-name><surname>Huang</surname> <given-names>J</given-names></string-name></person-group>. <article-title>RSSD: defend against ransomware with hardware-isolated network-storage codesign and post-attack analysis</article-title>. In: <conf-name>Proceedings of the 27th ACM International Conference on Architectural Support for Programming Languages and Operating Systems; 2022 Feb 28&#x2013;Mar 4</conf-name>; <publisher-loc>La Jolla, CA, USA</publisher-loc>. p. <fpage>726</fpage>&#x2013;<lpage>39</lpage>.</mixed-citation></ref>
<ref id="ref-190"><label>[190]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Oz</surname> <given-names>H</given-names></string-name>, <string-name><surname>Aris</surname> <given-names>A</given-names></string-name>, <string-name><surname>Acar</surname> <given-names>A</given-names></string-name>, <string-name><surname>Tuncay</surname> <given-names>GS</given-names></string-name>, <string-name><surname>Babun</surname> <given-names>L</given-names></string-name>, <string-name><surname>Uluagac</surname> <given-names>S</given-names></string-name></person-group>. <article-title>R&#x00D8;B: ransomware over modern web browsers</article-title>. In: <conf-name>Proceedings of 32nd USENIX Security Symposium (USENIX Security 23); 2023 Aug 9&#x2013;11</conf-name>; <publisher-loc>Anaheim, CA, USA</publisher-loc>. p. <fpage>7073</fpage>&#x2013;<lpage>90</lpage>.</mixed-citation></ref>
<ref id="ref-191"><label>[191]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rana</surname> <given-names>MU</given-names></string-name>, <string-name><surname>Shah</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Al-Naeem</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Maple</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Ransomware attacks in cyber-physical systems: countermeasure of attack vectors through automated web defenses</article-title>. <source>IEEE Access</source>. <year>2024</year>;<volume>12</volume>:<fpage>149722</fpage>&#x2013;<lpage>39</lpage>.</mixed-citation></ref>
<ref id="ref-192"><label>[192]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>McIntosh</surname> <given-names>T</given-names></string-name>, <string-name><surname>Kayes</surname> <given-names>ASM</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>YPP</given-names></string-name>, <string-name><surname>Ng</surname> <given-names>A</given-names></string-name>, <string-name><surname>Watters</surname> <given-names>P</given-names></string-name></person-group>. <article-title>Applying staged event-driven access control to combat ransomware</article-title>. <source>Comput Secur</source>. <year>2023</year>;<volume>128</volume>(<issue>1</issue>):<fpage>103160</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2023.103160</pub-id>.</mixed-citation></ref>
<ref id="ref-193"><label>[193]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Raj</surname> <given-names>A</given-names></string-name>, <string-name><surname>Narayan</surname> <given-names>V</given-names></string-name>, <string-name><surname>Muskan</surname> <given-names>V</given-names></string-name>, <string-name><surname>Sani</surname> <given-names>A</given-names></string-name>, <string-name><surname>Sharma</surname> <given-names>P</given-names></string-name>, <string-name><surname>Sarma</surname> <given-names>SS</given-names></string-name></person-group>. <article-title>Modern ransomware: evolution, methodology, attack model, prevention and mitigation using multi-tiered approach</article-title>. <source>Secur Priv</source>. <year>2024</year>;<volume>7</volume>(<issue>6</issue>):<fpage>e436</fpage>.</mixed-citation></ref>
<ref id="ref-194"><label>[194]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chimmanee</surname> <given-names>K</given-names></string-name>, <string-name><surname>Jantavongso</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Digital forensic of maze ransomware: a case of electricity distributor enterprise in ASEAN</article-title>. <source>Expert Syst Appl</source>. <year>2024</year>;<volume>249</volume>:<fpage>123652</fpage>.</mixed-citation></ref>
<ref id="ref-195"><label>[195]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lee</surname> <given-names>S</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>HK</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>K</given-names></string-name></person-group>. <article-title>Ransomware protection using the moving target defense perspective</article-title>. <source>Comput Electr Eng</source>. <year>2019</year>;<volume>78</volume>(<issue>66</issue>):<fpage>288</fpage>&#x2013;<lpage>99</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.compeleceng.2019.07.014</pub-id>.</mixed-citation></ref>
<ref id="ref-196"><label>[196]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lee</surname> <given-names>S</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>S</given-names></string-name>, <string-name><surname>Park</surname> <given-names>J</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>K</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>K</given-names></string-name></person-group>. <article-title>Hiding in the crowd: ransomware protection by adopting camouflage and hiding strategy with the link file</article-title>. <source>IEEE Access</source>. <year>2023</year>;<volume>11</volume>:<fpage>92693</fpage>&#x2013;<lpage>704</lpage>.</mixed-citation></ref>
<ref id="ref-197"><label>[197]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Khan</surname> <given-names>MM</given-names></string-name>, <string-name><surname>Hyder</surname> <given-names>MF</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>SM</given-names></string-name>, <string-name><surname>Arshad</surname> <given-names>J</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>MM</given-names></string-name></person-group>. <article-title>Ransomware prevention using moving target defense based approach</article-title>. <source>Concurr Comput Pract Exp</source>. <year>2023</year>;<volume>35</volume>(<issue>7</issue>):<fpage>e7592</fpage>. doi:<pub-id pub-id-type="doi">10.1002/cpe.7592</pub-id>.</mixed-citation></ref>
<ref id="ref-198"><label>[198]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhao</surname> <given-names>JY</given-names></string-name>, <string-name><surname>Kessler</surname> <given-names>EG</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Jalal</surname> <given-names>K</given-names></string-name>, <string-name><surname>Cooper</surname> <given-names>CA</given-names></string-name>, <string-name><surname>Brewer</surname> <given-names>JJ</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Impact of trauma hospital ransomware attack on surgical residency training</article-title>. <source>J Surg Res</source>. <year>2018</year>;<volume>232</volume>:<fpage>389</fpage>&#x2013;<lpage>97</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.jss.2018.06.072</pub-id>; <pub-id pub-id-type="pmid">30463746</pub-id></mixed-citation></ref>
<ref id="ref-199"><label>[199]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Neprash</surname> <given-names>HT</given-names></string-name>, <string-name><surname>McGlave</surname> <given-names>CC</given-names></string-name>, <string-name><surname>Cross</surname> <given-names>DA</given-names></string-name>, <string-name><surname>Virnig</surname> <given-names>BA</given-names></string-name>, <string-name><surname>Puskarich</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Huling</surname> <given-names>JD</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Trends in ransomware attacks on us hospitals, clinics, and other health care delivery organizations, 2016&#x2013;2021</article-title>. <source>JAMA Health Forum</source>. <year>2022</year>;<volume>3</volume>(<issue>12</issue>):<fpage>e224873</fpage>. doi:<pub-id pub-id-type="doi">10.1001/jamahealthforum.2022.4873</pub-id>; <pub-id pub-id-type="pmid">36580326</pub-id></mixed-citation></ref>
<ref id="ref-200"><label>[200]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Dameff</surname> <given-names>C</given-names></string-name>, <string-name><surname>Tully</surname> <given-names>J</given-names></string-name>, <string-name><surname>Chan</surname> <given-names>TC</given-names></string-name>, <string-name><surname>Castillo</surname> <given-names>EM</given-names></string-name>, <string-name><surname>Savage</surname> <given-names>S</given-names></string-name>, <string-name><surname>Maysent</surname> <given-names>P</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Ransomware attack associated with disruptions at adjacent emergency departments in the US</article-title>. <source>JAMA Netw Open</source>. <year>2023</year>;<volume>6</volume>(<issue>5</issue>):<fpage>e2312270</fpage>. doi:<pub-id pub-id-type="doi">10.1001/jamanetworkopen.2023.12270</pub-id>; <pub-id pub-id-type="pmid">37155166</pub-id></mixed-citation></ref>
<ref id="ref-201"><label>[201]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Villalba</surname> <given-names>LJG</given-names></string-name>, <string-name><surname>Orozco</surname> <given-names>ALS</given-names></string-name>, <string-name><surname>Vivar</surname> <given-names>AL</given-names></string-name>, <string-name><surname>Vega</surname> <given-names>EAA</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>T-H</given-names></string-name></person-group>. <article-title>Ransomware automatic data acquisition tool</article-title>. <source>IEEE Access</source>. <year>2018</year>;<volume>6</volume>:<fpage>55043</fpage>&#x2013;<lpage>52</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2018.2868885</pub-id>.</mixed-citation></ref>
<ref id="ref-202"><label>[202]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Song</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Tian</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Similarity analysis of ransomware attacks based on ATT&#x0026;CK matrix</article-title>. <source>IEEE Access</source>. <year>2023</year>;<volume>11</volume>:<fpage>111378</fpage>&#x2013;<lpage>88</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2023.3322427</pub-id>.</mixed-citation></ref>
<ref id="ref-203"><label>[203]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>John</surname> <given-names>TC</given-names></string-name>, <string-name><surname>Abbasi</surname> <given-names>MS</given-names></string-name>, <string-name><surname>Al-Sahaf</surname> <given-names>H</given-names></string-name>, <string-name><surname>Welch</surname> <given-names>I</given-names></string-name>, <string-name><surname>Jang-Jaccard</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Evolving malice scoring models for ransomware detection: an automated approach by utilising genetic programming and cooperative coevolution</article-title>. <source>Comput Secur</source>. <year>2023</year>;<volume>129</volume>:<fpage>103215</fpage>.</mixed-citation></ref>
<ref id="ref-204"><label>[204]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Anand</surname> <given-names>PM</given-names></string-name>, <string-name><surname>Charan</surname> <given-names>PVS</given-names></string-name>, <string-name><surname>Chunduri</surname> <given-names>H</given-names></string-name>, <string-name><surname>Shukla</surname> <given-names>SK</given-names></string-name></person-group>. <article-title>LARM: linux anti ransomware monitor</article-title>. <source>Comput Secur</source>. <year>2025</year>;<volume>159</volume>:<fpage>104700</fpage>.</mixed-citation></ref>
<ref id="ref-205"><label>[205]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Venturini</surname> <given-names>M</given-names></string-name>, <string-name><surname>Freda</surname> <given-names>F</given-names></string-name>, <string-name><surname>Miotto</surname> <given-names>E</given-names></string-name>, <string-name><surname>Conti</surname> <given-names>M</given-names></string-name>, <string-name><surname>Giaretta</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Differential area analysis for ransomware: attacks, countermeasures, and limitations</article-title>. <source>IEEE Trans Dependable Secur Comput</source>. <year>2025</year>;<volume>22</volume>(<issue>4</issue>):<fpage>3449</fpage>&#x2013;<lpage>64</lpage>.</mixed-citation></ref>
<ref id="ref-206"><label>[206]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cevallos-Salas</surname> <given-names>D</given-names></string-name>, <string-name><surname>Estrada-Jim&#x00E9;nez</surname> <given-names>J</given-names></string-name>, <string-name><surname>Guam&#x00E1;n</surname> <given-names>DS</given-names></string-name>, <string-name><surname>Urquiza-Aguiar</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Ransomware dynamics: mitigating personal data exfiltration through the SCIRAS lens</article-title>. <source>Comput Secur</source>. <year>2025</year>;<volume>157</volume>:<fpage>104583</fpage>.</mixed-citation></ref>
<ref id="ref-207"><label>[207]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Gray</surname> <given-names>IW</given-names></string-name>, <string-name><surname>Cable</surname> <given-names>J</given-names></string-name>, <string-name><surname>Brown</surname> <given-names>B</given-names></string-name>, <string-name><surname>Cuiujuclu</surname> <given-names>V</given-names></string-name>, <string-name><surname>McCoy</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Money over morals: a business analysis of conti ransomware</article-title>. In: <conf-name>Proceedings of 2022 APWG Symposium on Electronic Crime Research (eCrime); 2022 Nov 30&#x2013;Dec 2</conf-name>; <publisher-loc>Virtual</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>12</lpage>.</mixed-citation></ref>
<ref id="ref-208"><label>[208]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Falco</surname> <given-names>G</given-names></string-name>, <string-name><surname>Thummala</surname> <given-names>R</given-names></string-name>, <string-name><surname>Kubadia</surname> <given-names>A</given-names></string-name></person-group>. <article-title>WannaFly: an approach to satellite ransomware</article-title>. In: <conf-name>Proceedings of the 2023 IEEE 9th International Conference on Space Mission Challenges for Information Technology (SMC-IT); 2023 Jul 18&#x2013;21</conf-name>; <publisher-loc>Pasadena, CA, USA</publisher-loc>. p. <fpage>84</fpage>&#x2013;<lpage>93</lpage>.</mixed-citation></ref>
<ref id="ref-209"><label>[209]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Beerman</surname> <given-names>J</given-names></string-name>, <string-name><surname>Berent</surname> <given-names>D</given-names></string-name>, <string-name><surname>Falter</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Bhunia</surname> <given-names>S</given-names></string-name></person-group>. <article-title>A review of colonial pipeline ransomware attack</article-title>. In: <conf-name>Proceedings of 2023 IEEE/ACM 23rd International Symposium on Cluster, Cloud and Internet Computing Workshops (CCGridW); 2023 May 1&#x2013;4</conf-name>; <publisher-loc>Bangalore, India</publisher-loc>. p. <fpage>8</fpage>&#x2013;<lpage>15</lpage>.</mixed-citation></ref>
<ref id="ref-210"><label>[210]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Zou</surname> <given-names>S</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Jiang</surname> <given-names>S</given-names></string-name>, <string-name><surname>Cheng</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Ji</surname> <given-names>X</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>W</given-names></string-name></person-group>. <article-title>OutletGuarder: detecting darkside ransomware by power factor correction signals in an electrical outlet</article-title>. In: <conf-name>Proceedings of 2022 IEEE 28th International Conference on Parallel and Distributed Systems (ICPADS); 2023 Jun 10&#x2013;13</conf-name>; <publisher-loc>Nanjing, China</publisher-loc>. p. <fpage>419</fpage>&#x2013;<lpage>26</lpage>.</mixed-citation></ref>
<ref id="ref-211"><label>[211]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Mofidi</surname> <given-names>F</given-names></string-name>, <string-name><surname>Hounsinou</surname> <given-names>SG</given-names></string-name>, <string-name><surname>Bloom</surname> <given-names>G</given-names></string-name></person-group>. <article-title>L-IDS: a multi-layered approach to ransomware detection in IoT</article-title>. In: <conf-name>Proceedings of 2024 IEEE 14th Annual Computing and Communication Workshop and Conference (CCWC); 2024 Jan 8&#x2013;10</conf-name>; <publisher-loc>Las Vegas, NV, USA</publisher-loc>. p. <fpage>0387</fpage>&#x2013;<lpage>96</lpage>.</mixed-citation></ref>
<ref id="ref-212"><label>[212]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Lawall</surname> <given-names>A</given-names></string-name>, <string-name><surname>Beenken</surname> <given-names>P</given-names></string-name></person-group>. <article-title>A threat-led approach to mitigating ransomware attacks: insights from a comprehensive analysis of the ransomware ecosystem</article-title>. In: <conf-name>Proceedings of the 2024 European Interdisciplinary Cybersecurity Conference, EICC&#x2019;24; 2024 Jan 5&#x2013;6</conf-name>; <publisher-loc>Xanthi, Greece</publisher-loc>. p. <fpage>210</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-213"><label>[213]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Hansen</surname> <given-names>P</given-names></string-name>, <string-name><surname>Henry</surname> <given-names>WC</given-names></string-name>, <string-name><surname>Reith</surname> <given-names>MG</given-names></string-name>, <string-name><surname>Thummala</surname> <given-names>R</given-names></string-name>, <string-name><surname>Falco</surname> <given-names>G</given-names></string-name></person-group>. <article-title>Guarding the galaxy: satellite ransomware and countermeasures</article-title>. In: <conf-name>Proceedings of 2024 IEEE Aerospace Conference; 2024 Mar 2&#x2013;9</conf-name>; <publisher-loc>Big Sky, MT, USA</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-214"><label>[214]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Holmstr&#x00F6;m</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Managing a ransomware attack: the resilience of a swedish municipality&#x2014;A case study</article-title>. In: <conf-name>Proceedings of International Conference on Information Systems Security and Privacy; 2024 Feb 26&#x2013;28; Lisbon, Portugal</conf-name>.</mixed-citation></ref>
<ref id="ref-215"><label>[215]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Dhumal</surname> <given-names>A</given-names></string-name>, <string-name><surname>Ghaleb</surname> <given-names>M</given-names></string-name>, <string-name><surname>Abdelsalam</surname> <given-names>S</given-names></string-name>, <string-name><surname>Moldovan</surname> <given-names>A-N</given-names></string-name>, <string-name><surname>Hamdan</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Zero trust architecture for ransomware defense in virtualized environment</article-title>. In: <conf-name>Proceedings of the IEEE/ACM 12th International Conference on Big Data Computing, Applications and Technologies; 2025 Dec 1&#x2013;4</conf-name>; <publisher-loc>Nantes, France</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>7</lpage>.</mixed-citation></ref>
<ref id="ref-216"><label>[216]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Barker</surname> <given-names>WC</given-names></string-name>, <string-name><surname>Fisher</surname> <given-names>W</given-names></string-name>, <string-name><surname>Scarfone</surname> <given-names>K</given-names></string-name>, <string-name><surname>Souppaya</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Cybersecurity framework profile for ransomware risk management</article-title>. <source>Natl Inst Stand Technol</source>. <year>2022</year>. doi:<pub-id pub-id-type="doi">10.6028/NIST.IR.8374-draft</pub-id>.</mixed-citation></ref>
<ref id="ref-217"><label>[217]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Zhu</surname> <given-names>T</given-names></string-name>, <string-name><surname>Li</surname> <given-names>X</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>W</given-names></string-name></person-group>. <article-title>Applying ChatGPT-powered game theory in ransomware negotiations</article-title>. TechRxiv. 2023. doi:<pub-id pub-id-type="doi">10.36227/techrxiv.170244324.48846520/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-218"><label>[218]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Fujima</surname> <given-names>H</given-names></string-name>, <string-name><surname>Kumamoto</surname> <given-names>T</given-names></string-name>, <string-name><surname>Yoshida</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Using ChatGPT to analyze ransomware messages and to predict ransomware threats</article-title>. <source>Res Sq</source>. <year>2023</year>. doi:<pub-id pub-id-type="doi">10.21203/rs.3.rs-3645967/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-219"><label>[219]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kumamoto</surname> <given-names>T</given-names></string-name>, <string-name><surname>Yoshida</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Fujima</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Evaluating large language models in ransomware negotiation: a comparative analysis of ChatGPT and claude</article-title>. <source>Res Sq</source>. <year>2023</year>. doi:<pub-id pub-id-type="doi">10.21203/rs.3.rs-3719038/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-220"><label>[220]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>W</given-names></string-name>, <string-name><surname>Li</surname> <given-names>X</given-names></string-name>, <string-name><surname>Zhu</surname> <given-names>T</given-names></string-name></person-group>. <article-title>Entropy and memory forensics in ransomware analysis: utilizing LLAMA-7B for advanced pattern recognition</article-title>. TechRxiv. 2023. doi:<pub-id pub-id-type="doi">10.36227/techrxiv.24742389.v1</pub-id>.</mixed-citation></ref>
<ref id="ref-221"><label>[221]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Hyslip</surname> <given-names>TS</given-names></string-name>, <string-name><surname>Burruss</surname> <given-names>GW</given-names></string-name></person-group>. <chapter-title>Ransomware</chapter-title>. In: <source>Handbook on crime and technology</source>. <publisher-loc>Cheltenham, UK</publisher-loc>: <publisher-name>Edward Elgar Publishing</publisher-name>; <year>2023</year>. p. <fpage>86</fpage>&#x2013;<lpage>104</lpage>.</mixed-citation></ref>
<ref id="ref-222"><label>[222]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>M&#x00F6;ller</surname> <given-names>DPF</given-names></string-name></person-group>. <chapter-title>Ransomware attacks and scenarios: cost factors and loss of reputation</chapter-title>. In: <source>Guide to cybersecurity in digital transformation: trends, methods, technologies, applications and best practices</source>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2023</year>. p. <fpage>273</fpage>&#x2013;<lpage>303</lpage>.</mixed-citation></ref>
<ref id="ref-223"><label>[223]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kang</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Gu</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Enhancing ransomware detection: a windows API min max relevance refinement approach</article-title>. <source>Preprints</source>. <year>2023</year>. doi:<pub-id pub-id-type="doi">10.20944/preprints202311.1004.v1</pub-id>.</mixed-citation></ref>
<ref id="ref-224"><label>[224]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Liu</surname> <given-names>S</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>X</given-names></string-name></person-group>. <article-title>Applying moving target defense against data theft ransomware on windows OS</article-title>. <source>Preprints</source>. <year>2023</year>. doi:<pub-id pub-id-type="doi">10.20944/preprints202312.0948.v1</pub-id>.</mixed-citation></ref>
<ref id="ref-225"><label>[225]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Horduna</surname> <given-names>M</given-names></string-name>, <string-name><surname>L&#x0103;z&#x0103;rescu</surname> <given-names>S-M</given-names></string-name>, <string-name><surname>Simion</surname> <given-names>E</given-names></string-name></person-group>. <article-title>A note on machine learning applied in ransomware detection</article-title>. 2023 [cited 2026 Jan 1]. Available from: <ext-link ext-link-type="uri" xlink:href="https://ia.cr/2023/045">https://ia.cr/2023/045</ext-link>.</mixed-citation></ref>
<ref id="ref-226"><label>[226]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Takeuchi</surname> <given-names>K</given-names></string-name>, <string-name><surname>Kumamoto</surname> <given-names>T</given-names></string-name>, <string-name><surname>Yoshida</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Fujima</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Decentralized identity verification system for data access to prevent data exfiltration ransomware</article-title>. TechRxiv. <year>2022</year>. doi:<pub-id pub-id-type="doi">10.36227/techrxiv.24732729.v1</pub-id>.</mixed-citation></ref>
<ref id="ref-227"><label>[227]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Altais</surname> <given-names>B</given-names></string-name>, <string-name><surname>Arkwright</surname> <given-names>B</given-names></string-name>, <string-name><surname>Ashbourne</surname> <given-names>T</given-names></string-name>, <string-name><surname>Middleham</surname> <given-names>E</given-names></string-name></person-group>. <article-title>Novel algorithmic framework for high-fidelity ransomware detection using entropy-based behavioural signatures</article-title>. <comment>Preprints. 2024</comment>. doi:<pub-id pub-id-type="doi">10.31219/osf.io/sdkfj</pub-id>.</mixed-citation></ref>
<ref id="ref-228"><label>[228]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Panaras</surname> <given-names>A</given-names></string-name>, <string-name><surname>Silverstein</surname> <given-names>B</given-names></string-name>, <string-name><surname>Edwards</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Automated cooperative clustering for proactive ransomware detection and mitigation using machine learning</article-title>. <source>TechRxiv</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.36227/techrxiv.172684422.25967523/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-229"><label>[229]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sarewap</surname> <given-names>R</given-names></string-name>, <string-name><surname>Muller</surname> <given-names>P</given-names></string-name>, <string-name><surname>Baker</surname> <given-names>T</given-names></string-name>, <string-name><surname>Dupont</surname> <given-names>M</given-names></string-name>, <string-name><surname>Steinberg</surname> <given-names>W</given-names></string-name></person-group>. <article-title>Efficient ransomware detection through dynamic file system traffic analysis: a methodological approach</article-title>. Preprints. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.31219/osf.io/xju6w</pub-id>.</mixed-citation></ref>
<ref id="ref-230"><label>[230]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Miranem</surname> <given-names>V</given-names></string-name>, <string-name><surname>Petrescu</surname> <given-names>G</given-names></string-name>, <string-name><surname>Schelling</surname> <given-names>D</given-names></string-name>, <string-name><surname>Vasiliev</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Ransomware detection on Windows systems using file system activities and a hybrid machine learning approach</article-title>. Preprints. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.31219/osf.io/27neh</pub-id>.</mixed-citation></ref>
<ref id="ref-231"><label>[231]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Moritaka</surname> <given-names>H</given-names></string-name>, <string-name><surname>Komuro</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Enhanced ransomware detection using dual-layer random forest on opcode sequences</article-title>. <source>Preprints</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.22541/au.172193050.02354794/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-232"><label>[232]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ozturk</surname> <given-names>M</given-names></string-name>, <string-name><surname>Yilmaz</surname> <given-names>B</given-names></string-name>, <string-name><surname>Arslan</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Demirbas</surname> <given-names>A</given-names></string-name></person-group>. <article-title>An effective strategy for ransomware mitigation on android devices via android OS file system API</article-title>. <source>Res Sq</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.21203/rs.3.rs-4299415/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-233"><label>[233]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wiles</surname> <given-names>A</given-names></string-name>, <string-name><surname>Colombo</surname> <given-names>F</given-names></string-name>, <string-name><surname>Mascorro</surname> <given-names>R</given-names></string-name></person-group>. <article-title>Ransomware detection using network traffic analysis and generative adversarial networks</article-title>. <source>Preprints</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.22541/au.172659907.77469627/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-234"><label>[234]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Gong</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zha</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Tang</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Ransomware detection and classification using generative adversarial networks with dynamic weight adaptation</article-title>. Preprints. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.31219/osf.io/5vju7</pub-id>.</mixed-citation></ref>
<ref id="ref-235"><label>[235]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Optimized ransomware detection through reverse bayer analysis of file system activities</article-title>. Preprints. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.31219/osf.io/du74g</pub-id>.</mixed-citation></ref>
<ref id="ref-236"><label>[236]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Eisenwer</surname> <given-names>S</given-names></string-name>, <string-name><surname>Berenyi</surname> <given-names>S</given-names></string-name>, <string-name><surname>Zaharoff</surname> <given-names>A</given-names></string-name>, <string-name><surname>Montrose</surname> <given-names>J</given-names></string-name>, <string-name><surname>Solberg</surname> <given-names>E</given-names></string-name>, <string-name><surname>Grimaldi</surname> <given-names>F</given-names></string-name></person-group>. <article-title>Automated detection of ransomware using dynamic code sequence mapping</article-title>. <source>TechRxiv</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.36227/techrxiv.173014814.48823875/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-237"><label>[237]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Stastne</surname> <given-names>S</given-names></string-name>, <string-name><surname>Johansson</surname> <given-names>S</given-names></string-name>, <string-name><surname>Laurent</surname> <given-names>S</given-names></string-name>, <string-name><surname>Kruger</surname> <given-names>T</given-names></string-name>, <string-name><surname>Fitzgerald</surname> <given-names>G</given-names></string-name></person-group>. <article-title>Dynamic signal-based ransomware detection with temporal-pattern profiling technique</article-title>. <source>Preprints</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.22541/au.173083395.56558646/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-238"><label>[238]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Axali</surname> <given-names>J</given-names></string-name>, <string-name><surname>Devereaux</surname> <given-names>L</given-names></string-name>, <string-name><surname>Spencer</surname> <given-names>A</given-names></string-name>, <string-name><surname>Vasilev</surname> <given-names>F</given-names></string-name></person-group>. <article-title>A multicriteria decision-making approach for ransomware detection using Mitre ATT&#x0026;CK mitigation strategy</article-title>. <source>Preprints</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.22541/au.172591117.70081883/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-239"><label>[239]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Limer</surname> <given-names>A</given-names></string-name>, <string-name><surname>Abramovich</surname> <given-names>R</given-names></string-name>, <string-name><surname>Devereux</surname> <given-names>G</given-names></string-name>, <string-name><surname>Ziemniak</surname> <given-names>P</given-names></string-name>, <string-name><surname>Dubois</surname> <given-names>F</given-names></string-name></person-group>. <article-title>Automated ransomware detection using dynamic behavior trace profiling</article-title>. <source>TechRxiv</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.36227/techrxiv.173030558.85237080/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-240"><label>[240]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Neweva</surname> <given-names>W</given-names></string-name>, <string-name><surname>Fitzwilliam</surname> <given-names>O</given-names></string-name>, <string-name><surname>Waterbridge</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Forensic analysis of live ransomware attacks on linux-based laptop systems: techniques and evaluation</article-title>. <source>Res Sq</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.21203/rs.3.rs-4900486/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-241"><label>[241]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>R</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Ransomware detection with a 2-tier machine learning approach using a novel clustering algorithm</article-title>. <source>Res Sq</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.21203/rs.3.rs-4567706/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-242"><label>[242]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lowev</surname> <given-names>T</given-names></string-name>, <string-name><surname>Fisher</surname> <given-names>C</given-names></string-name>, <string-name><surname>Collins</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Advanced ransomware detection and classification via semantic analysis of memory opcode patterns</article-title>. Preprints. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.31219/osf.io/5cfvp</pub-id>.</mixed-citation></ref>
<ref id="ref-243"><label>[243]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tariq</surname> <given-names>U</given-names></string-name></person-group>. <article-title>Combatting ransomware in ZephyrOS-activated industrial IoT environments</article-title>. <source>Heliyon</source>. <year>2024</year>;<volume>10</volume>(<issue>9</issue>):<fpage>e29917</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.heliyon.2024.e29917</pub-id>; <pub-id pub-id-type="pmid">38694103</pub-id></mixed-citation></ref>
<ref id="ref-244"><label>[244]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Alzonem</surname> <given-names>F</given-names></string-name>, <string-name><surname>Albrecht</surname> <given-names>G</given-names></string-name>, <string-name><surname>Castellanos</surname> <given-names>D</given-names></string-name>, <string-name><surname>Vandermeer</surname> <given-names>M</given-names></string-name>, <string-name><surname>Stansfield</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Ransomware detection using convolutional neural networks and isolation forests in network traffic patterns</article-title>. <source>Res Sq</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.21203/rs.3.rs-5278706/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-245"><label>[245]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Blaas</surname> <given-names>N</given-names></string-name>, <string-name><surname>Winterbourne</surname> <given-names>J</given-names></string-name>, <string-name><surname>Beauregarde</surname> <given-names>W</given-names></string-name>, <string-name><surname>Heathcote</surname> <given-names>E</given-names></string-name></person-group>. <article-title>Ransomware detection through contextual behavior mapping and sequential dependency analysis</article-title>. <source>Res Sq</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.21203/rs.3.rs-5527159/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-246"><label>[246]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Baston</surname> <given-names>P</given-names></string-name>, <string-name><surname>Lacroix</surname> <given-names>E</given-names></string-name>, <string-name><surname>Jackson</surname> <given-names>T</given-names></string-name>, <string-name><surname>Maitland</surname> <given-names>L</given-names></string-name>, <string-name><surname>Lehmann</surname> <given-names>E</given-names></string-name>, <string-name><surname>Shulman</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Hierarchical ransomware detection with adaptive anomaly clustering and threat signature prediction</article-title>. <source>TechRxiv</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.36227/techrxiv.173203458.80683063/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-247"><label>[247]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bennett</surname> <given-names>E</given-names></string-name>, <string-name><surname>Ellington</surname> <given-names>J</given-names></string-name>, <string-name><surname>Blackstone</surname> <given-names>G</given-names></string-name>, <string-name><surname>Whitfield</surname> <given-names>H</given-names></string-name>, <string-name><surname>Ashcroft</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Enhanced vectorized ransomware detection: a novel spectral segmentation approach using nonlinear frequency patterns</article-title>. <year>2024 [cited 2026 Jan 1]</year>. Available from: <ext-link ext-link-type="uri" xlink:href="https://osf.io/preprints/osf/qd253_v1">https://osf.io/preprints/osf/qd253_v1</ext-link>.</mixed-citation></ref>
<ref id="ref-248"><label>[248]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hurley</surname> <given-names>R</given-names></string-name>, <string-name><surname>Kruger</surname> <given-names>P</given-names></string-name>, <string-name><surname>Nascimento</surname> <given-names>H</given-names></string-name>, <string-name><surname>Keller</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Real-time ransomware detection through adaptive behavior fingerprinting for improved cybersecurity resilience and defense</article-title>. Preprints. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.31219/osf.io/7d2y5</pub-id>.</mixed-citation></ref>
<ref id="ref-249"><label>[249]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Loaiza</surname> <given-names>C</given-names></string-name>, <string-name><surname>Becker</surname> <given-names>J</given-names></string-name>, <string-name><surname>Johansson</surname> <given-names>M</given-names></string-name>, <string-name><surname>Corbett</surname> <given-names>S</given-names></string-name>, <string-name><surname>Vesely</surname> <given-names>F</given-names></string-name>, <string-name><surname>Demir</surname> <given-names>P</given-names></string-name></person-group>. <article-title>Dynamic temporal signature analysis for ransomware detection using sequential entropy monitoring</article-title>. <source>TechRxiv</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.36227/techrxiv.173091147.70647129/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-250"><label>[250]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bai</surname> <given-names>H</given-names></string-name>, <string-name><surname>Hu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>L</given-names></string-name>, <string-name><surname>Lin</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Ransomware detection on Windows systems using file system activity monitoring and a hybrid XGBoost-isolation forest approach</article-title>. <source>Preprints</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.22541/au.172893916.67101182/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-251"><label>[251]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Schmaltz</surname> <given-names>K</given-names></string-name>, <string-name><surname>Thompson</surname> <given-names>S</given-names></string-name>, <string-name><surname>Mendes</surname> <given-names>D</given-names></string-name>, <string-name><surname>Carvalho</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Robust defense mechanisms against adversarial ransomware attacks: implementing a universal network-level detection filter</article-title>. <source>Res Sq</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.21203/rs.3.rs-5123680/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-252"><label>[252]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xu</surname> <given-names>B</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Examining windows file system IRP operations with machine learning for ransomware detection</article-title>. <source>Res Sq</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.21203/rs.3.rs-4032456/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-253"><label>[253]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lummen</surname> <given-names>D</given-names></string-name>, <string-name><surname>Gruber</surname> <given-names>S</given-names></string-name>, <string-name><surname>Schmidt</surname> <given-names>A</given-names></string-name>, <string-name><surname>Abramov</surname> <given-names>J</given-names></string-name>, <string-name><surname>Anderson</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Opcode-based ransomware detection using hybrid extreme gradient boosting and recurrent neural networks</article-title>. <source>TechRxiv</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.36227/techrxiv.172962886.67904740/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-254"><label>[254]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Brinkley</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Thompson</surname> <given-names>D</given-names></string-name>, <string-name><surname>Simmons</surname> <given-names>N</given-names></string-name></person-group>. <article-title>Machine learning-based intrusion detection for zero-day ransomware in unseen data</article-title>. <source>Preprints</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.22541/au.172685266.62026194/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-255"><label>[255]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Blue</surname> <given-names>E</given-names></string-name>, <string-name><surname>Campbell</surname> <given-names>G</given-names></string-name>, <string-name><surname>Stokes</surname> <given-names>A</given-names></string-name>, <string-name><surname>Thompson</surname> <given-names>L</given-names></string-name>, <string-name><surname>Clarke</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Ransomware detection on linux operating system using recurrent neural networks with binary opcode analysis</article-title>. Preprints. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.31219/osf.io/vzk3d</pub-id>.</mixed-citation></ref>
<ref id="ref-256"><label>[256]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Feyal</surname> <given-names>J</given-names></string-name>, <string-name><surname>Matthews</surname> <given-names>R</given-names></string-name></person-group>. <article-title>Quality evaluation of true random bit-streams in ransomware payload bytecode</article-title>. <source>TechRxiv</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.36227/techrxiv.172651853.33813035/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-257"><label>[257]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Keyogeg</surname> <given-names>B</given-names></string-name>, <string-name><surname>Thompson</surname> <given-names>M</given-names></string-name>, <string-name><surname>Dawson</surname> <given-names>G</given-names></string-name>, <string-name><surname>Wagner</surname> <given-names>D</given-names></string-name>, <string-name><surname>Johnson</surname> <given-names>G</given-names></string-name>, <string-name><surname>Elliott</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Automated detection of ransomware in windows active directory domain services using log analysis and machine learning</article-title>. <source>Preprints</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.22541/au.172779663.36925703/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-258"><label>[258]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>G</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>S</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>Q</given-names></string-name></person-group>. <article-title>A hybrid framework for ransomware detection using deep learning and monte carlo tree search</article-title>. <source>OSF</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.31219/osf.io/cjyvb</pub-id>.</mixed-citation></ref>
<ref id="ref-259"><label>[259]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Olabim</surname> <given-names>M</given-names></string-name>, <string-name><surname>Greenfield</surname> <given-names>A</given-names></string-name>, <string-name><surname>Barlow</surname> <given-names>A</given-names></string-name></person-group>. <article-title>A differential privacy-based approach for mitigating data theft in ransomware attacks</article-title>. <source>Preprints</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.22541/au.172625434.48862692/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-260"><label>[260]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hagerty</surname> <given-names>S</given-names></string-name>, <string-name><surname>Huxley</surname> <given-names>D</given-names></string-name>, <string-name><surname>Fiennes</surname> <given-names>A</given-names></string-name>, <string-name><surname>Hartwell</surname> <given-names>L</given-names></string-name>, <string-name><surname>Pembroke</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Ransomware detection using network traffic patterns: a hybrid approach with isolation forest and gradient boosting</article-title>. <source>Res Sq</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.21203/rs.3.rs-5297735/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-261"><label>[261]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Pavica</surname> <given-names>C</given-names></string-name>, <string-name><surname>Swanson</surname> <given-names>G</given-names></string-name>, <string-name><surname>Whitaker</surname> <given-names>R</given-names></string-name>, <string-name><surname>Johansson</surname> <given-names>S</given-names></string-name></person-group>. <article-title>A feedback controlled optimization approach to minimize ransomware propagation in internet of things networks</article-title>. <source>Preprints</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.31219/osf.io/8qkva</pub-id>.</mixed-citation></ref>
<ref id="ref-262"><label>[262]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Argene</surname> <given-names>M</given-names></string-name>, <string-name><surname>Ravenscroft</surname> <given-names>C</given-names></string-name>, <string-name><surname>Kingswell</surname> <given-names>I</given-names></string-name></person-group>. <article-title>Ransomware detection via cosine similarity-based machine learning on bytecode representations</article-title>. <source>Preprints</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.22541/au.172348750.00074165/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-263"><label>[263]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ozturk</surname> <given-names>M</given-names></string-name>, <string-name><surname>Demir</surname> <given-names>A</given-names></string-name>, <string-name><surname>Arslan</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Caliskan</surname> <given-names>O</given-names></string-name></person-group>. <article-title>Dynamic behavioural analysis of privacy-breaching and data theft ransomware</article-title>. <source>Res Sq</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.21203/rs.3.rs-4097219/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-264"><label>[264]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>LaRocque</surname> <given-names>A</given-names></string-name>, <string-name><surname>Gross</surname> <given-names>G</given-names></string-name>, <string-name><surname>Lindholm</surname> <given-names>F</given-names></string-name>, <string-name><surname>Greco</surname> <given-names>P</given-names></string-name>, <string-name><surname>Dupont</surname> <given-names>B</given-names></string-name>, <string-name><surname>Kruger</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Effective ransomware detection using autonomous patternbased signature extraction</article-title>. <source>Preprints</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.22541/au.173016272.26231350/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-265"><label>[265]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Koike</surname> <given-names>S</given-names></string-name>, <string-name><surname>Tanaka</surname> <given-names>H</given-names></string-name>, <string-name><surname>Maeda</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Federated learning-based ransomware detection via indicators of compromise</article-title>. <source>Res Sq</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.21203/rs.3.rs-4585988/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-266"><label>[266]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Azugo</surname> <given-names>P</given-names></string-name>, <string-name><surname>Venter</surname> <given-names>H</given-names></string-name>, <string-name><surname>Nkongolo</surname> <given-names>MW</given-names></string-name></person-group>. <article-title>Ransomware detection and classification using random forest: a case study with the UGRansome2024 dataset</article-title>. <comment>arXiv:2404.12855. 2024</comment>.</mixed-citation></ref>
<ref id="ref-267"><label>[267]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Matae</surname> <given-names>T</given-names></string-name>, <string-name><surname>Fentiman</surname> <given-names>K</given-names></string-name>, <string-name><surname>Kingsleigh</surname> <given-names>S</given-names></string-name>, <string-name><surname>Antonovich</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Introducing adaptive sequence embedding for effective ransomware detection</article-title>. <source>Preprints</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.22541/au.173161592.25153018/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-268"><label>[268]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wasoye</surname> <given-names>S</given-names></string-name>, <string-name><surname>Stevens</surname> <given-names>M</given-names></string-name>, <string-name><surname>Morgan</surname> <given-names>C</given-names></string-name>, <string-name><surname>Hughes</surname> <given-names>D</given-names></string-name>, <string-name><surname>Walker</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Ransomware classification using BTLS algorithm and machine learning approaches</article-title>. <source>Res Sq</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.21203/rs.3.rs-5131919/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-269"><label>[269]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Jabid</surname> <given-names>T</given-names></string-name>, <string-name><surname>Masum</surname> <given-names>S</given-names></string-name>, <string-name><surname>Shams</surname> <given-names>RA</given-names></string-name>, <string-name><surname>Chowdhury</surname> <given-names>A</given-names></string-name>, <string-name><surname>Islam</surname> <given-names>MM</given-names></string-name>, <string-name><surname>Ferdaus</surname> <given-names>MH</given-names></string-name>, <etal>et al</etal></person-group>. <chapter-title>A brief history of ransomware</chapter-title>. In: <source>Ransomware evolution</source>. <publisher-loc>Boca Raton, FL, USA</publisher-loc>: <publisher-name>CRC Press</publisher-name>; <year>2024</year>. p. <fpage>3</fpage>&#x2013;<lpage>17</lpage>.</mixed-citation></ref>
<ref id="ref-270"><label>[270]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Long</surname> <given-names>J</given-names></string-name>, <string-name><surname>Liang</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Ranaway: a novel ransomware-resilient refs file system</article-title>. <source>Res Sq</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.21203/rs.3.rs-3960276/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-271"><label>[271]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Gihavo</surname> <given-names>D</given-names></string-name>, <string-name><surname>Ivanovich</surname> <given-names>O</given-names></string-name>, <string-name><surname>Harrison</surname> <given-names>A</given-names></string-name>, <string-name><surname>Merritt</surname> <given-names>L</given-names></string-name>, <string-name><surname>Schneider</surname> <given-names>V</given-names></string-name></person-group>. <article-title>Automated file trap selection using machine learning for early detection of ransomware attacks</article-title>. <source>TechRxiv</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.36227/techrxiv.172840476.68122495/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-272"><label>[272]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Guo</surname> <given-names>J</given-names></string-name>, <string-name><surname>Liang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Long</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Leveraging file system characteristics for ransomware mitigation in linux operating system environments</article-title>. <source>Res Sq</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.21203/rs.3.rs-4308346/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-273"><label>[273]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Williams</surname> <given-names>M</given-names></string-name>, <string-name><surname>Morales</surname> <given-names>R</given-names></string-name>, <string-name><surname>Johnson</surname> <given-names>K</given-names></string-name>, <string-name><surname>Martinez</surname> <given-names>G</given-names></string-name>, <string-name><surname>Bennett</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Entropy-based network traffic analysis for efficient ransomware detection</article-title>. <source>TechRxiv</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.36227/techrxiv.172840776.66718131/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-274"><label>[274]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Chang</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Ransomware detection on linux using machine learning with random forest algorithm</article-title>. <source>TechRxiv</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.36227/techrxiv.171778770.06550236/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-275"><label>[275]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Gupret</surname> <given-names>E</given-names></string-name>, <string-name><surname>Turner</surname> <given-names>A</given-names></string-name>, <string-name><surname>Evans</surname> <given-names>C</given-names></string-name>, <string-name><surname>Morgan</surname> <given-names>R</given-names></string-name>, <string-name><surname>Richardson</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Dual-layer ransomware classification using opcode and network traffic similarity</article-title>. <source>Preprints</source>. <year>2024</year>. doi:<pub-id pub-id-type="doi">10.22541/au.172719839.91919526/v1</pub-id>.</mixed-citation></ref>
<ref id="ref-276"><label>[276]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Schuetz</surname> <given-names>SW</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Forderer</surname> <given-names>J</given-names></string-name>, <string-name><surname>Ma</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Does ransomware make investors &#x201C;WannaCry?&#x201D; on investors&#x2019; divergent reactions to ransomware hits and near misses</article-title>. <source>MIS Q</source>. <year>2025</year>;<volume>49</volume>(<issue>3</issue>):<fpage>1153</fpage>&#x2013;<lpage>68</lpage>. doi:<pub-id pub-id-type="doi">10.25300/misq/2024/18509</pub-id>.</mixed-citation></ref>
</ref-list>
</back></article>