Abstract
This study presents a machine learning-based approach for ransomware detection through the header feature of executable files. A dataset was constructed consisting of 2,497 samples, including 962 benign files and 1,535 ransomware samples belonging to 19 active families identified since 2020. The samples were collected from specialized sources and processed within a controlled virtual environment, ensuring safe conditions throughout the analysis. Various internal features were extracted from the samples and subsequently subjected to preparation, cleaning, and balancing procedures to ensure proper interpretation by the predictive models. Four widely used classification algorithms were trained: LightGBM, XGBoost, Random Forest, and MLP. After hyperparameter tuning and stratified cross-validation, each model's performance was evaluated using standard metrics such as precision, recall, and F1-score. The results showed outstanding performance from Random Forest and XGBoost, both achieving an F1-score close to 97.68%, followed closely by LightGBM. The MLP model yielded slightly lower, yet acceptable, performance. These findings confirm that static analysis, combined with machine learning techniques, is an effective alternative for detecting ransomware, enabling the accurate identification of malicious files without executing them.
Author supplied keywords
Cite
CITATION STYLE
Monsalve Obregon, V. A., Rios Diaz, J. P., & Torres Paredes, C. M. (2025). Ransomware Detection Using Executable Header Features and Machine Learning Techniques. In Proceedings of 8th International Conference on Systems Engineering - Cybersecurity and AI: Building a reliable digital future, CIIS 2025 (pp. 87–97). Association for Computing Machinery, Inc. https://doi.org/10.1145/3771678.3771690
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.