Early Ransomware Detection using Behavioral Analytics in Enterprise Networks

  • . M
  • Dalal S
N/ACitations
Citations of this article
9Readers
Mendeley users who have this article in their library.

Abstract

Ransomware is one of the greatest and fastest-changing risks to enterprise networks across the global scene. Conventional signature-based security software is becoming less effective in terms of combating growing ransomware variants, which use polymorphism, obfuscation, and fileless execution. Behavioral analytics is a stronger solution because it detects the abnormal behaviors of the system calls of user activity, file transactions, and behavior of the processes. This paper develops a multi-layered and behavior-driven ransomware detection model, which applies to an ensemble of machine learning models, including Isolation Forest, Autoencoders, and a Long Short-Term Memory (LSTM) network, to detect ransomware during its early execution phases. The model tracks such significant indicators of behavior like spikes in file entropy, unusual file access logs, intensive I/O operation and privilege escalation. As the experimental results prove, the proposed model is very accurate and is able to discover zero-day variants of ransomware in a matter of seconds, thus reducing the threat to enterprise systems greatly.

Cite

CITATION STYLE

APA

. M., & Dalal, S. (2025). Early Ransomware Detection using Behavioral Analytics in Enterprise Networks. International Journal of Innovative Research in Engineering and Management, 12(6), 65–72. https://doi.org/10.55524/ijirem.2025.12.6.12

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free