{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,14]],"date-time":"2025-10-14T00:17:16Z","timestamp":1760401036340,"version":"build-2065373602"},"publisher-location":"Cham","reference-count":52,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031962301"},{"type":"electronic","value":"9783031962318"}],"license":[{"start":{"date-parts":[[2025,6,22]],"date-time":"2025-06-22T00:00:00Z","timestamp":1750550400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,6,22]],"date-time":"2025-06-22T00:00:00Z","timestamp":1750550400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-031-96231-8_5","type":"book-chapter","created":{"date-parts":[[2025,6,21]],"date-time":"2025-06-21T01:56:31Z","timestamp":1750470991000},"page":"57-73","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Enhancing Ransomware Detection Using Storage Access Pattern"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-6937-640X","authenticated-orcid":false,"given":"Amjad","family":"Alraizza","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7556-958X","authenticated-orcid":false,"given":"Abdulmohsen","family":"Algarni","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7276-3195","authenticated-orcid":false,"given":"Asmaa","family":"Alrayzah","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,6,22]]},"reference":[{"key":"5_CR1","doi-asserted-by":"crossref","unstructured":"Malik, V., Khanna, A., Sharma, N., et\u00a0al., Trends in ransomware attacks: analysis and future predictions. IJGIS (2024)","DOI":"10.21428\/e90189c8.f2996624"},{"issue":"3","key":"5_CR2","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1365\/s43439-023-00095-w","volume":"4","author":"F Teichmann","year":"2023","unstructured":"Teichmann, F., Boticiu, S.R., Sergi, B.S.: The evolution of ransomware attacks in light of recent cyber threats. How can geopolitical conflicts influence the cyber climate? Int. Cybersecur. Law Rev. 4(3), 259\u2013280 (2023)","journal-title":"Int. Cybersecur. Law Rev."},{"key":"5_CR3","doi-asserted-by":"crossref","unstructured":"Basha, C.B., et al.: Understanding and mitigating ransomware threats: Trends, techniques, and countermeasures in the digital age, In: ICTEASD, pp. 383\u2013387. IEEE (2023)","DOI":"10.1109\/ICTEASD57136.2023.10585140"},{"key":"5_CR4","doi-asserted-by":"crossref","unstructured":"Biondi, F., Given-Wilson, T., Legay, A., Puodzius, C., Quilbeuf, J.: Tutorial: an overview of malware detection and evasion techniques, pp. 565\u2013586 (2018)","DOI":"10.1007\/978-3-030-03418-4_34"},{"key":"5_CR5","doi-asserted-by":"crossref","unstructured":"Andronache, M.M., Vulpe, A. Burileanu, C.: A malware study using static and dynamic analysis, pp. 1\u20136 (2024)","DOI":"10.1109\/COMM62355.2024.10741424"},{"key":"5_CR6","unstructured":"Niraj, S.P., Tiwari, A.K.: Performance analysis of signature based and behavior based malware detection (2022)"},{"key":"5_CR7","unstructured":"Chaikovskyi, M., Chaikovska, I., Sochor, T., Martyniuk, I., Lyhun, O.: Comprehensive approach to the detection and analysis of polymorphic malware, vol. 3736, pp. 312\u2013323 (2024)"},{"key":"5_CR8","unstructured":"Zengeni, I.P., fadli Zolkipli, M.: Zero-day exploits and vulnerability management. Borneo Int. J. 7(3), 26\u201333 (2024)"},{"key":"5_CR9","doi-asserted-by":"crossref","unstructured":"Blowing, A., Stanislaw, V., Wagner, R., Ferrari, L., Magomedov, S.: Performing ransomware detection through predictive behavioral mapping to autonomous threat identification (2024)","DOI":"10.31219\/osf.io\/5zu9r"},{"key":"5_CR10","doi-asserted-by":"crossref","unstructured":"Viddiu, O., Macpherson, G., Vasquez, E., Kamenova, I., Calderon, D.: Automated ransomware detection using windows file system activity monitoring and a novel machine learning approach, Authorea Preprints (2024)","DOI":"10.22541\/au.172893987.71304373\/v1"},{"key":"5_CR11","doi-asserted-by":"crossref","unstructured":"Baker, J., Schreiber, P., Meyerstein, O., Lebedev, N., Vandenberg, R.: Hypergraph-driven ransomware detection via anomalous behavior profiling in encrypted network environments, Authorea Preprints (2024)","DOI":"10.36227\/techrxiv.173156099.92422869\/v1"},{"issue":"5","key":"5_CR12","doi-asserted-by":"publisher","first-page":"1446","DOI":"10.3390\/s24051446","volume":"24","author":"J Bang","year":"2024","unstructured":"Bang, J., Kim, J.N., Lee, S.: Entropy sharing in ransomware: bypassing entropy-based detection of cryptographic operations. Sensors 24(5), 1446 (2024)","journal-title":"Sensors"},{"key":"5_CR13","doi-asserted-by":"crossref","unstructured":"Hivola, C., Evesham, J., Wolverstone, G., Baskerville, L., Marchant, A.: Anomaly-based detection of ransomware using virtualized file system entropy analysis (2024)","DOI":"10.21203\/rs.3.rs-5545551\/v1"},{"key":"5_CR14","doi-asserted-by":"crossref","unstructured":"Shiring, B., Stanhope, C., Devito, H., Brigham, R., Tschernov, L.: Adaptive ransomware detection using dynamic encryption pattern analysis, Authorea Preprints (2024)","DOI":"10.36227\/techrxiv.173047783.31909733\/v1"},{"key":"5_CR15","doi-asserted-by":"crossref","unstructured":"Snave, M., Klein, R., Hayes, M., Nielsen, S., Blanchard, T.: Classification of ransomware variants through adaptive pattern recognition in real-time environments (2024)","DOI":"10.21203\/rs.3.rs-5398213\/v1"},{"key":"5_CR16","doi-asserted-by":"publisher","first-page":"109509","DOI":"10.1016\/j.compeleceng.2024.109509","volume":"119","author":"K Ashwini","year":"2024","unstructured":"Ashwini, K., Nagasundara, K.: An intelligent ransomware attack detection and classification using dual vision transformer with mantis search split attention network. Comput. Electr. Eng. 119, 109509 (2024)","journal-title":"Comput. Electr. Eng."},{"key":"5_CR17","doi-asserted-by":"crossref","unstructured":"Brinkley, Y., Thompson, D., Simmons, N.: Machine learning-based intrusion detection for zero-day ransomware in unseen data (2024)","DOI":"10.22541\/au.172685266.62026194\/v1"},{"key":"5_CR18","unstructured":"Idliman, P., Balfour, W., Featheringham, B., Chesterfield, H.: Entropy-synchronized neural hashing for unsupervised ransomware detection. arXiv preprint arXiv:2501.18131 (2025)"},{"issue":"8","key":"5_CR19","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s42979-024-03454-4","volume":"5","author":"N Gurukala","year":"2024","unstructured":"Gurukala, N., Verma, D.K.: Feature selection using particle swarm optimization and ensemble-based machine learning models for ransomware detection. SN Comput. Sci. 5(8), 1\u201318 (2024)","journal-title":"SN Comput. Sci."},{"key":"5_CR20","doi-asserted-by":"publisher","first-page":"103631","DOI":"10.1016\/j.cose.2023.103631","volume":"137","author":"M Wurzenberger","year":"2024","unstructured":"Wurzenberger, M., H\u00f6ld, G., Landauer, M., Skopik, F.: Analysis of statistical properties of variables in log data for advanced anomaly detection in cyber security. Comput. Secur. 137, 103631 (2024)","journal-title":"Comput. Secur."},{"key":"5_CR21","doi-asserted-by":"crossref","unstructured":"Olateju, O., Okon, S.U., Igwenagu, U., Salami, A.A., Oladoyinbo, T.O., Olaniyi, O.O.: Combating the challenges of false positives in ai-driven anomaly detection systems and enhancing data security in the cloud. SSRN 4859958 (2024)","DOI":"10.2139\/ssrn.4859958"},{"key":"5_CR22","first-page":"301314","volume":"40","author":"M Hirano","year":"2022","unstructured":"Hirano, M., Hodota, R., Kobayashi, R.: RanSAP: an open dataset of ransomware storage access patterns for training machine learning models. Forensic Sci. Int. Digital Investig. 40, 301314 (2022)","journal-title":"Forensic Sci. Int. Digital Investig."},{"key":"5_CR23","doi-asserted-by":"crossref","unstructured":"Sharma, P., Chaudhary, K.: An advanced comparative study of ransomware anomaly detection techniques through optimized hyperparameters. In: International Conference on Sustainable and Innovative Solutions for Current Challenges in Engineering & Technology, pp. 379\u2013393. Springer (2023)","DOI":"10.1007\/978-981-97-0327-2_28"},{"issue":"1","key":"5_CR24","doi-asserted-by":"publisher","first-page":"43","DOI":"10.12928\/telkomnika.v20i1.18812","volume":"20","author":"BM Khammas","year":"2022","unstructured":"Khammas, B.M.: Comparative analysis of various machine learning algorithms for ransomware detection. TELKOMNIKA Telecommun. Comput. Electron. Control 20(1), 43\u201351 (2022)","journal-title":"TELKOMNIKA Telecommun. Comput. Electron. Control"},{"issue":"06","key":"5_CR25","doi-asserted-by":"publisher","first-page":"1282","DOI":"10.18535\/ijsrm\/v12i06.ec09","volume":"12","author":"G Nagar","year":"2024","unstructured":"Nagar, G.: The evolution of ransomware: tactics, techniques, and mitigation strategies. IJSRM 12(06), 1282\u20131298 (2024)","journal-title":"IJSRM"},{"key":"5_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-319-20550-2_1","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"A Kharraz","year":"2015","unstructured":"Kharraz, A., Robertson, W., Balzarotti, D., Bilge, L., Kirda, E.: Cutting the Gordian knot: a look under the hood of ransomware attacks. In: Almgren, M., Gulisano, V., Maggi, F. (eds.) DIMVA 2015. LNCS, vol. 9148, pp. 3\u201324. Springer, Cham (2015). https:\/\/doi.org\/10.1007\/978-3-319-20550-2_1"},{"key":"5_CR27","doi-asserted-by":"crossref","unstructured":"Scaife, N., Carter, H., Traynor, P., Butler, K.R.: Cryptolock (and drop it): stopping ransomware attacks on user data. In: 2016 IEEE 36th International Conference on Distributed Computing Systems (ICDCS), pp. 303\u2013312. IEEE (2016)","DOI":"10.1109\/ICDCS.2016.46"},{"key":"5_CR28","doi-asserted-by":"publisher","first-page":"289","DOI":"10.1016\/j.procs.2020.02.249","volume":"168","author":"A Arabo","year":"2020","unstructured":"Arabo, A., Dijoux, R., Poulain, T., Chevalier, G.: Detecting ransomware using process behavior analysis. Procedia Comput. Sci. 168, 289\u2013296 (2020)","journal-title":"Procedia Comput. Sci."},{"key":"5_CR29","doi-asserted-by":"crossref","unstructured":"Akibis, M., Pereira, J., Clark, D., Mitchell, V., Alvarez, H.: Measuring ransomware propagation patterns via network traffic analysis: an automated approach (2024)","DOI":"10.21203\/rs.3.rs-5180048\/v1"},{"key":"5_CR30","doi-asserted-by":"crossref","unstructured":"Kiyol, S., Franchini, D., Moreno, E., Kowalski, R., Fernandez, W., Milosevic, A.: Ransomware detection using LSTM networks and file entropy analysis: a sequence-based approach (2024)","DOI":"10.22541\/au.172841694.49477944\/v1"},{"issue":"1","key":"5_CR31","doi-asserted-by":"publisher","first-page":"1190","DOI":"10.1109\/TNSM.2023.3298533","volume":"21","author":"U Sabeel","year":"2023","unstructured":"Sabeel, U., Heydari, S.S., El-Khatib, K., Elgazzar, K.: Unknown, atypical and polymorphic network intrusion detection: a systematic survey. IEEE Trans. Netw. Serv. Manag. 21(1), 1190\u20131212 (2023)","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"5_CR32","doi-asserted-by":"publisher","first-page":"41255","DOI":"10.1109\/ACCESS.2024.3377658","volume":"12","author":"RA Yunmar","year":"2024","unstructured":"Yunmar, R.A., Kusumawardani, S.S., Mohsen, F., et al.: Hybrid android malware detection: a review of heuristic-based approach. IEEE Access 12, 41255\u201341286 (2024)","journal-title":"IEEE Access"},{"key":"5_CR33","doi-asserted-by":"crossref","unstructured":"Jabid, T., et al.: A brief history of ransomware, pp. 3\u201317. In: Ransomware Evolution. CRC Press (2025)","DOI":"10.1201\/9781003469506-2"},{"key":"5_CR34","doi-asserted-by":"crossref","unstructured":"Gromov, F., Ferreira, J., Lombardi, P., Grigori, S.: Novel approach for enhanced ransomware detection: introducing adaptive pattern signature analysis (2024)","DOI":"10.21203\/rs.3.rs-5414506\/v1"},{"issue":"5","key":"5_CR35","doi-asserted-by":"publisher","first-page":"1687","DOI":"10.1007\/s13198-023-02017-9","volume":"15","author":"KS Sangher","year":"2024","unstructured":"Sangher, K.S., Singh, A., Pandey, H.M.: Signature based ransomware detection based on optimizations approaches using RandomClassifier and CNN algorithms. Int. J. Syst. Assur. Eng. Manag. 15(5), 1687\u20131703 (2024)","journal-title":"Int. J. Syst. Assur. Eng. Manag."},{"issue":"3","key":"5_CR36","doi-asserted-by":"publisher","first-page":"154","DOI":"10.1007\/s42979-021-00535-6","volume":"2","author":"IH Sarker","year":"2021","unstructured":"Sarker, I.H.: Deep cybersecurity: a comprehensive overview from neural network and deep learning perspective. SN Comput. Sci. 2(3), 154 (2021)","journal-title":"SN Comput. Sci."},{"key":"5_CR37","doi-asserted-by":"crossref","unstructured":"Limer, A., Abramovich, R., Devereux, G., Ziemniak, P., Dubois, F.: Automated ransomware detection using dynamic behavior trace profiling, Authorea Preprints (2024)","DOI":"10.36227\/techrxiv.173030558.85237080\/v1"},{"key":"5_CR38","doi-asserted-by":"crossref","unstructured":"Meurs, T., et al.: Ransomware economics: a two-step approach to model ransom paid. In: 2023 APWG Symposium on Electronic Crime Research (eCrime), pp. 1\u201313. IEEE (2023)","DOI":"10.1109\/eCrime61234.2023.10485506"},{"key":"5_CR39","doi-asserted-by":"crossref","unstructured":"Ganguli, P.: The rise of cybercrime-as-a-service: implications and countermeasures. SSRN 4959188 (2024)","DOI":"10.2139\/ssrn.4959188"},{"key":"5_CR40","doi-asserted-by":"publisher","first-page":"119133","DOI":"10.1016\/j.eswa.2022.119133","volume":"214","author":"I Kara","year":"2023","unstructured":"Kara, I.: Fileless malware threats: recent advances, analysis approach through memory forensics and research challenges. Expert Syst. Appl. 214, 119133 (2023)","journal-title":"Expert Syst. Appl."},{"key":"5_CR41","doi-asserted-by":"crossref","unstructured":"Mazunin, E., Bishop, R., Carter, E., Knight, L.: An advanced quantum-entropy based ransomware detection mechanism (2024)","DOI":"10.31219\/osf.io\/6csq7"},{"key":"5_CR42","doi-asserted-by":"crossref","unstructured":"Koyirar, W., Harris, B., Williams, J., Moreno, A., Davis, E.: Efficient ransomware detection through process memory analysis in operating systems. Authorea Preprints (2024)","DOI":"10.22541\/au.172806160.00635511\/v1"},{"issue":"2","key":"5_CR43","doi-asserted-by":"publisher","first-page":"573","DOI":"10.1109\/TDSC.2022.3204535","volume":"21","author":"P S\u00e1nchez","year":"2022","unstructured":"S\u00e1nchez, P., et al.: Studying the robustness of anti-adversarial federated learning models detecting cyberattacks in IoT spectrum sensors. IEEE Trans. Dependable Secur. Comput. 21(2), 573\u2013584 (2022)","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"5_CR44","doi-asserted-by":"crossref","unstructured":"Kang, Q., Gu, Y.: A survey on ransomware threats: contrasting static and dynamic analysis methods (2023)","DOI":"10.20944\/preprints202311.0798.v1"},{"key":"5_CR45","doi-asserted-by":"crossref","unstructured":"Belea, A.R.: Methods for detecting malware using static, dynamic and hybrid analysis. In: Proceedings of the International Conference on Cybersecurity and Cybercrime-2023, Asociatia Romana pentru Asigurarea Securitatii Informatiei, pp. 258\u2013265 (2023)","DOI":"10.19107\/CYBERCON.2023.34"},{"key":"5_CR46","doi-asserted-by":"crossref","unstructured":"Fortino, G., Greco, C., Guzzo, A., Ianni, M.: SigIL: a signature-based approach of malware detection on intermediate language. In: European Symposium on Research in Computer Security, pp. 256\u2013266. Springer (2023)","DOI":"10.1007\/978-3-031-54129-2_15"},{"key":"5_CR47","doi-asserted-by":"crossref","unstructured":"Miranem, V., Petrescu, G., Schelling, D., Vasiliev, A.: Ransomware detection on windows systems using file system activities and a hybrid machine learning approach (2024)","DOI":"10.31219\/osf.io\/27neh"},{"issue":"1","key":"5_CR48","doi-asserted-by":"publisher","first-page":"1554","DOI":"10.1038\/s41598-025-85248-z","volume":"15","author":"N Dash","year":"2025","unstructured":"Dash, N., Chakravarty, S., Rath, A.K., Giri, N.C., AboRas, K.M., Gowtham, N.: An optimized LSTM-based deep learning model for anomaly network intrusion detection. Sci. Rep. 15(1), 1554 (2025)","journal-title":"Sci. Rep."},{"key":"5_CR49","doi-asserted-by":"publisher","first-page":"102691","DOI":"10.1016\/j.cose.2022.102691","volume":"117","author":"J Zhu","year":"2022","unstructured":"Zhu, J., Jang-Jaccard, J., Singh, A., Welch, I., Harith, A.-S., Camtepe, S.: A few-shot meta-learning based Siamese neural network using entropy features for ransomware classification. Comput. Secur. 117, 102691 (2022)","journal-title":"Comput. Secur."},{"issue":"3","key":"5_CR50","first-page":"1","volume":"20","author":"CJW Chew","year":"2024","unstructured":"Chew, C.J.W., Kumar, V., Patros, P., Malik, R.: Real-time system call-based ransomware detection. Int. J. Inf. Secur. 20(3), 1\u201320 (2024)","journal-title":"Int. J. Inf. Secur."},{"key":"5_CR51","doi-asserted-by":"crossref","unstructured":"Loco, P., Alonso, S., Hartmann, G., Whitmore, J., McLaughlin, E.: Adaptive behavior-based ransomware detection via dynamic flow signatures (2024)","DOI":"10.21203\/rs.3.rs-5317374\/v1"},{"key":"5_CR52","doi-asserted-by":"crossref","unstructured":"Denis, J., Featherstone, J., Beaufort, O., Edelstein, H.: A novel algorithmic framework for autonomous ransomware detection using multi-layer temporal anomaly patterns (2024)","DOI":"10.31219\/osf.io\/g7yku"}],"container-title":["IFIP Advances in Information and Communication Technology","Artificial Intelligence Applications and Innovations"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-96231-8_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,13]],"date-time":"2025-10-13T06:23:23Z","timestamp":1760336603000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-96231-8_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,22]]},"ISBN":["9783031962301","9783031962318"],"references-count":52,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-96231-8_5","relation":{},"ISSN":["1868-4238","1868-422X"],"issn-type":[{"type":"print","value":"1868-4238"},{"type":"electronic","value":"1868-422X"}],"subject":[],"published":{"date-parts":[[2025,6,22]]},"assertion":[{"value":"22 June 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"AIAI","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"IFIP International Conference on Artificial Intelligence Applications and Innovations","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Limassol","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Cyprus","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 June 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 June 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"aiai2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/ifipaiai.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}