{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,24]],"date-time":"2026-04-24T19:35:04Z","timestamp":1777059304662,"version":"3.51.4"},"publisher-location":"Singapore","reference-count":28,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819562084","type":"print"},{"value":"9789819562091","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-95-6209-1_20","type":"book-chapter","created":{"date-parts":[[2026,1,2]],"date-time":"2026-01-02T02:26:52Z","timestamp":1767320812000},"page":"369-383","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["FuzzyHawk: Unveiling Ransomware Behavior Patterns via\u00a0Graph-Based Fuzzy Matching"],"prefix":"10.1007","author":[{"given":"Lingbo","family":"Zhao","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuhui","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rui","family":"Hou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,1,2]]},"reference":[{"key":"20_CR1","doi-asserted-by":"crossref","unstructured":"Baek, S., Jung, Y., Mohaisen, A., Lee, S., Nyang, D.: SSD-insider: internal defense of solid-state drive against ransomware with perfect data recovery. In: 2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS), pp. 875\u2013884 (2018). https:\/\/api.semanticscholar.org\/CorpusID:50775506","DOI":"10.1109\/ICDCS.2018.00089"},{"issue":"10","key":"20_CR2","doi-asserted-by":"publisher","first-page":"1762","DOI":"10.1109\/TC.2020.3011214","volume":"70","author":"S Baek","year":"2021","unstructured":"Baek, S., Jung, Y., Mohaisen, D., Lee, S., Nyang, D.: SSD-assisted ransomware detection and data recovery techniques. IEEE Trans. Comput. 70(10), 1762\u20131776 (2021). https:\/\/doi.org\/10.1109\/TC.2020.3011214","journal-title":"IEEE Trans. Comput."},{"key":"20_CR3","unstructured":"Behal, S., Brar, A.S., Kumar, K.: Signature-based botnet detection and prevention. In: Proceedings of International Symposium on Computer Engineering and Technology, pp. 127\u2013132 (2010)"},{"key":"20_CR4","unstructured":"Brengel, M., Rossow, C.: Yarix: Scalable Yara-based malware intelligence. In: USENIX Security Symposium (2021). https:\/\/api.semanticscholar.org\/CorpusID:232096243"},{"key":"20_CR5","doi-asserted-by":"publisher","first-page":"353","DOI":"10.1016\/j.compeleceng.2017.10.012","volume":"66","author":"K Cabaj","year":"2018","unstructured":"Cabaj, K., Gregorczyk, M., Mazurczyk, W.: Software-defined networking-based crypto ransomware detection using http traffic characteristics. Comput. Electr. Eng. 66, 353\u2013368 (2018)","journal-title":"Comput. Electr. Eng."},{"key":"20_CR6","doi-asserted-by":"publisher","unstructured":"Chen, Z.G., Kang, H.S., Yin, S.N., Kim, S.R.: Automatic ransomware detection and analysis based on dynamic API calls flow graph. In: Proceedings of the International Conference on Research in Adaptive and Convergent Systems, pp. 196\u2013201. RACS \u201917, Association for Computing Machinery, New York, NY, USA (2017). https:\/\/doi.org\/10.1145\/3129676.3129704","DOI":"10.1145\/3129676.3129704"},{"key":"20_CR7","doi-asserted-by":"publisher","unstructured":"Continella, A., et al.: ShieldFS: a self-healing, ransomware-aware filesystem. In: ACSAC, pp. 336\u2013347. ACM SIGCOMM (2016). https:\/\/doi.org\/10.1145\/2991079.2991110","DOI":"10.1145\/2991079.2991110"},{"key":"20_CR8","doi-asserted-by":"crossref","unstructured":"Cusack, G., Michel, O., Keller, E.: Machine learning-based detection of ransomware using SDN. In: Proceedings of the 2018 ACM International Workshop on Security in Software Defined Networks & Network Function Virtualization, pp.\u00a01\u20136 (2018)","DOI":"10.1145\/3180465.3180467"},{"key":"20_CR9","doi-asserted-by":"publisher","first-page":"111830","DOI":"10.1109\/ACCESS.2022.3215267","volume":"10","author":"Y Gao","year":"2022","unstructured":"Gao, Y., Hasegawa, H., Yamaguchi, Y., Shimada, H.: Malware detection by control-flow graph level representation learning with graph isomorphism network. IEEE Access 10, 111830\u2013111841 (2022)","journal-title":"IEEE Access"},{"key":"20_CR10","doi-asserted-by":"crossref","unstructured":"Kirda, E.: Unveil: a large-scale, automated approach to detecting ransomware (keynote). In: IEEE International Conference on Software Analysis, Evolution, and Reengineering (2016). https:\/\/api.semanticscholar.org\/CorpusID:14678747","DOI":"10.1109\/SANER.2017.7884603"},{"key":"20_CR11","doi-asserted-by":"crossref","unstructured":"Kolodenker, E., Koch, W., Stringhini, G., Egele, M.: Paybreak: defense against cryptographic ransomware. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security (2017). https:\/\/api.semanticscholar.org\/CorpusID:16620710","DOI":"10.1145\/3052973.3053035"},{"key":"20_CR12","unstructured":"MalwareBazaar: Malwarebazaar (2023). https:\/\/bazaar.abuse.ch\/"},{"key":"20_CR13","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1007\/978-3-030-36802-9_20","volume-title":"Neural Information Processing","author":"T McIntosh","year":"2019","unstructured":"McIntosh, T., Jang-Jaccard, J., Watters, P., Susnjak, T.: The inadequacy of entropy-based ransomware detection. In: Gedeon, T., Wong, K.W., Lee, M. (eds.) Neural Information Processing, pp. 181\u2013189. Springer, Cham (2019)"},{"key":"20_CR14","doi-asserted-by":"publisher","first-page":"114","DOI":"10.1007\/978-3-030-00470-5_6","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"S Mehnaz","year":"2018","unstructured":"Mehnaz, S., Mudgerikar, A., Bertino, E.: RWGuard: a real-time detection system against cryptographic ransomware. In: Bailey, M., Holz, T., Stamatogiannakis, M., Ioannidis, S. (eds.) Research in Attacks, Intrusions, and Defenses, pp. 114\u2013136. Springer, Cham (2018)"},{"key":"20_CR15","doi-asserted-by":"crossref","unstructured":"Popli, N.K., Girdhar, A.: Behavioural analysis of recent ransomwares and prediction of future attacks by polymorphic and metamorphic ransomware. In: Computational Intelligence: Theories, Applications and Future Directions-Volume II: ICCI-2017, pp. 65\u201380. Springer (2019)","DOI":"10.1007\/978-981-13-1135-2_6"},{"key":"20_CR16","doi-asserted-by":"crossref","unstructured":"Reidys, B., Liu, P., Huang, J.: RSSD: defend against ransomware with hardware-isolated network-storage codesign and post-attack analysis. In: Proceedings of the 27th ACM International Conference on Architectural Support for Programming Languages and Operating Systems (2022). https:\/\/api.semanticscholar.org\/CorpusID:247026945","DOI":"10.1145\/3503222.3507773"},{"issue":"1","key":"20_CR17","doi-asserted-by":"publisher","first-page":"124","DOI":"10.1007\/S10791-025-09651-W","volume":"28","author":"S Satpathy","year":"2025","unstructured":"Satpathy, S., Swain, P.K.: Graph-contrast ransomware detection (GCRD) with advanced feature selection and deep learning. Discov. Comput. 28(1), 124 (2025). https:\/\/doi.org\/10.1007\/S10791-025-09651-W","journal-title":"Discov. Comput."},{"key":"20_CR18","doi-asserted-by":"publisher","first-page":"132306","DOI":"10.1016\/j.physd.2019.132306","volume":"404","author":"A Sherstinsky","year":"2020","unstructured":"Sherstinsky, A.: Fundamentals of recurrent neural network (RNN) and long short-term memory (LSTM) network. Physica D 404, 132306 (2020)","journal-title":"Physica D"},{"key":"20_CR19","doi-asserted-by":"publisher","first-page":"101997","DOI":"10.1016\/j.cose.2020.101997","volume":"97","author":"F Tang","year":"2020","unstructured":"Tang, F., Ma, B., Li, J., Zhang, F., Su, J., Ma, J.: Ransomspector: an introspection-based approach to detect crypto ransomware. Comput. Secur. 97, 101997 (2020). https:\/\/doi.org\/10.1016\/j.cose.2020.101997","journal-title":"Comput. Secur."},{"key":"20_CR20","unstructured":"Team, T.M.T.I.: 2023 state of ransomware. https:\/\/try.malwarebytes.com\/business-2023-state-of-ransomware\/?utm_source=blog&utm_medium=social &utm_campaign=b2b_ws_state_of_ransomware_2023_169048562376. Accessed 20 March 2025"},{"key":"20_CR21","doi-asserted-by":"publisher","unstructured":"Tsunewaki, K., Kimura, T., Cheng, J.: LSTM-based ransomware detection using API call information. In: 2022 IEEE International Conference on Consumer Electronics - Taiwan, pp. 211\u2013212 (2022). https:\/\/doi.org\/10.1109\/ICCE-Taiwan55306.2022.9869122","DOI":"10.1109\/ICCE-Taiwan55306.2022.9869122"},{"key":"20_CR22","doi-asserted-by":"crossref","unstructured":"Urooj, U., Al-rimy, B.A.S., Zainal, A., Ghaleb, F.A., Rassam, M.A.: Ransomware detection using the dynamic analysis and machine learning: A survey and research directions. Appl. Sci. 12(1) (2022). https:\/\/www.mdpi.com\/2076-3417\/12\/1\/172","DOI":"10.3390\/app12010172"},{"key":"20_CR23","unstructured":"VirusShare: Virusshare.com - because sharing is caring (2023). https:\/\/virusshare.com\/"},{"key":"20_CR24","doi-asserted-by":"publisher","unstructured":"Wang, S., Dong, F., Yang, H., Xu, J., Wang, H.: Cancal: towards real-time and lightweight ransomware detection and response in industrial environments. In: Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, pp. 2326\u20132340. CCS \u201924, Association for Computing Machinery, New York, NY, USA (2024). https:\/\/doi.org\/10.1145\/3658644.3690269","DOI":"10.1145\/3658644.3690269"},{"key":"20_CR25","doi-asserted-by":"crossref","unstructured":"Xia, Y., Liu, Y., Chen, H., Zang, B.: CFIMon: detecting violation of control flow integrity using performance counters. In: IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN 2012), pp. 1\u201312 (2012)","DOI":"10.1109\/DSN.2012.6263958"},{"issue":"4","key":"20_CR26","doi-asserted-by":"publisher","first-page":"171","DOI":"10.1145\/1402946.1402979","volume":"38","author":"Y Xie","year":"2008","unstructured":"Xie, Y., Yu, F., Achan, K., Panigrahy, R., Hulten, G., Osipkov, I.: Spamming botnets: signatures and characteristics. ACM SIGCOMM Comput. Commun. Rev. 38(4), 171\u2013182 (2008)","journal-title":"ACM SIGCOMM Comput. Commun. Rev."},{"key":"20_CR27","doi-asserted-by":"publisher","first-page":"6113","DOI":"10.1109\/TIFS.2024.3410511","volume":"19","author":"H Zhang","year":"2024","unstructured":"Zhang, H., Zhao, L., Yu, A., Cai, L., Meng, D.: Ranker: early ransomware detection through kernel-level behavioral analysis. IEEE Trans. Inf. Forensics Secur. 19, 6113\u20136127 (2024). https:\/\/doi.org\/10.1109\/TIFS.2024.3410511","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"20_CR28","doi-asserted-by":"publisher","unstructured":"Zhou, C., et al.: Limits of i\/o based ransomware detection: an imitation based attack. In: 2023 IEEE Symposium on Security and Privacy (SP), pp. 2584\u20132601 (2023). https:\/\/doi.org\/10.1109\/SP46215.2023.10179372","DOI":"10.1109\/SP46215.2023.10179372"}],"container-title":["Lecture Notes in Computer Science","Information Security and Cryptology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-95-6209-1_20","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,11]],"date-time":"2026-03-11T17:46:31Z","timestamp":1773251191000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-95-6209-1_20"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9789819562084","9789819562091"],"references-count":28,"URL":"https:\/\/doi.org\/10.1007\/978-981-95-6209-1_20","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"2 January 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors declare no conflicts of interest related to this study.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"Inscrypt","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Information Security and Cryptology","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Xi'an","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 October 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 October 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"cisc22025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/inscrypt2025.xidian.edu.cn\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}