{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,3]],"date-time":"2026-04-03T15:49:20Z","timestamp":1775231360848,"version":"3.50.1"},"publisher-location":"Singapore","reference-count":30,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819691005","type":"print"},{"value":"9789819691012","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-981-96-9101-2_21","type":"book-chapter","created":{"date-parts":[[2025,7,10]],"date-time":"2025-07-10T09:48:37Z","timestamp":1752140917000},"page":"399-414","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Ransomware Encryption Detection: Adaptive File System Analysis Against Evasive Encryption Tactics"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0487-0615","authenticated-orcid":false,"given":"Arash","family":"Mahboubi","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9285-9917","authenticated-orcid":false,"given":"Hamed","family":"Aboutorab","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6353-8359","authenticated-orcid":false,"given":"Seyit","family":"Camtepe","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6851-7717","authenticated-orcid":false,"given":"Hang Thanh","family":"Bui","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6981-7367","authenticated-orcid":false,"given":"Khanh","family":"Luong","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9969-7682","authenticated-orcid":false,"given":"Keyvan","family":"Ansari","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0009-4057","authenticated-orcid":false,"given":"Shenlu","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bazara","family":"Barry","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,7,7]]},"reference":[{"key":"21_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"240","DOI":"10.1007\/978-3-030-88418-5_12","volume-title":"Computer Security \u2013 ESORICS 2021","author":"ME Ahmed","year":"2021","unstructured":"Ahmed, M.E., Kim, H., Camtepe, S., Nepal, S.: Peeler: profiling kernel-level events to detect ransomware. In: Bertino, E., Shulman, H., Waidner, M. (eds.) ESORICS 2021. LNCS, vol. 12972, pp. 240\u2013260. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-88418-5_12"},{"key":"21_CR2","doi-asserted-by":"crossref","unstructured":"Alam, M., Bhattacharya, S., Dutta, S., Sinha, S., Mukhopadhyay, D., Chattopadhyay, A.: RATAFIA: ransomware analysis using time and frequency informed autoencoders. In: 2019 IEEE International Symposium on Hardware Oriented Security and Trust (HOST), pp. 218\u2013227. IEEE (2019)","DOI":"10.1109\/HST.2019.8740837"},{"key":"21_CR3","doi-asserted-by":"crossref","unstructured":"Alzubi, J., Nayyar, A., Kumar, A.: Machine learning from theory to algorithms: an overview. In: Journal of Physics: Conference Series, vol.\u00a01142, p. 012012. IOP Publishing (2018)","DOI":"10.1088\/1742-6596\/1142\/1\/012012"},{"key":"21_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"382","DOI":"10.1007\/978-3-319-26362-5_18","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"N Andronio","year":"2015","unstructured":"Andronio, N., Zanero, S., Maggi, F.: HelDroid: dissecting and detecting mobile ransomware. In: Bos, H., Monrose, F., Blanc, G. (eds.) RAID 2015. LNCS, vol. 9404, pp. 382\u2013404. Springer, Cham (2015). https:\/\/doi.org\/10.1007\/978-3-319-26362-5_18"},{"key":"21_CR5","doi-asserted-by":"publisher","first-page":"e361","DOI":"10.7717\/peerj-cs.361","volume":"7","author":"S Aurangzeb","year":"2021","unstructured":"Aurangzeb, S., Rais, R., Aleem, M., Islam, M.A., Iqbal, M.A.: On the classification of Microsoft-windows ransomware using hardware profile. PeerJ Comput. Sci. 7, e361 (2021)","journal-title":"PeerJ Comput. Sci."},{"key":"21_CR6","doi-asserted-by":"crossref","unstructured":"Beyazit, E., Alagurajah, J., Wu, X.: Online learning from data streams with varying feature spaces. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a033, pp. 3232\u20133239 (2019)","DOI":"10.1609\/aaai.v33i01.33013232"},{"issue":"11","key":"21_CR7","first-page":"201","volume":"91","author":"K Cabaj","year":"2015","unstructured":"Cabaj, K., Gawkowski, P., Grochowski, K., Osojca, D.: Network activity analysis of cryptowall ransomware. Przeglad Elektrotech. 91(11), 201\u2013204 (2015)","journal-title":"Przeglad Elektrotech."},{"key":"21_CR8","unstructured":"Constantin, L.: New royal ransomware group evades detection with partial encryption. CSO (2022). https:\/\/shorturl.at\/9Hg3E"},{"key":"21_CR9","doi-asserted-by":"publisher","unstructured":"Continella, A., et al.: ShieldFS: a self-healing, ransomware-aware filesystem. In: Proceedings of the 32nd Annual Conference on Computer Security Applications, ACSAC 2016, pp. 336\u2013347. Association for Computing Machinery, New York (2016). https:\/\/doi.org\/10.1145\/2991079.2991110","DOI":"10.1145\/2991079.2991110"},{"issue":"2","key":"21_CR10","first-page":"1301","volume":"5","author":"K Das","year":"2017","unstructured":"Das, K., Behera, R.N.: A survey on machine learning: concept, algorithms and applications. Int. J. Innov. Res. Comput. Commun. Eng. 5(2), 1301\u20131309 (2017)","journal-title":"Int. J. Innov. Res. Comput. Commun. Eng."},{"key":"21_CR11","doi-asserted-by":"publisher","first-page":"136666","DOI":"10.1109\/ACCESS.2024.3461965","volume":"12","author":"J Ferdous","year":"2024","unstructured":"Ferdous, J., Islam, R., Mahboubi, A., Zahidul Islam, M.: Ai-based ransomware detection: a comprehensive review. IEEE Access 12, 136666\u2013136695 (2024). https:\/\/doi.org\/10.1109\/ACCESS.2024.3461965","journal-title":"IEEE Access"},{"key":"21_CR12","doi-asserted-by":"crossref","unstructured":"Ganfure, G.O., Wu, C.F., Chang, Y.H., Shih, W.K.: DeepGuard: deep generative user-behavior analytics for ransomware detection. In: 2020 IEEE International Conference on Intelligence and Security Informatics (ISI), pp.\u00a01\u20136. IEEE (2020)","DOI":"10.1109\/ISI49825.2020.9280508"},{"key":"21_CR13","doi-asserted-by":"publisher","first-page":"1433","DOI":"10.1109\/TIFS.2023.3240025","volume":"18","author":"GO Ganfure","year":"2023","unstructured":"Ganfure, G.O., Wu, C.F., Chang, Y.H., Shih, W.K.: RTrap: trapping and containing ransomware with machine learning. IEEE Trans. Inf. Forensics Secur. 18, 1433\u20131448 (2023)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"21_CR14","doi-asserted-by":"crossref","unstructured":"G\u00f3mez-Hern\u00e1ndez, J., \u00c1lvarez Gonz\u00e1lez, L., Garc\u00eda-Teodoro, P.: R-locker: thwarting ransomware action through a honeyfile-based approach. Comput. Secur. 73, 389\u2013398 (2018). https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404817302560","DOI":"10.1016\/j.cose.2017.11.019"},{"key":"21_CR15","doi-asserted-by":"publisher","first-page":"249","DOI":"10.1016\/j.neucom.2021.04.112","volume":"459","author":"SC Hoi","year":"2021","unstructured":"Hoi, S.C., Sahoo, D., Lu, J., Zhao, P.: Online learning: a comprehensive survey. Neurocomputing 459, 249\u2013289 (2021)","journal-title":"Neurocomputing"},{"key":"21_CR16","doi-asserted-by":"publisher","first-page":"138345","DOI":"10.1109\/ACCESS.2021.3114148","volume":"9","author":"CM Hsu","year":"2021","unstructured":"Hsu, C.M., Yang, C.C., Cheng, H.H., Setiasabda, P.E., Leu, J.S.: Enhancing file entropy analysis to improve machine learning detection rate of ransomware. IEEE Access 9, 138345\u2013138351 (2021)","journal-title":"IEEE Access"},{"key":"21_CR17","unstructured":"Kharaz, A., Arshad, S., Mulliner, C., Robertson, W., Kirda, E.: $$\\{$$UNVEIL$$\\}$$: a $$\\{$$large-scale$$\\}$$, automated approach to detecting ransomware. In: 25th USENIX security symposium (USENIX Security 16), pp. 757\u2013772 (2016)"},{"key":"21_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"98","DOI":"10.1007\/978-3-319-66332-6_5","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"A Kharraz","year":"2017","unstructured":"Kharraz, A., Kirda, E.: Redemption: real-time protection against ransomware at end-hosts. In: Dacier, M., Bailey, M., Polychronakis, M., Antonakakis, M. (eds.) RAID 2017. LNCS, vol. 10453, pp. 98\u2013119. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-66332-6_5"},{"key":"21_CR19","doi-asserted-by":"crossref","unstructured":"Lee, J., Lee, J., Hong, J.: How to make efficient decoy files for ransomware detection? In: Proceedings of the International Conference on Research in Adaptive and Convergent Systems, pp. 208\u2013212 (2017)","DOI":"10.1145\/3129676.3129713"},{"key":"21_CR20","doi-asserted-by":"publisher","first-page":"110205","DOI":"10.1109\/ACCESS.2019.2931136","volume":"7","author":"K Lee","year":"2019","unstructured":"Lee, K., Lee, S.Y., Yim, K.: Machine learning based file entropy analysis for ransomware detection in backup systems. IEEE Access 7, 110205\u2013110215 (2019)","journal-title":"IEEE Access"},{"issue":"1","key":"21_CR21","doi-asserted-by":"publisher","first-page":"186","DOI":"10.1109\/TNNLS.2021.3091681","volume":"34","author":"S Liu","year":"2021","unstructured":"Liu, S., et al.: Online active learning for drifting data streams. IEEE Trans. Neural Netw. Learn. Syst. 34(1), 186\u2013200 (2021)","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"21_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"57","DOI":"10.1007\/978-3-030-67550-9_5","volume-title":"Mobile, Secure, and Programmable Networking","author":"A Mahboubi","year":"2021","unstructured":"Mahboubi, A., Ansari, K., Camtepe, S.: Using process mining to identify file system metrics impacted by ransomware execution. In: Bouzefrane, S., Laurent, M., Boumerdassi, S., Renault, E. (eds.) MSPN 2020. LNCS, vol. 12605, pp. 57\u201371. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-67550-9_5"},{"key":"21_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"213","DOI":"10.1007\/978-981-97-7737-2_12","volume-title":"Advances in Information and Computer Security","author":"A Mahboubi","year":"2024","unstructured":"Mahboubi, A., Camtepe, S., Ansari, K., Paw\u0142owski, M., Morawiecki, P., Duda, J., Pieprzyk, J.: File system shield (FSS): a pass-through strategy against unwanted encryption in network file systems. In: Minematsu, K., Mimura, M. (eds.) IWSEC 2024. LNCS, vol. 14977, pp. 213\u2013233. Springer, Singapore (2024). https:\/\/doi.org\/10.1007\/978-981-97-7737-2_12"},{"key":"21_CR24","first-page":"103873","volume":"86","author":"A Mahboubi","year":"2024","unstructured":"Mahboubi, A., et al.: Shared file protection against unauthorised encryption using a buffer-based signature verification method. J. Inf. Secur. Appl. 86, 103873 (2024)","journal-title":"J. Inf. Secur. Appl."},{"key":"21_CR25","doi-asserted-by":"crossref","unstructured":"Mahboubi, A., Camtepe, S., Morarji, H.: Reducing USB attack surface: a lightweight authentication and delegation protocol. In: 2018 International Conference on Smart Computing and Electronic Enterprise (ICSCEE), pp.\u00a01\u20137 (2018)","DOI":"10.1109\/ICSCEE.2018.8538400"},{"key":"21_CR26","series-title":"Communications in Computer and Information Science","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1007\/978-3-030-36802-9_20","volume-title":"Neural Information Processing","author":"T McIntosh","year":"2019","unstructured":"McIntosh, T., Jang-Jaccard, J., Watters, P., Susnjak, T.: The inadequacy of entropy-based ransomware detection. In: Gedeon, T., Wong, K.W., Lee, M. (eds.) ICONIP 2019. CCIS, vol. 1143, pp. 181\u2013189. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-36802-9_20"},{"key":"21_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"114","DOI":"10.1007\/978-3-030-00470-5_6","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"S Mehnaz","year":"2018","unstructured":"Mehnaz, S., Mudgerikar, A., Bertino, E.: RWGuard: a real-time detection system against cryptographic ransomware. In: Bailey, M., Holz, T., Stamatogiannakis, M., Ioannidis, S. (eds.) RAID 2018. LNCS, vol. 11050, pp. 114\u2013136. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-00470-5_6"},{"key":"21_CR28","unstructured":"Oz, H., Aris, A., Acar, A., Tuncay, G.S., Babun, L., Uluagac, S.: R\u00f8B: ransomware over modern web browsers. In: 32nd USENIX Security Symposium (USENIX Security 2023), pp. 7073\u20137090. USENIX Association, Anaheim (2023)"},{"key":"21_CR29","unstructured":"Palmer, D.: Ransomware is the biggest global cyber threat and the attacks are still evolving (2022). https:\/\/shorturl.at\/xPwTy. zDNet"},{"key":"21_CR30","doi-asserted-by":"crossref","unstructured":"Song, S., Kim, B., Lee, S., et\u00a0al.: The effective ransomware prevention technique using process monitoring on android platform. Mob. Inf. Syst. 2016 (2016)","DOI":"10.1155\/2016\/2946735"}],"container-title":["Lecture Notes in Computer Science","Information Security and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-96-9101-2_21","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,3]],"date-time":"2026-04-03T14:56:26Z","timestamp":1775228186000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-96-9101-2_21"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9789819691005","9789819691012"],"references-count":30,"URL":"https:\/\/doi.org\/10.1007\/978-981-96-9101-2_21","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"7 July 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ACISP","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Australasian Conference on Information Security and Privacy","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Wollongong, NSW","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Australia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 July 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 July 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"acisp2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/uow-ic2.github.io\/acisp2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}