{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,20]],"date-time":"2026-05-20T02:00:08Z","timestamp":1779242408514,"version":"3.51.4"},"reference-count":32,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T00:00:00Z","timestamp":1750118400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"},{"start":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T00:00:00Z","timestamp":1750118400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Discov Computing"],"DOI":"10.1007\/s10791-025-09651-w","type":"journal-article","created":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T14:57:27Z","timestamp":1750172247000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Graph-contrast ransomware detection (GCRD) with advanced feature selection and deep learning"],"prefix":"10.1007","volume":"28","author":[{"given":"Suneeta","family":"Satpathy","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pratik Kumar","family":"Swain","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,6,17]]},"reference":[{"key":"9651_CR1","doi-asserted-by":"publisher","first-page":"104167","DOI":"10.1016\/j.cose.2024.104167","volume":"148","author":"M Gaber","year":"2025","unstructured":"Gaber M, Ahmed M, Janicke H. Zero-day ransomware detection with a pulse: function classification with transformer models and assembly Language. Comput Secur. 2025;148:104167.","journal-title":"Computers Secur"},{"key":"9651_CR2","doi-asserted-by":"crossref","unstructured":"Hirano M, Kobayashi R. RanSMAP: open dataset of ransomware storage and memory access patterns for creating deep learning-based ransomware detectors. Comput Secur. 2025;150:104202.","DOI":"10.1016\/j.cose.2024.104202"},{"key":"9651_CR3","doi-asserted-by":"crossref","unstructured":"Koyirar W, Harris B, Williams J, Moreno A, Davis E. Efficient ransomware detection through process memory analysis in operating systems. Authorea Preprints; 2024.","DOI":"10.22541\/au.172806160.00635511\/v1"},{"key":"9651_CR4","unstructured":"https:\/\/www.fortinet.com\/resources\/cyberglossary\/ransomware"},{"key":"9651_CR5","doi-asserted-by":"crossref","unstructured":"Lumazine A, Drakos G, Salvatore M, Armand V, Andros B, Castiglione R, Grigorescu E. Ransomware detection in network traffic using a hybrid Cnn and isolation forest approach. 2024.","DOI":"10.22541\/au.172901014.44599790\/v1"},{"issue":"17","key":"9651_CR6","doi-asserted-by":"publisher","first-page":"8482","DOI":"10.3390\/app12178482","volume":"12","author":"FA Aboaoja","year":"2022","unstructured":"Aboaoja FA, Zainal A, Ghaleb FA, Al-Rimy BAS, Eisa TAE, Elnour AA H. Malware detection issues, challenges, and future directions: a survey. Appl Sci. 2022;12(17):8482.","journal-title":"Appl Sci"},{"key":"9651_CR7","doi-asserted-by":"crossref","unstructured":"Masum M, Faruk MJH, Shahriar H, Qian K, Lo D, Adnan MI. Ransomware classification and detection with machine learning algorithms. In 2022 IEEE 12th annual computing and communication workshop and conference (CCWC) (pp. 0316\u20130322). IEEE. 2022.","DOI":"10.1109\/CCWC54503.2022.9720869"},{"key":"9651_CR8","doi-asserted-by":"publisher","first-page":"1141","DOI":"10.1007\/s12652-017-0558-5","volume":"9","author":"A Azmoodeh","year":"2018","unstructured":"Azmoodeh A, Dehghantanha A, Conti M, Choo KKR. Detecting crypto-ransomware in IoT networks based on energy consumption footprint. J Ambient Intell Humaniz Comput. 2018;9:1141\u201352.","journal-title":"J Ambient Intell Humaniz Comput"},{"key":"9651_CR9","unstructured":"Ameer M. Android ransomware detection using machine learning techniques to mitigate adversarial evasion attacks, master\u2019s thesis, capital university of science and technology, Islamabad, Pakistan, 2019."},{"key":"9651_CR10","doi-asserted-by":"publisher","first-page":"325","DOI":"10.1016\/j.icte.2020.11.001","volume":"6","author":"BM Khammas","year":"2020","unstructured":"Khammas BM. Ransomware detection using random forest technique. ICT Express. 2020;6:325\u201331.","journal-title":"ICT Express"},{"key":"9651_CR11","doi-asserted-by":"publisher","first-page":"2597","DOI":"10.1007\/s11277-020-07166-9","volume":"112","author":"J Hwang","year":"2020","unstructured":"Hwang J, Kim J, Lee S, Kim K. Two-stage ransomware detection using dynamic analysis and machine learning techniques. Wirel Pers Commun. 2020;112:2597\u2013609.","journal-title":"Wireless Pers Commun"},{"key":"9651_CR12","doi-asserted-by":"publisher","first-page":"5","DOI":"10.25271\/sjuoz.2022.10.1.865","volume":"10","author":"HS Talabani","year":"2022","unstructured":"Talabani HS, Abdulhadi HMT. Bitcoin ransomware detection employing rule-based algorithms. Sci J Univ Zakho. 2022;10:5\u201310.","journal-title":"Sci J Univ Zakho"},{"key":"9651_CR13","doi-asserted-by":"crossref","unstructured":"Hirano M, Kobayashi R.  Machine Learning-based ransomware detection using low-level memory access patterns obtained from live-forensic hypervisor. In 2022 IEEE International Conference on Cyber Security and Resilience (CSR) (pp. 323\u2013330). IEEE. 2022.","DOI":"10.1109\/CSR54599.2022.9850340"},{"key":"9651_CR14","doi-asserted-by":"crossref","unstructured":"Singh A, Ikuesan RA, Venter H. Ransomware detection using process memory, arXiv preprint arXiv:2203.16871, 2022.","DOI":"10.34190\/iccws.17.1.53"},{"key":"9651_CR15","doi-asserted-by":"crossref","unstructured":"Medhat M, Essa M, Faisal H, Sayed SG. Yaramon: a memory-based detection framework for ransomware families, in Proceedings of the 15th international conference for internet technology and secured transactions (ICITST), 2020.","DOI":"10.23919\/ICITST51030.2020.9351319"},{"key":"9651_CR16","doi-asserted-by":"publisher","first-page":"8604","DOI":"10.3390\/app12178604","volume":"12","author":"M Dener","year":"2022","unstructured":"Dener M, Ok G, Orman A. Malware detection using memory analysis data in a big data environment. Appl Sci. 2022;12:8604.","journal-title":"Appl Sci"},{"key":"9651_CR17","doi-asserted-by":"crossref","unstructured":"Xu Z, Ray S, Subramanyan P, Malik S. Malware detection using machine learning-based analysis of virtual memory access patterns. In Design, Automation & Test in Europe Conference & Exhibition (DATE), 2017 (pp. 169\u2013174). IEEE.","DOI":"10.23919\/DATE.2017.7926977"},{"key":"9651_CR18","doi-asserted-by":"crossref","unstructured":"Shah SSH, Ur Rehman, Ur Rehman Khan A. Memory visualization-based malware detection technique, 2022.","DOI":"10.3390\/s22197611"},{"key":"9651_CR19","doi-asserted-by":"publisher","first-page":"107399","DOI":"10.1016\/j.engappai.2023.107399","volume":"128","author":"GS Kumar","year":"2024","unstructured":"Kumar GS, Premalatha K, Maheshwari GU, Kanna PR, Vijaya G, Nivaashini M. Differential privacy scheme using Laplace mechanism and statistical method computation in deep neural network for privacy preservation. Eng Appl Artif Intell. 2024;128:107399.","journal-title":"Eng Appl Artif Intell"},{"key":"9651_CR20","doi-asserted-by":"publisher","first-page":"121071","DOI":"10.1016\/j.eswa.2023.121071","volume":"234","author":"GS Kumar","year":"2023","unstructured":"Kumar GS, Premalatha K, Maheshwari GU, Kanna PR. No more privacy concern: a privacy-chain based homomorphic encryption scheme and statistical method for privacy preservation of user\u2019s private and sensitive data. Expert Syst Appl. 2023;234:121071.","journal-title":"Expert Syst Appl"},{"key":"9651_CR21","doi-asserted-by":"publisher","first-page":"116545","DOI":"10.1016\/j.eswa.2022.116545","volume":"194","author":"PR Kanna","year":"2022","unstructured":"Kanna PR, Santhi P. Hybrid intrusion detection using mapreduce based black widow optimized convolutional long short-term memory neural networks. Expert Syst Appl. 2022;194:116545.","journal-title":"Expert Syst Appl"},{"key":"9651_CR22","doi-asserted-by":"publisher","first-page":"107132","DOI":"10.1016\/j.knosys.2021.107132","volume":"226","author":"PR Kanna","year":"2021","unstructured":"Kanna PR, Santhi P. Unified deep learning approach for efficient intrusion detection system using integrated spatial\u2013temporal features. Knowl Based Syst. 2021;226:107132.","journal-title":"Knowl Based Syst"},{"issue":"1","key":"9651_CR23","first-page":"71","volume":"11","author":"PR Kanna","year":"2017","unstructured":"Kanna PR, Sindhanaiselvan K, Vijaymeena MK. A defensive mechanism based on PCA to defend denial of-service attack. Int J Secur its Appl. 2017;11(1):71\u201382.","journal-title":"Int J Secur its Appl"},{"key":"9651_CR24","doi-asserted-by":"crossref","unstructured":"Hanafi AS, Saheed YK, Arowolo MO. (2023). An effective intrusion detection in mobile Ad-hoc network using deep belief networks and long short-term memory. Int J Interact Mobile Technol. 17(19).","DOI":"10.3991\/ijim.v17i19.27663"},{"key":"9651_CR25","doi-asserted-by":"publisher","first-page":"100297","DOI":"10.1016\/j.sintl.2024.100297","volume":"6","author":"YK Saheed","year":"2025","unstructured":"Saheed YK, Omole AI, Sabit MO. GA-mADAM-IIoT: a new lightweight threats detection in the industrial IoT via genetic algorithm with attention mechanism and LSTM on multivariate time series sensor data. Sens Int. 2025;6:100297.","journal-title":"Sens Int"},{"key":"9651_CR26","unstructured":"Mathur M. Ransomware (Malware) detection using machine learning, GitHub, Available: https:\/\/github.com\/muditmathur2020\/RansomwareDetection\/blob\/master\/Ransomware.csv"},{"issue":"1","key":"9651_CR27","first-page":"45","volume":"2","author":"P Gupta","year":"2022","unstructured":"Gupta P, Kumar A, Joshi R. Ransomware detection using XGBoost algorithm: a machine learning approach. J Cybersecur Priv. 2022;2(1):45\u201359.","journal-title":"J Cybersecur Priv"},{"key":"9651_CR28","first-page":"1201","volume":"18","author":"Y Wang","year":"2023","unstructured":"Wang Y, Li H, Zhang X. Deep learning-based ransomware detection using convolutional neural networks. IEEE Trans Inf Forensics Secur. 2023;18:1201\u201315.","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"9651_CR29","doi-asserted-by":"crossref","unstructured":"Hasan MM, Rahman MM. (2017, December). RansHunt: A support vector machines based ransomware analysis framework with integrated feature set. In 2017 20th international conference of computer and information technology (ICCIT) (pp. 1-7). IEEE","DOI":"10.1109\/ICCITECHN.2017.8281835"},{"key":"9651_CR30","first-page":"200519","volume":"26","author":"OH Abdulganiyu","year":"2025","unstructured":"Abdulganiyu OH, Tchakoucht A, Alaoui T, A. E. H., Saheed YK. Attention-driven multi-model architecture for unbalanced network traffic intrusion detection via extreme gradient boosting. Intell Syst Appl. 2025;26:200519.","journal-title":"Intell Syst Appl"},{"issue":"1","key":"9651_CR31","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s11227-024-06552-5","volume":"81","author":"OH Abdulganiyu","year":"2025","unstructured":"Abdulganiyu OH, Tchakoucht TA, Saheed YK, Ahmed HA. XIDINTFL-VAE: XGBoost-based intrusion detection of imbalance network traffic via class-wise focal loss variational autoencoder. J Supercomputing. 2025;81(1):1\u201338.","journal-title":"J Supercomputing"},{"key":"9651_CR32","doi-asserted-by":"publisher","first-page":"100674","DOI":"10.1016\/j.ijcip.2024.100674","volume":"45","author":"YK Saheed","year":"2024","unstructured":"Saheed YK, Abdulganiyu OH, Majikumna KU, Mustapha M, Workneh AD. ResNet50-1D-CNN: a new lightweight resNet50-One-dimensional convolution neural network transfer learning-based approach for improved intrusion detection in cyber-physical systems. Int J Crit Infrastruct Prot. 2024;45:100674.","journal-title":"Int J Crit Infrastruct Prot"}],"container-title":["Discover Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10791-025-09651-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10791-025-09651-w\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10791-025-09651-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T14:57:32Z","timestamp":1750172252000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10791-025-09651-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,17]]},"references-count":32,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["9651"],"URL":"https:\/\/doi.org\/10.1007\/s10791-025-09651-w","relation":{},"ISSN":["2948-2992"],"issn-type":[{"value":"2948-2992","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,6,17]]},"assertion":[{"value":"24 February 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 June 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 June 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"This work does not involve any human or animal subjects.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval"}},{"value":"Not Applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent to participate"}},{"value":"Not Applicable.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent to publish"}},{"value":"The authors declare no competing interests.","order":5,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}},{"value":"All authors of this research paper declare that the result\/data\/figure included in this submission have not been previously published, or are under consideration for publication elsewhere.","order":6,"name":"Ethics","group":{"name":"EthicsHeading","label":"Dual publication"}},{"value":"The corresponding author Suneeta Satpathy confirms that all the authors have read the journal policies and is submitting their manuscript in accordance with those policies.","order":7,"name":"Ethics","group":{"name":"EthicsHeading","label":"Authorship"}},{"value":"All the tables\/figures, results are created by the authors. The figure used in Fig.\u00a01 \u201c6 Stages of Ransomware Attack\u201d, is available online for which reference is given.","order":8,"name":"Ethics","group":{"name":"EthicsHeading","label":"Permission to use third-party material"}}],"article-number":"124"}}