{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T16:09:11Z","timestamp":1784131751675,"version":"3.55.0"},"reference-count":95,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,6,11]],"date-time":"2026-06-11T00:00:00Z","timestamp":1781136000000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Journal of Information Security and Applications"],"published-print":{"date-parts":[[2026,9]]},"DOI":"10.1016\/j.jisa.2026.104547","type":"journal-article","created":{"date-parts":[[2026,6,14]],"date-time":"2026-06-14T15:58:30Z","timestamp":1781452710000},"page":"104547","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Rethinking ransomware defense in the age of generative AI"],"prefix":"10.1016","volume":"101","author":[{"given":"Nelly","family":"Elsayed","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"issue":"2","key":"10.1016\/j.jisa.2026.104547_bib0001","article-title":"Information security breaches due to ransomware attacks-a systematic literature review","volume":"1","author":"Reshmi","year":"2021","journal-title":"Int J Inf Manag Data Insights"},{"issue":"9","key":"10.1016\/j.jisa.2026.104547_bib0002","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1016\/S1353-4858(16)30086-1","article-title":"Ransomware attacks: detection, prevention and cure","volume":"2016","author":"Brewer","year":"2016","journal-title":"Netw Secur"},{"key":"10.1016\/j.jisa.2026.104547_bib0003","article-title":"Defeating evasive malware with peekaboo: extracting authentic malware behavior with dynamic binary instrumentation","volume":"95","author":"Gaber","year":"2025","journal-title":"J Inf Secur Appl"},{"key":"10.1016\/j.jisa.2026.104547_bib0004","series-title":"2021 11th international conference on advanced computer information technologies (ACIT)","first-page":"473","article-title":"Ransomware attacks: risks, protection and prevention measures","author":"Farion-Melnyk","year":"2021"},{"issue":"5","key":"10.1016\/j.jisa.2026.104547_bib0005","doi-asserted-by":"crossref","first-page":"1837","DOI":"10.3390\/s22051837","article-title":"A survey of crypto ransomware attack detection methodologies: an evolving outlook","volume":"22","author":"Alqahtani","year":"2022","journal-title":"Sensors"},{"issue":"1","key":"10.1016\/j.jisa.2026.104547_bib0006","doi-asserted-by":"crossref","DOI":"10.1093\/cybsec\/tyz003","article-title":"Ransomware payments in the bitcoin ecosystem","volume":"5","author":"Paquet-Clouston","year":"2019","journal-title":"J Cybersecur"},{"issue":"02","key":"10.1016\/j.jisa.2026.104547_bib0007","doi-asserted-by":"crossref","first-page":"624","DOI":"10.4338\/ACI-2016-04-SOA-0064","article-title":"A socio-technical approach to preventing, mitigating, and recovering from ransomware attacks","volume":"7","author":"Sittig","year":"2016","journal-title":"Appl Clin Inform"},{"issue":"10","key":"10.1016\/j.jisa.2026.104547_bib0008","doi-asserted-by":"crossref","first-page":"8","DOI":"10.1016\/S1353-4858(16)30096-4","article-title":"Ransomware: taking businesses hostage","volume":"2016","author":"Mansfield-Devine","year":"2016","journal-title":"Netw Secur"},{"key":"10.1016\/j.jisa.2026.104547_bib0009","series-title":"2020 2nd international conference on computer and information sciences (ICCIS)","first-page":"1","article-title":"Evolution, mitigation, and prevention of ransomware","author":"Chesti","year":"2020"},{"issue":"12","key":"10.1016\/j.jisa.2026.104547_bib0010","doi-asserted-by":"crossref","first-page":"4334","DOI":"10.3390\/app10124334","article-title":"Cyber threat actors for the factory of the future","volume":"10","author":"Sailio","year":"2020","journal-title":"Appl Sci"},{"issue":"1","key":"10.1016\/j.jisa.2026.104547_bib0011","article-title":"An empirical study of ransomware attacks on organizations: an assessment of severity and salient factors affecting vulnerability","volume":"6","author":"Connolly","year":"2020","journal-title":"J Cybersecur"},{"key":"10.1016\/j.jisa.2026.104547_bib0012","unstructured":"Verizon. 2025 data breach investigations report (DBIR), Statistic regarding 88% of ransomware incidents involving small and medium-sized enterprises. 2025. https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\/."},{"key":"10.1016\/j.jisa.2026.104547_bib0013","series-title":"Exploring small business cybersecurity perceptions and preparedness","author":"Harris","year":"2023"},{"issue":"1","key":"10.1016\/j.jisa.2026.104547_bib0014","first-page":"64","article-title":"The impact of ransomware on government agencies: lessons learned and future strategies","volume":"6","author":"Pemmasani","year":"2023","journal-title":"Int J Mod Comput"},{"key":"10.1016\/j.jisa.2026.104547_bib0015","series-title":"International conference on computing and network communications","first-page":"439","article-title":"Evolving trends in ransomware: inherent advanced persistent threat","author":"Addetla","year":"2023"},{"key":"10.1016\/j.jisa.2026.104547_bib0016","doi-asserted-by":"crossref","DOI":"10.1109\/ACCESS.2025.3613668","article-title":"Optimal defense strategies against ransomware with quantum acceleration","author":"Ababneh","year":"2025","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2026.104547_bib0017","first-page":"1","article-title":"The threat of ransomware in the food supply chain: a challenge for food defence","volume":"26","author":"Manning","year":"2023","journal-title":"Trends Organ Crime"},{"issue":"4","key":"10.1016\/j.jisa.2026.104547_bib0018","doi-asserted-by":"crossref","first-page":"1000","DOI":"10.1111\/rego.12505","article-title":"The government behind insurance governance: lessons for ransomware","volume":"17","author":"Baker","year":"2023","journal-title":"Regul Gov"},{"key":"10.1016\/j.jisa.2026.104547_bib0019","unstructured":"Sophos. The state of ransomware 2025. https:\/\/www.sophos.com\/en-us\/content\/state-of-ransomware; 2025. data on the average ransom payment of USD 2 million, and the increase from previous years. (2025)."},{"key":"10.1016\/j.jisa.2026.104547_bib0020","unstructured":"Cybersecurity VenturesRansomware damage costs $265 billion by 2031. https:\/\/cybersecurityventures.com\/ransomware-will-strike-every-2-seconds-by-2031\/; 2023. Web Page, projection of global ransomware damage costs and attack frequency."},{"key":"10.1016\/j.jisa.2026.104547_bib0021","unstructured":"IBM Security,& Ponemon Institute. Cost of a data breach report 2024, statistics on the average cost of a data breach in the healthcare (10.93million)andfinancial(6.08 million) sectors. https:\/\/www.ibm.com\/security\/data-breach; 2024. accessed 2024-05-15."},{"key":"10.1016\/j.jisa.2026.104547_bib0022","unstructured":"HIMSS. The hidden cost of healthcare cyber attacks: Beyond ransoms and regulatory fines. 2025. Online Report, information and estimated total cost related to the Change Healthcare breach, exceeding $1 billion; https:\/\/www.himss.org\/news\/hidden-cost-healthcare-cyber-attacks-beyond-ransoms-and-regulatory-fines."},{"key":"10.1016\/j.jisa.2026.104547_bib0023","series-title":"Ransomware attacks and scenarios: cost factors and loss of reputation","first-page":"273","author":"M\u00f6ller","year":"2023"},{"key":"10.1016\/j.jisa.2026.104547_bib0024","unstructured":"PKWARE. The true cost of a data breach in banking and financial services. Online Blog\/Article; 2025. information regarding per-record costs, customer churn, and stock price drop in the financial sector following a breach."},{"key":"10.1016\/j.jisa.2026.104547_bib0025","series-title":"Ransomware threat mitigation strategies for protecting critical infrastructure assets","first-page":"120","author":"Kalinaki","year":"2024"},{"key":"10.1016\/j.jisa.2026.104547_bib0026","article-title":"The ransomware blueprint: attack patterns and strategic variations across gangs","volume":"95","author":"Saccone","year":"2025","journal-title":"J Inf Secur Appl"},{"key":"10.1016\/j.jisa.2026.104547_bib0027","article-title":"Exploring the ransomware ecosystem and the active defense concept: review of attacks and defense","volume":"94","author":"Zhao","year":"2025","journal-title":"J Inf Secur Appl"},{"issue":"12","key":"10.1016\/j.jisa.2026.104547_bib0028","doi-asserted-by":"crossref","first-page":"8979","DOI":"10.1287\/mnsc.2022.4300","article-title":"Economics of ransomware: risk interdependence and large-scale attacks","volume":"68","author":"August","year":"2022","journal-title":"Manag Sci"},{"issue":"1","key":"10.1016\/j.jisa.2026.104547_bib0029","doi-asserted-by":"crossref","first-page":"20","DOI":"10.1287\/isre.2024.1160","article-title":"\u201cExtortionality\u201d in ransomware attacks: a microeconomic study of extortion and externality","volume":"37","author":"Dey","year":"2025","journal-title":"Inf Syst Res"},{"issue":"11","key":"10.1016\/j.jisa.2026.104547_bib0030","doi-asserted-by":"crossref","first-page":"1283","DOI":"10.1001\/jamainternmed.2024.3162","article-title":"Cybersecurity lessons from the change healthcare attack","volume":"184","author":"Neprash","year":"2024","journal-title":"JAMA Intern Med"},{"key":"10.1016\/j.jisa.2026.104547_bib0031","series-title":"2021 1st babylon international conference on information technology and science (BICITS)","first-page":"210","article-title":"A survey of ransomware attacks for healthcare systems: risks, challenges, solutions and opportunity of research","author":"Thamer","year":"2021"},{"key":"10.1016\/j.jisa.2026.104547_bib0032","doi-asserted-by":"crossref","unstructured":"Neprash H.T., McGlave C.C., Decker W.E., Wood B.P., et al. Hacked to pieces? The effects of ransomware attacks on hospitals and patients. https:\/\/www.nber.org\/papers\/w32095; 2024. Available as NBER Working Paper No 32095 (2024).","DOI":"10.2139\/ssrn.4579292"},{"key":"10.1016\/j.jisa.2026.104547_bib0033","article-title":"Economic impact of a hospital cyberattack in a national health system: descriptive case study","volume":"11","author":"Portela","year":"2023","journal-title":"JMIR Med Inform"},{"key":"10.1016\/j.jisa.2026.104547_bib0034","series-title":"Business impacts of ransomware","first-page":"25","author":"Halikias","year":"2024"},{"issue":"3","key":"10.1016\/j.jisa.2026.104547_bib0035","first-page":"55","article-title":"The growing threat of ransomware what accountants, their clients, and security professionals need to know","volume":"13","author":"Ryle","year":"2023","journal-title":"J Account Manag"},{"key":"10.1016\/j.jisa.2026.104547_bib0036","doi-asserted-by":"crossref","first-page":"305","DOI":"10.18060\/3911.0051","article-title":"Once more unto the breach: how the growing threat of ransomware affects hipaa compliance for covered entities","volume":"15","author":"McLarren","year":"2018","journal-title":"Ind Health L Rev"},{"issue":"3","key":"10.1016\/j.jisa.2026.104547_bib0037","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1016\/S1353-4858(17)30030-2","article-title":"Ransomware and the gdpr","volume":"2017","author":"Green","year":"2017","journal-title":"Netw Secur"},{"issue":"2","key":"10.1016\/j.jisa.2026.104547_bib0038","doi-asserted-by":"crossref","first-page":"367","DOI":"10.1365\/s43439-022-00062-x","article-title":"Could incorporating cybersecurity reporting into SOX have prevented most data breaches at US publicly traded companies? an exploratory study","volume":"3","author":"Sebastian","year":"2022","journal-title":"Int Cybersecur Law Rev"},{"issue":"12","key":"10.1016\/j.jisa.2026.104547_bib0039","first-page":"20","article-title":"Comprehensive analysis of ransomware evolution and countermeasures in the era of digital transformation","volume":"8","author":"Karim","year":"2024","journal-title":"Int J Adv Cybersecur Syst Technol Appl"},{"issue":"1","key":"10.1016\/j.jisa.2026.104547_bib0040","doi-asserted-by":"crossref","first-page":"247","DOI":"10.18485\/ijdrm.2025.7.1.14","article-title":"Understanding ransomware through the lens of disaster risk: implications for cybersecurity and economic stability","volume":"7","author":"Vidovi\u0107","year":"2025","journal-title":"Int J Disaster Risk Sci"},{"key":"10.1016\/j.jisa.2026.104547_bib0041","series-title":"International conference on computational intelligence in information system","first-page":"205","article-title":"Anatomy of ransomware: attack stages, patterns and handling techniques","author":"Kumar","year":"2021"},{"key":"10.1016\/j.jisa.2026.104547_bib0042","doi-asserted-by":"crossref","first-page":"144","DOI":"10.1016\/j.cose.2018.01.001","article-title":"Ransomware threat success factors, taxonomy, and countermeasures: a survey and research directions","volume":"74","author":"Al-Rimy","year":"2018","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2026.104547_bib0043","series-title":"2021 International conference on software engineering & computer systems and 4th international conference on computational science and information management (ICSECS-ICOCSIM)","first-page":"227","article-title":"Ransomware: stages, detection and evasion","author":"Yunus","year":"2021"},{"key":"10.1016\/j.jisa.2026.104547_bib0044","doi-asserted-by":"crossref","first-page":"40698","DOI":"10.1109\/ACCESS.2023.3268535","article-title":"The age of ransomware: a survey on the evolution, taxonomy, and research directions","volume":"11","author":"Razaulla","year":"2023","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2026.104547_bib0045","series-title":"Ransomware and cyber extortion: response and prevention","author":"Davidoff","year":"2022"},{"issue":"2","key":"10.1016\/j.jisa.2026.104547_bib0046","first-page":"164","article-title":"Ransom ware attacks on financial institutions: a review of the literature on cybersecurity risks and countermeasures","volume":"2","author":"Abid","year":"2023","journal-title":"Int J Multidiscip Sci Arts"},{"key":"10.1016\/j.jisa.2026.104547_bib0047","unstructured":"TMicrosoft Security Team. Human-operated ransomware: guidance and overview. https:\/\/learn.microsoft.com\/en-us\/security\/ransomware\/human-operated-ransomware; 2025. accessed November 2025 (2025)."},{"issue":"2","key":"10.1016\/j.jisa.2026.104547_bib0048","doi-asserted-by":"crossref","first-page":"34","DOI":"10.37134\/jictie.vol8.2.4.2021","article-title":"Review on confidentiality, integrity and availability in information security","volume":"8","author":"Yee","year":"2021","journal-title":"J ICT Educ"},{"key":"10.1016\/j.jisa.2026.104547_bib0049","series-title":"Nursing informatics: a health informatics, interprofessional and global perspective","first-page":"391","article-title":"Cybersecurity: ensuring confidentiality, integrity, and availability of information","author":"Kim","year":"2022"},{"issue":"3","key":"10.1016\/j.jisa.2026.104547_bib0050","doi-asserted-by":"crossref","first-page":"2082","DOI":"10.59934\/jaiea.v4i3.1096","article-title":"Case study: how t&s survived a ransomware attack","volume":"4","author":"Yusfrizal","year":"2025","journal-title":"J Artif Intell Eng Appl"},{"key":"10.1016\/j.jisa.2026.104547_bib0051","series-title":"Combating ransomware","author":"Force","year":"2021"},{"key":"10.1016\/j.jisa.2026.104547_bib0052","unstructured":"Cybersecurity and Infrastructure Security Agency (CISA), Understanding the ransomware threat landscape. https:\/\/www.cisa.gov\/resources-tools\/resources\/ransomware-guide; 2023. accessed November 2025."},{"issue":"5","key":"10.1016\/j.jisa.2026.104547_bib0053","doi-asserted-by":"crossref","first-page":"321","DOI":"10.1049\/iet-net.2017.0207","article-title":"Evolution of ransomware","volume":"7","author":"O\u2019Kane","year":"2018","journal-title":"Iet Netw"},{"issue":"1","key":"10.1016\/j.jisa.2026.104547_bib0054","first-page":"26","article-title":"Understanding the evolution of ransomware: paradigm shifts in attack structures","volume":"11","author":"Zimba","year":"2019","journal-title":"Int J Comput Netw Inf Secur"},{"issue":"11s","key":"10.1016\/j.jisa.2026.104547_bib0055","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3514229","article-title":"A survey on ransomware: evolution, taxonomy, and defense solutions","volume":"54","author":"Oz","year":"2022","journal-title":"ACM Comput Surv"},{"key":"10.1016\/j.jisa.2026.104547_bib0056","series-title":"2021 14th international conference on developments in esystems engineering (DeSE)","first-page":"92","article-title":"A survey of ransomware as a service (raas) and methods to mitigate the attack","author":"Alwashali","year":"2021"},{"key":"10.1016\/j.jisa.2026.104547_bib0057","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2020.101762","article-title":"The ransomware-as-a-service economy within the darknet","volume":"92","author":"Meland","year":"2020","journal-title":"Comput Secur"},{"issue":"6","key":"10.1016\/j.jisa.2026.104547_bib0058","first-page":"586","article-title":"Raas: ransomware-as-a-service","volume":"7","author":"Salvi","year":"2019","journal-title":"Int J Comput Sci Eng"},{"key":"10.1016\/j.jisa.2026.104547_bib0059","unstructured":"Europol. Wannacry ransomware overview. https:\/\/www.europol.europa.eu\/media-press\/newsroom\/news\/wannacry-ransomware-attack-analysis; 2022. accessed November 2025."},{"key":"10.1016\/j.jisa.2026.104547_bib0060","unstructured":"Cybersecurity, Infrastructure Security Agency (CISA). Ryuk ransomware: technical analysis. https:\/\/www.cisa.gov\/news-events\/analysis-reports\/aa20-302a-ryuk-ransomware; 2023. accessed November 2025."},{"key":"10.1016\/j.jisa.2026.104547_bib0061","unstructured":"Kaspersky Lab. Revil (sodinokibi) ransomware analysis. https:\/\/securelist.com\/revil-sodinokibi-ransomware\/91670\/; 2023. accessed November 2025."},{"key":"10.1016\/j.jisa.2026.104547_bib0062","unstructured":"Trend Micro Research. Lockbit ransomware: technical details and mitigation. https:\/\/www.trendmicro.com\/en_us\/research\/24\/c\/lockbit-ransomware.html; 2024. accessed November 2025."},{"key":"10.1016\/j.jisa.2026.104547_bib0063","unstructured":"Cybersecurity, Infrastructure Security Agency (CISA). Conti ransomware: threat profile and mitigation strategies. https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa22-138a; 2022. accessed November 2025."},{"key":"10.1016\/j.jisa.2026.104547_bib0064","unstructured":"Symantec Threat Hunter Team. Blackcat (alphv) ransomware: technical overview. https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/blackcat-ransomware; 2023. accessed November 2025."},{"key":"10.1016\/j.jisa.2026.104547_bib0065","unstructured":"SophosLabs. Clop ransomware and moveit exploitation analysis. https:\/\/news.sophos.com\/en-us\/2023\/06\/08\/clop-ransomware-analysis\/; 2023. accessed November 2025 (2023)."},{"issue":"1","key":"10.1016\/j.jisa.2026.104547_bib0066","doi-asserted-by":"crossref","first-page":"46","DOI":"10.3390\/info15010046","article-title":"A holistic approach to ransomware classification: leveraging static and dynamic analysis with visualization","volume":"15","author":"Yamany","year":"2024","journal-title":"Information"},{"key":"10.1016\/j.jisa.2026.104547_bib0067","unstructured":"Sindiramutty S.R.. Autonomous threat hunting: a future paradigm for ai-driven threat intelligence. 2023. arXiv: 2401.00286."},{"issue":"1","key":"10.1016\/j.jisa.2026.104547_bib0068","article-title":"Comprehensive review of advanced machine learning techniques for detecting and mitigating zero-day exploits","volume":"12","author":"Mohamed","year":"2025","journal-title":"EAI Endorsed Trans Scalable Inf Syst"},{"key":"10.1016\/j.jisa.2026.104547_bib0069","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.103849","article-title":"Zero-ran sniff: a zero-day ransomware early detection method based on zero-shot learning","volume":"142","author":"Cen","year":"2024","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2026.104547_bib0070","series-title":"AIP Conference proceedings","doi-asserted-by":"crossref","DOI":"10.1063\/5.0242269","article-title":"Zero-day vulnerabilities and attacks","volume":"Vol. 3227","author":"Das","year":"2025"},{"key":"10.1016\/j.jisa.2026.104547_bib0071","unstructured":"Singh N., Chaudhary V., Singh N., Soni N., Kapoor A.. Transforming business with generative AI: research, innovation, market deployment and future shifts in business models. 2024. arXiv preprint arXiv: 2411.14437."},{"key":"10.1016\/j.jisa.2026.104547_bib0072","series-title":"Proceedings of the 25th annual conference on information technology education","first-page":"1","article-title":"Beyond the code: the role of non-traditional sectors in shaping generative ai innovations and transforming global industries","author":"Glantz","year":"2024"},{"key":"10.1016\/j.jisa.2026.104547_bib0073","series-title":"Information modelling and knowledge bases XXXVI","first-page":"58","article-title":"Challenges and opportunities to apply generative ai in practice","author":"Soini","year":"2025"},{"key":"10.1016\/j.jisa.2026.104547_bib0074","doi-asserted-by":"crossref","first-page":"185181","DOI":"10.1109\/ACCESS.2025.3622002","article-title":"Adapting GenAI strategies: understanding models, aims, and challenges in different targeted data and domains","volume":"13","author":"Yang","year":"2025","journal-title":"IEEE Access"},{"issue":"4","key":"10.1016\/j.jisa.2026.104547_bib0075","doi-asserted-by":"crossref","first-page":"182","DOI":"10.59324\/ejaset.2025.3(4).16","article-title":"Generative artificial intelligence in healthcare: a systematic review of gans, diffusion models, large language models, and variational autoencoders for medical applications","volume":"3","author":"Chataut","year":"2025","journal-title":"Eur J Appl Sci Eng Technol"},{"key":"10.1016\/j.jisa.2026.104547_bib0076","doi-asserted-by":"crossref","first-page":"69812","DOI":"10.1109\/ACCESS.2024.3397775","article-title":"Advancements in generative ai: a comprehensive review of gans, gpt, autoencoders, diffusion model, and transformers","volume":"12","author":"Bengesi","year":"2024","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2026.104547_bib0077","doi-asserted-by":"crossref","unstructured":"Abubakar M.. Generative adversarial networks for simulating financial cyber threat scenarios. Available at SSRN 5374735; 2025.","DOI":"10.2139\/ssrn.5374735"},{"issue":"1","key":"10.1016\/j.jisa.2026.104547_bib0078","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1007\/s10922-022-09690-4","article-title":"Vae-based latent representations learning for botnet detection in iot networks","volume":"31","author":"Snoussi","year":"2023","journal-title":"J Netw Syst Manag"},{"issue":"11","key":"10.1016\/j.jisa.2026.104547_bib0079","doi-asserted-by":"crossref","first-page":"957","DOI":"10.3390\/info16110957","article-title":"LLMs for cybersecurity in the big data era: a comprehensive review of applications, challenges, and future directions","volume":"16","author":"Karras","year":"2025","journal-title":"Information"},{"issue":"1","key":"10.1016\/j.jisa.2026.104547_bib0080","doi-asserted-by":"crossref","DOI":"10.1002\/aisy.202400304","article-title":"A perspective on explainable artificial intelligence methods: shap and lime","volume":"7","author":"Salih","year":"2025","journal-title":"Adv Intell Syst"},{"issue":"4","key":"10.1016\/j.jisa.2026.104547_bib0081","doi-asserted-by":"crossref","first-page":"800","DOI":"10.3390\/jcp2040041","article-title":"A survey of the recent trends in deep learning based malware detection","volume":"2","author":"Tayyab","year":"2022","journal-title":"J Cybersecur Priv"},{"issue":"2","key":"10.1016\/j.jisa.2026.104547_bib0082","doi-asserted-by":"crossref","first-page":"551","DOI":"10.3390\/iot1020030","article-title":"A study on the evolution of ransomware detection using machine learning and deep learning techniques","volume":"1","author":"Fernando","year":"2020","journal-title":"IoT"},{"key":"10.1016\/j.jisa.2026.104547_bib0083","doi-asserted-by":"crossref","DOI":"10.1016\/j.ijhcs.2020.102551","article-title":"The effects of explainability and causability on perception, trust, and acceptance: implications for explainable ai","volume":"146","author":"Shin","year":"2021","journal-title":"Int J Hum-Comput Stud"},{"issue":"2","key":"10.1016\/j.jisa.2026.104547_bib0084","doi-asserted-by":"crossref","first-page":"425","DOI":"10.1108\/INTR-05-2020-0300","article-title":"Managing the tension between opposing effects of explainability of artificial intelligence: a contingency theory perspective","volume":"32","author":"Abedin","year":"2022","journal-title":"Internet Res"},{"issue":"3","key":"10.1016\/j.jisa.2026.104547_bib0085","doi-asserted-by":"crossref","first-page":"499","DOI":"10.1177\/27523543251365451","article-title":"The organization\u2013AI\u2013user responsibility triangle: public understandings of ai and expectations for organizational responses in ai-service-failure crises","volume":"3","author":"Huang","year":"2025","journal-title":"Emerg Media"},{"key":"10.1016\/j.jisa.2026.104547_bib0086","series-title":"Vulnerabilities assessment and risk management in cyber security","first-page":"135","article-title":"Future trends in generative AI for cyber defense: preparing for the next wave of threats","author":"Khan","year":"2025"},{"key":"10.1016\/j.jisa.2026.104547_bib0087","series-title":"2024\u202fIEEE 4th international conference on ICT in business industry & government (ICTBIG)","first-page":"1","article-title":"Ransomware classification: a comparative analysis of ml algorithms","author":"Waghmare","year":"2024"},{"key":"10.1016\/j.jisa.2026.104547_bib0088","series-title":"Proceedings of the IEEE symposium on security and privacy","first-page":"129","article-title":"Cryptovirology: extortion-based security threats and countermeasures","author":"Young","year":"1996"},{"key":"10.1016\/j.jisa.2026.104547_bib0089","article-title":"Developments in ransomware","volume":"87","author":"Bada","year":"2019","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2026.104547_bib0090","series-title":"Detection of intrusions and malware, and vulnerability assessment","first-page":"3","article-title":"Cutting the gordian knot: a look under the hood of ransomware attacks","author":"Kharraz","year":"2015"},{"key":"10.1016\/j.jisa.2026.104547_bib0091","series-title":"2016\u202fIEEE 36th international conference on distributed computing systems (ICDCS)","first-page":"303","article-title":"Cryptolock (and drop it): stopping ransomware attacks on user data","author":"Scaife","year":"2016"},{"issue":"5","key":"10.1016\/j.jisa.2026.104547_bib0092","first-page":"1938","article-title":"A brief study of wannacry threat: ransomware attack 2017","volume":"8","author":"Mohurle","year":"2017","journal-title":"Int J Adv Res Comput Sci"},{"issue":"2","key":"10.1016\/j.jisa.2026.104547_bib0093","first-page":"136","article-title":"Ransomware, threat and detection techniques: a review","volume":"19","author":"Kok","year":"2019","journal-title":"Int J Comput Sci Netw Secur"},{"key":"10.1016\/j.jisa.2026.104547_bib0094","series-title":"2025 14th mediterranean conference on embedded computing (MECO)","first-page":"1","article-title":"Structuring ai risk management framework: EU AI ACT FRIA, GDPR DPIA and ISO 42001\/23894","author":"Parlov","year":"2025"},{"key":"10.1016\/j.jisa.2026.104547_bib0095","series-title":"Presented: Irvine, CA, SAS user group of the Western Region of the United States (WUSS)","first-page":"1","article-title":"The basics of structural equation modeling","author":"Suhr","year":"2006"}],"container-title":["Journal of Information Security and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2214212626001778?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2214212626001778?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T15:47:37Z","timestamp":1784130457000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S2214212626001778"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,9]]},"references-count":95,"alternative-id":["S2214212626001778"],"URL":"https:\/\/doi.org\/10.1016\/j.jisa.2026.104547","relation":{},"ISSN":["2214-2126"],"issn-type":[{"value":"2214-2126","type":"print"}],"subject":[],"published":{"date-parts":[[2026,9]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Rethinking ransomware defense in the age of generative AI","name":"articletitle","label":"Article Title"},{"value":"Journal of Information Security and Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.jisa.2026.104547","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 The Author(s). Published by Elsevier Ltd.","name":"copyright","label":"Copyright"}],"article-number":"104547"}}