{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,21]],"date-time":"2025-12-21T08:33:47Z","timestamp":1766306027378,"version":"3.48.0"},"reference-count":22,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2025,9,19]],"date-time":"2025-09-19T00:00:00Z","timestamp":1758240000000},"content-version":"vor","delay-in-days":261,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100012639","name":"Prince Sultan University","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100012639","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Procedia Computer Science"],"published-print":{"date-parts":[[2025]]},"DOI":"10.1016\/j.procs.2025.09.207","type":"journal-article","created":{"date-parts":[[2025,11,6]],"date-time":"2025-11-06T22:13:28Z","timestamp":1762467208000},"page":"871-880","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Resilience without AI: Assessing the Viability of Deception-Based Ransomware Detection"],"prefix":"10.1016","volume":"270","author":[{"given":"Liam","family":"Goddard","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Muhammad Shahbaz","family":"Khan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Maha","family":"Driss","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Baraq","family":"Ghaleb","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mouad","family":"Lemoudden","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"William J.","family":"Buchanan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jawad","family":"Ahmad","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.procs.2025.09.207_bib1","unstructured":"Aayushjn, 2019. Github - aayushjn\/ransomwarelocker: Honeyfile-based ransomware detection and thwarting mechanism for linux platforms. https:\/\/github.com\/Aayushjn\/RansomwareLocker. [Accessed: Oct. 06, 2024]."},{"key":"10.1016\/j.procs.2025.09.207_bib2","doi-asserted-by":"crossref","unstructured":"Abbasi, M.S., Al-Sahaf, H., Mansoori, M., Welch, I., 2022. Behavior-based ransomware classification: A particle swarm optimization wrapper-based approach for feature selection. Applied Soft Computing 121. doi: 10.1016\/j.asoc.2022.108744.","DOI":"10.1016\/j.asoc.2022.108744"},{"key":"10.1016\/j.procs.2025.09.207_bib3","doi-asserted-by":"crossref","first-page":"733","DOI":"10.5267\/j.ijdns.2024.1.005","article-title":"A fine-tuning of decision tree classifier for ransomware detection based on memory data","volume":"8","author":"Abualhaj","year":"2024","journal-title":"International Journal of Data and Network Science"},{"key":"10.1016\/j.procs.2025.09.207_bib4","doi-asserted-by":"crossref","unstructured":"Ahmed, A.A., Shaahid, A., Alnasser, F., Alfaddagh, S., Binagag, S., Alqahtani, D., 2024. Android ransomware detection using supervised machine learning techniques based on trafic analysis. Sensors 24. doi: 10.3390\/s24010189.","DOI":"10.3390\/s24010189"},{"key":"10.1016\/j.procs.2025.09.207_bib5","doi-asserted-by":"crossref","unstructured":"Aljabri, M., Alhaidari, F., Albuainain, A., Alrashidi, S., Alansari, J., Alqahtani, W., Alshaya, J., 2024. Ransomware detection based on machine learning using memory features. Egyptian Informatics Journal 25. doi: 10.1016\/j.eij.2024.100445.","DOI":"10.1016\/j.eij.2024.100445"},{"key":"10.1016\/j.procs.2025.09.207_bib6","doi-asserted-by":"crossref","unstructured":"Davies, S.R., Macfarlane, R., Buchanan, W.J., 2022. Napierone: A modern mixed file data set alternative to govdocs1. Forensic Science International: Digital Investigation 40, 301330. URL: https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666281721002560, doi: https:\/\/doi.org\/10.1016\/j.fsidi.2021.301330.","DOI":"10.1016\/j.fsidi.2021.301330"},{"key":"10.1016\/j.procs.2025.09.207_bib7","doi-asserted-by":"crossref","unstructured":"Gulmez, S., Kakisim, A.G., Sogukpinar, I., 2024. Xran: Explainable deep learning-based ransomware detection using dynamic analysis. Computers and Security 139. doi: 10.1016\/j.cose.2024.103703.","DOI":"10.1016\/j.cose.2024.103703"},{"key":"10.1016\/j.procs.2025.09.207_bib8","doi-asserted-by":"crossref","first-page":"389","DOI":"10.1016\/j.cose.2017.11.019","article-title":"R-locker: Thwarting ransomware action through a honeyfile-based approach","volume":"73","author":"G\u00f3mez-Hern\u00e1ndez","year":"2018","journal-title":"Computers & Security"},{"key":"10.1016\/j.procs.2025.09.207_bib9","doi-asserted-by":"crossref","unstructured":"G\u00f3mez-Hern\u00e1ndez, J.A., Garc\u00eda-Teodoro, P., 2024. Lightweight crypto-ransomware detection in android based on reactive honeyfile monitoring. Sensors 24. doi: 10.3390\/s24092679.","DOI":"10.3390\/s24092679"},{"key":"10.1016\/j.procs.2025.09.207_bib10","doi-asserted-by":"crossref","first-page":"64","DOI":"10.1049\/ise2.12042","article-title":"Inhibiting crypto-ransomware on windows platforms through a honeyfile-based approach with r-locker","volume":"16","author":"G\u00f3mez-Hern\u00e1ndez","year":"2022","journal-title":"IET Information Security"},{"key":"10.1016\/j.procs.2025.09.207_bib11","doi-asserted-by":"crossref","first-page":"2597","DOI":"10.1007\/s11277-020-07166-9","article-title":"Two-stage ransomware detection using dynamic analysis and machine learning techniques","volume":"112","author":"Hwang","year":"2020","journal-title":"Wireless Personal Communications"},{"key":"10.1016\/j.procs.2025.09.207_bib12","doi-asserted-by":"crossref","first-page":"325","DOI":"10.1016\/j.icte.2020.11.001","article-title":"Ransomware detection using random forest technique","volume":"6","author":"Khammas","year":"2020","journal-title":"ICT Express"},{"key":"10.1016\/j.procs.2025.09.207_bib13","series-title":"A lightweight detection of sequential patterns in file system events during ransomware attacks, in: Barhamgi, M., Wang, H., Wang, X. (Eds.), Web Information Systems Engineering\u2013WISE 2024, Springer Nature Singapore","first-page":"204","author":"Mahboubi","year":"2025"},{"key":"10.1016\/j.procs.2025.09.207_bib14","unstructured":"National Cyber Security Centre (NCSC), National Crime Agency (NCA), 2023. Ransomware, extortion and the cyber crime ecosystem. URL: https:\/\/www.ncsc.gov.uk\/files\/White-paper-Ransomware-extortion-and-the-cyber-crime-ecosystem.pdf. accessed: Jul. 22, 2024."},{"key":"10.1016\/j.procs.2025.09.207_bib15","unstructured":"PricewaterhouseCoopers (PwC), 2022. Responding to the growing threat of human-operated ran-somware attacks. URL: https:\/\/www.pwc.co.uk\/issues\/cyber-security-services\/insights\/responding-to-growing-human-operated-ransomware-attacks-threat.html. accessed: Jul. 22, 2024."},{"key":"10.1016\/j.procs.2025.09.207_bib16","unstructured":"raulsf6, 2020. Github - raulsf6\/r-locker: A ransomware detection and monitoring tool based on deception techniques. https:\/\/github.com\/raulsf6\/R-Locker. [Accessed: Oct. 06, 2024]."},{"key":"10.1016\/j.procs.2025.09.207_bib17","unstructured":"Run, A., Interactive online malware analysis sandbox. https:\/\/app.any.run\/. [Accessed: Oct. 06, 2024]."},{"year":"2022","series-title":"Ransomware detection using process memory","author":"Singh","key":"10.1016\/j.procs.2025.09.207_bib18"},{"key":"10.1016\/j.procs.2025.09.207_bib19","unstructured":"Sophos, 2024. Sophos state of ransomware report 2024. URL: https:\/\/www.sophos.com\/en-us\/content\/state-of-ransomware."},{"key":"10.1016\/j.procs.2025.09.207_bib20","doi-asserted-by":"crossref","first-page":"5","DOI":"10.25271\/sjuoz.2022.10.1.865","article-title":"Bitcoin ransomware detection employing rule-based algorithms","volume":"10","author":"Talabani","year":"2022","journal-title":"Science Journal of University of Zakho"},{"key":"10.1016\/j.procs.2025.09.207_bib21","unstructured":"UIM-SEC, 2020. Github - uim-sec\/ransomware-samples: Warning! this repository contains samples of ransomware. https:\/\/github.com\/UIM-SEC\/ransomware-samples. [Accessed: Oct. 06, 2024]."},{"key":"10.1016\/j.procs.2025.09.207_bib22","unstructured":"Ytisf, 2019. ytisf\/thezoo. https:\/\/github.com\/ytisf\/theZoo. [Accessed: Oct. 06, 2024]."}],"container-title":["Procedia Computer Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1877050925028777?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1877050925028777?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2025,12,21]],"date-time":"2025-12-21T08:30:57Z","timestamp":1766305857000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1877050925028777"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":22,"alternative-id":["S1877050925028777"],"URL":"https:\/\/doi.org\/10.1016\/j.procs.2025.09.207","relation":{},"ISSN":["1877-0509"],"issn-type":[{"type":"print","value":"1877-0509"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Resilience without AI: Assessing the Viability of Deception-Based Ransomware Detection","name":"articletitle","label":"Article Title"},{"value":"Procedia Computer Science","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.procs.2025.09.207","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2025 The Author(s). Published by Elsevier B.V.","name":"copyright","label":"Copyright"}]}}