{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,16]],"date-time":"2026-03-16T14:20:34Z","timestamp":1773670834030,"version":"3.50.1"},"reference-count":44,"publisher":"Association for Computing Machinery (ACM)","issue":"1","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2026,3,31]]},"abstract":"<jats:p>Human-Operated Ransomware (HoR) is one of the most persistent and evolving threats in cybersecurity, as attackers use changing Tactics, Techniques, and Procedures (TTPs) to evade traditional detection. The lack of structured and publicly available TTP-level datasets has limited the development of models capable of identifying HoR behavior early. In this study, we construct a dataset of TTP sequences from 15 prominent ransomware families observed in 2023 and 2024, structured according to the MITRE ATT&amp;CK framework. We evaluate a range of sequence modeling approaches, including Markov chains, n-gram analysis, LSTM, GRU, and RNN, to classify ransomware behavior based on the progression of observed TTPs. The RNN model achieved the highest accuracy of 82% and an AUC of 0.9694 (95% CI: 0.0087\u20130.0168), with an average false positive rate between 0.0087 and 0.0168 using 10-fold cross-validation. SMOTE was used to address class imbalance, improving model accuracy by 6% (from 76% to 82%). These results show that learning from ordered TTP patterns can support timely detection of ransomware activity, enabling earlier intervention in threat response workflows.<\/jats:p>","DOI":"10.1145\/3786772","type":"journal-article","created":{"date-parts":[[2025,12,26]],"date-time":"2025-12-26T14:20:18Z","timestamp":1766758818000},"page":"1-21","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Sequence Learning over Behavioral Attack Patterns for Early Detection of Human-Operated Ransomware"],"prefix":"10.1145","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2658-1969","authenticated-orcid":false,"given":"Mohammed","family":"Rauf Ali Khan","sequence":"first","affiliation":[{"name":"Department of Computer Engineering, College of Computing and Mathematics, King Fahd University of Petroleum and Minerals, Dhahran, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-1546-2737","authenticated-orcid":false,"given":"Akram","family":"Algaolahi","sequence":"additional","affiliation":[{"name":"Department of Computer Engineering, College of Computing and Mathematics, King Fahd University of Petroleum and Minerals, Dhahran, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8630-1784","authenticated-orcid":false,"given":"Farid","family":"Binbeshr","sequence":"additional","affiliation":[{"name":"Interdisciplinary Research Center for Intelligent Secure Systems, King Fahd University of Petroleum and Minerals, Dhahran, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9131-6964","authenticated-orcid":false,"given":"Muhammad","family":"Imam","sequence":"additional","affiliation":[{"name":"Computer Engineering Department and Interdisciplinary Research Center for Intelligent Secure Systems, King Fahd University of Petroleum and Minerals, Dharan, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,3,16]]},"reference":[{"key":"e_1_3_1_2_2","unstructured":"Microsoft. 2021. Human-Operated Ransomware Attacks. Retrieved from https:\/\/www.microsoft.com\/en-us\/security\/blog\/2020\/03\/05\/human-operated-ransomware-attacks-a-preventable-disaster\/"},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.3390\/bdcc7030143"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-44885-4_5"},{"key":"e_1_3_1_5_2","unstructured":"The MITRE Corporation. Enterprise Matrix MITRE ATT&CK Framework. Retrieved from https:\/\/attack.mitre.org\/matrices\/enterprise\/"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102490"},{"key":"e_1_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/3514229"},{"issue":"40","key":"e_1_3_1_8_2","doi-asserted-by":"crossref","first-page":"31","DOI":"10.5120\/ijca2020919899","article-title":"Ransomware prevention and mitigation techniques","volume":"177","author":"Alshaikh H.","year":"2020","unstructured":"H. Alshaikh, N. Ramadan, and H. Ahmed. 2020. Ransomware prevention and mitigation techniques. International Journal of Computer Applications 177, 40 (2020), 31\u201339.","journal-title":"International Journal of Computer Applications"},{"key":"e_1_3_1_9_2","first-page":"1282","volume-title":"International Journal of Scientific Research and Management","author":"Nagar G.","year":"2024","unstructured":"G. Nagar. 2024. The evolution of ransomware: Tactics, techniques, and mitigation strategies. International Journal of Scientific Research and Management 12, 06 (2024), 1282\u20131298."},{"key":"e_1_3_1_10_2","doi-asserted-by":"publisher","DOI":"10.3390\/electronics12214494"},{"key":"e_1_3_1_11_2","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1109\/FiCloud49777.2021.00016","volume-title":"2021 8th International Conference on Future Internet of Things and Cloud (FiCloud)","author":"Mirza Q. K. A.","year":"2021","unstructured":"Q. K. A. Mirza, M. Brown, O. Halling, L. Shand, and A. Alam. 2021. Ransomware analysis using cyber kill chain. In 2021 8th International Conference on Future Internet of Things and Cloud (FiCloud). IEEE, 58\u201365."},{"key":"e_1_3_1_12_2","unstructured":"Sophos. 2024. The State of Ransomware 2024. Retrieved from https:\/\/www.sophos.com\/en-us\/content\/state-of-ransomware"},{"key":"e_1_3_1_13_2","unstructured":"Kaspersky. 2024. State of ransomware in 2024. Retrieved from https:\/\/securelist.com\/state-of-ransomware-2023\/112590\/"},{"key":"e_1_3_1_14_2","unstructured":"S. Gihon. 2023. Ransomware Trends 2023 Report. Retrieved from https:\/\/cyberint.com\/blog\/research\/ransomware-trends-and-statistics-2023-report\/"},{"issue":"2","key":"e_1_3_1_15_2","first-page":"111","article-title":"Automating malware detection: A study on the efficacy of AI-driven solutions","volume":"2","author":"Maddireddy B. R.","year":"2023","unstructured":"B. R. Maddireddy. 2023. Automating malware detection: A study on the efficacy of AI-driven solutions. Journal of Environmental Science and Technology 2, 2 (2023), 111\u2013124.","journal-title":"Journal of Environmental Science and Technology"},{"key":"e_1_3_1_16_2","doi-asserted-by":"crossref","first-page":"356","DOI":"10.1109\/COMSNETS.2018.8328219","volume-title":"2018 10th International Conference on Communication Systems and Networks (COMSNETS)","author":"Shaukat S. K.","year":"2018","unstructured":"S. K. Shaukat and V. J. Ribeiro. 2018. RansomWall: A layered defense system against cryptographic ransomware attacks using machine learning. In 2018 10th International Conference on Communication Systems and Networks (COMSNETS). IEEE, 356\u2013363."},{"key":"e_1_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1007\/s12652-017-0558-5"},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_6"},{"key":"e_1_3_1_19_2","doi-asserted-by":"publisher","DOI":"10.3390\/s19051114"},{"key":"e_1_3_1_20_2","first-page":"82","volume-title":"2020 17th ISC Conference on Information Security and Cryptology (ISCISC)","author":"Manavi F.","year":"2020","unstructured":"F. Manavi and A. Hamzeh. 2020. A new method for ransomware detection based on PE header using convolutional neural networks. In 2020 17th ISC Conference on Information Security and Cryptology (ISCISC). IEEE, 82\u201387."},{"key":"e_1_3_1_21_2","volume-title":"Network and Distributed Systems Security (NDSS) Symposium","author":"Aghakhani H.","year":"2020","unstructured":"H. Aghakhani, F. Gritti, F. Mecca, M. Lindorfer, S. Ortolani, D. Balzarotti, G. Vigna, and C. Kruegel. 2020. When malware is packin\u2019 heat; limits of machine learning classifiers based on static analysis features. In Network and Distributed Systems Security (NDSS) Symposium."},{"key":"e_1_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2015.02.149"},{"key":"e_1_3_1_23_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103160"},{"key":"e_1_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3322427"},{"key":"e_1_3_1_25_2","unstructured":"C. Sauerwein and A. Pfohl. 2022. Towards automated classification of attackers\u2019 TTPs by combining NLP with ML techniques. arXiv:2207.08478. Retrieved from https:\/\/arxiv.org\/abs\/2207.08478"},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.3390\/electronics13050824"},{"key":"e_1_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.3390\/app11167738"},{"key":"e_1_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.icte.2020.11.001"},{"key":"e_1_3_1_29_2","unstructured":"Malware Bazaar. 2020. MalwareBazaar: A Community-Driven Malware Sharing Platform. Retrieved from https:\/\/bazaar.abuse.ch\/browse\/"},{"key":"e_1_3_1_30_2","unstructured":"Virus Total. 2012. VirusTotal: A Free Online Virus Malware and URL Scanner. Retrieved from https:\/\/www.virustotal.com\/gui\/home\/search"},{"key":"e_1_3_1_31_2","unstructured":"CISA. 2021. Conti Ransomware Healthcare Networks. Retrieved from https:\/\/www.cisa.gov\/stopransomware\/conti-ransomware-healthcare-networks"},{"key":"e_1_3_1_32_2","doi-asserted-by":"publisher","unstructured":"Preeti Mishra Tanmay Jain Palak Aggarwal Gunjan Paul Brij B. Gupta Razaz Waheeb Attar and Akshat Gaurav. 2024. CloudIntellMal: An advanced cloud based intelligent malware detection framework to analyze android applications. Computers & Electrical Engineering 119 Part A (Oct. 2024) 109483. DOI: 10.1016\/j.compeleceng.2024.109483","DOI":"10.1016\/j.compeleceng.2024.109483"},{"key":"e_1_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.1080\/19393555.2025.2543450"},{"issue":"9","key":"e_1_3_1_34_2","doi-asserted-by":"crossref","first-page":"1140","DOI":"10.3897\/jucs.131753","article-title":"Exploiting TTPs to design an extensible and explainable malware detection system","volume":"30","author":"Sharma Y.","year":"2024","unstructured":"Y. Sharma, S. Birnbach, and I. Martinovic. 2024. Exploiting TTPs to design an extensible and explainable malware detection system. Journal of Universal Computer Science 30, 9 (2024), 1140\u20131162.","journal-title":"Journal of Universal Computer Science"},{"key":"e_1_3_1_35_2","doi-asserted-by":"publisher","unstructured":"H.-W. Li P.-T. Liu B.-W. Lin Y.-C. Liao and Y. Huang. 2024. IPMES: A tool for incremental TTP detection over the system audit event stream. In 2024 54th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN) 265\u2013273 . DOI: 10.1109\/DSN58291.2024.00036","DOI":"10.1109\/DSN58291.2024.00036"},{"key":"e_1_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.3390\/electronics14020257"},{"key":"e_1_3_1_37_2","unstructured":"HSE. 2021. Cyber-Attack and HSE Response. Retrieved from https:\/\/www2.hse.ie\/services\/cyber-attack\/what-happened\/"},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.3390\/electronics14071245"},{"key":"e_1_3_1_39_2","unstructured":"P. Idliman W. Balfour B. Featheringham and H. Chesterfield. 2025. Entropy-synchronized neural hashing for unsupervised ransomware detection. arXiv:2501.18131. Retrieved from https:\/\/arxiv.org\/abs\/2501.18131"},{"key":"e_1_3_1_40_2","unstructured":"F. Pembroke E. Featherstonehaugh S. Wetherington H. Fitzgerald M. Featherington and P. Idliman. 2025. Hierarchical manifold projection for ransomware detection: A novel geometric approach to identifying malicious encryption patterns. arXiv:2502.08013. Retrieved from https:\/\/arxiv.org\/abs\/2502.08013"},{"key":"e_1_3_1_41_2","unstructured":"B. Fortescue E. Hawksmoor A. Wetherington F. Marlowe and K. Pekepok. 2025. Neural encrypted state transduction for ransomware classification: A novel approach using cryptographic flow residuals. arXiv:2502.05341. Retrieved from https:\/\/arxiv.org\/abs\/2502.05341"},{"key":"e_1_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.3991\/ijim.v19i10.49245"},{"key":"e_1_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.1007\/s41870-025-02681-z"},{"key":"e_1_3_1_44_2","doi-asserted-by":"crossref","unstructured":"H. W. Li P. T. Liu B. W. Lin Y. C. Liao and Y. Huang. 2024. IPMES: A tool for incremental TTP detection over the system audit event stream. In 2024 54th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN). IEEE 265\u2013273.","DOI":"10.1109\/DSN58291.2024.00036"},{"key":"e_1_3_1_45_2","unstructured":"Y. Jiang Q. Meng F. Shang N. Oo L. T. H. Minh H. W. Lim and B. Sikdar. 2025. MITRE ATT&CK applications in cybersecurity and the way forward. arXiv:2502.10825. Retrieved from https:\/\/arxiv.org\/abs\/2502.10825"}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3786772","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,16]],"date-time":"2026-03-16T13:07:39Z","timestamp":1773666459000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3786772"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,16]]},"references-count":44,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026,3,31]]}},"alternative-id":["10.1145\/3786772"],"URL":"https:\/\/doi.org\/10.1145\/3786772","relation":{},"ISSN":["2692-1626","2576-5337"],"issn-type":[{"value":"2692-1626","type":"print"},{"value":"2576-5337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3,16]]},"assertion":[{"value":"2025-07-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-12-08","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-03-16","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}