{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,2]],"date-time":"2026-08-02T12:35:15Z","timestamp":1785674115643,"version":"3.56.0"},"reference-count":58,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2023,8,16]],"date-time":"2023-08-16T00:00:00Z","timestamp":1692144000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Deanship of Scientific Research at King Khalid University","award":["R.G.P.2\/549\/44"],"award-info":[{"award-number":["R.G.P.2\/549\/44"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["BDCC"],"abstract":"<jats:p>Ransomware attacks pose significant security threats to personal and corporate data and information. The owners of computer-based resources suffer from verification and privacy violations, monetary losses, and reputational damage due to successful ransomware assaults. As a result, it is critical to accurately and swiftly identify ransomware. Numerous methods have been proposed for identifying ransomware, each with its own advantages and disadvantages. The main objective of this research is to discuss current trends in and potential future debates on automated ransomware detection. This document includes an overview of ransomware, a timeline of assaults, and details on their background. It also provides comprehensive research on existing methods for identifying, avoiding, minimizing, and recovering from ransomware attacks. An analysis of studies between 2017 and 2022 is another advantage of this research. This provides readers with up-to-date knowledge of the most recent developments in ransomware detection and highlights advancements in methods for combating ransomware attacks. In conclusion, this research highlights unanswered concerns and potential research challenges in ransomware detection.<\/jats:p>","DOI":"10.3390\/bdcc7030143","type":"journal-article","created":{"date-parts":[[2023,8,16]],"date-time":"2023-08-16T09:57:02Z","timestamp":1692179822000},"page":"143","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":89,"title":["Ransomware Detection Using Machine Learning: A Survey"],"prefix":"10.3390","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-6937-640X","authenticated-orcid":false,"given":"Amjad","family":"Alraizza","sequence":"first","affiliation":[{"name":"Department of Information Systems, King Khalid University, Alfara, Abha 61421, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7556-958X","authenticated-orcid":false,"given":"Abdulmohsen","family":"Algarni","sequence":"additional","affiliation":[{"name":"Department of Computer Science, King Khalid University, Alfara, Abha 61421, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,8,16]]},"reference":[{"key":"ref_1","first-page":"541","article-title":"Intelligent and behavioral-based detection of malware in IoT spectrum sensors","volume":"22","author":"Castillo","year":"2022","journal-title":"Int. J. Inf. Secur."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Chesti, I.A., Humayun, M., Sama, N.U., and Jhanjhi, N. (2020, January 13\u201315). Evolution, mitigation, and prevention of ransomware. Proceedings of the 2020 2nd International Conference on Computer and Information Sciences (ICCIS), Sakaka, Saudi Arabia.","DOI":"10.1109\/ICCIS49240.2020.9257708"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"321","DOI":"10.1049\/iet-net.2017.0207","article-title":"Evolution of ransomware","volume":"7","author":"Philip","year":"2018","journal-title":"IET Netw."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"17","DOI":"10.33736\/jcsi.4932.2022","article-title":"Trends and Future Directions in Automated Ransomware Detection","volume":"1","author":"Jegede","year":"2022","journal-title":"J. Comput. Soc. Inform."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1016\/S1353-4858(16)30086-1","article-title":"Ransomware attacks: Detection, prevention and cure","volume":"2016","author":"Brewer","year":"2016","journal-title":"Netw. Secur."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"8699","DOI":"10.1007\/s12652-020-02630-7","article-title":"Detecting ransomware attacks using intelligent algorithms: Recent development and next direction from deep learning and big data perspectives","volume":"12","author":"Bello","year":"2021","journal-title":"J. Ambient Intell. Humaniz. Comput."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Zahra, A., and Shah, M.A. (2017, January 7\u20138). IoT based ransomware growth rate evaluation and detection using command and control blacklisting. Proceedings of the 2017 23rd International Conference on Automation and Computing (ICAC), Huddersfield, UK.","DOI":"10.23919\/IConAC.2017.8082013"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Shaukat, S.K., and Ribeiro, V.J. (2018, January 3\u20137). RansomWall: A layered defense system against cryptographic ransomware attacks using machine learning. Proceedings of the 2018 10th International Conference on Communication Systems & Networks (COMSNETS), Bengaluru, India.","DOI":"10.1109\/COMSNETS.2018.8328219"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Makinde, O., Sangodoyin, A., Mohammed, B., Neagu, D., and Adamu, U. (2019, January 26\u201328). Distributed network behaviour prediction using machine learning and agent-based micro simulation. Proceedings of the 2019 7th International Conference on Future Internet of Things and Cloud (FiCloud), Istanbul, Turkey.","DOI":"10.1109\/FiCloud.2019.00033"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"47053","DOI":"10.1109\/ACCESS.2019.2907485","article-title":"A multi-classifier network-based crypto ransomware detection system: A case study of locky ransomware","volume":"7","author":"Almashhadani","year":"2019","journal-title":"IEEE Access"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Singh, A., Ikuesan, R.A., and Venter, H. (2022). Ransomware detection using process memory. arXiv.","DOI":"10.34190\/iccws.17.1.53"},{"key":"ref_12","unstructured":"Silva, J.A.H., and Hern\u00e1ndez-Alvarez, M. (2017, January 16\u201320). Large scale ransomware detection by cognitive security. Proceedings of the 2017 IEEE Second Ecuador Technical Chapters Meeting (ETCM), Salinas, Ecuador."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"1141","DOI":"10.1007\/s12652-017-0558-5","article-title":"Detecting crypto-ransomware in IoT networks based on energy consumption footprint","volume":"9","author":"Azmoodeh","year":"2018","journal-title":"J. Ambient Intell. Humaniz. Comput."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"419","DOI":"10.1049\/iet-ifs.2019.0189","article-title":"Malware classification using compact image features and multiclass support vector machines","volume":"14","author":"Ghouti","year":"2020","journal-title":"IET Inf. Secur."},{"key":"ref_15","unstructured":"Modi, J. (2019). Detecting Ransomware in Encrypted Network Traffic Using Machine Learning. [Ph.D. Thesis, University of Victoria]."},{"key":"ref_16","unstructured":"Ameer, M. (2019). Android Ransomware Detection Using Machine Learning Techniques to Mitigate Adversarial Evasion Attacks. [Master\u2019s Thesis, Capital University of Science and Technology]."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"325","DOI":"10.1016\/j.icte.2020.11.001","article-title":"Ransomware detection using random forest technique","volume":"6","author":"Khammas","year":"2020","journal-title":"ICT Express"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"2597","DOI":"10.1007\/s11277-020-07166-9","article-title":"Two-stage ransomware detection using dynamic analysis and machine learning techniques","volume":"112","author":"Hwang","year":"2020","journal-title":"Wirel. Pers. Commun."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"5","DOI":"10.25271\/sjuoz.2022.10.1.865","article-title":"Bitcoin ransomware detection employing rule-based algorithms","volume":"10","author":"Talabani","year":"2022","journal-title":"Sci. J. Univ. Zakho"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Adamu, U., and Awan, I. (2019, January 26\u201328). Ransomware prediction using supervised learning algorithms. Proceedings of the 2019 7th International Conference on Future Internet of Things and Cloud (FiCloud), Istanbul, Turkey.","DOI":"10.1109\/FiCloud.2019.00016"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Wan, Y.L., Chang, J.C., Chen, R.J., and Wang, S.J. (2018, January 27\u201330). Feature-selection-based ransomware detection with machine learning of data analysis. Proceedings of the 2018 3rd International Conference on Computer and Communication Systems (ICCCS), Nagoya, Japan.","DOI":"10.1109\/CCOMS.2018.8463300"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Alzahrani, A., Alshehri, A., Alshahrani, H., Alharthi, R., Fu, H., Liu, A., and Zhu, Y. (2018, January 3\u20135). Randroid: Structural similarity approach for detecting ransomware applications in android platform. Proceedings of the 2018 IEEE International Conference on Electro\/Information Technology (EIT), Rochester, MI, USA.","DOI":"10.1109\/EIT.2018.8500161"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Scaife, N., Carter, H., Traynor, P., and Butler, K.R. (2016, January 27\u201330). Cryptolock (and drop it): Stopping ransomware attacks on user data. Proceedings of the 2016 IEEE 36th International Conference on Distributed Computing Systems (ICDCS), Nara, Japan.","DOI":"10.1109\/ICDCS.2016.46"},{"key":"ref_24","unstructured":"Sgandurra, D., Mu\u00f1oz-Gonz\u00e1lez, L., Mohsen, R., and Lupu, E.C. (2016). Automated dynamic analysis of ransomware: Benefits, limitations and use for detection. arXiv."},{"key":"ref_25","first-page":"392","article-title":"Preventive Measures and Incident Response for Locky Ransomware","volume":"8","author":"Prakash","year":"2017","journal-title":"Int. J. Adv. Res. Comput. Sci."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"tyz003","DOI":"10.1093\/cybsec\/tyz003","article-title":"Ransomware payments in the bitcoin ecosystem","volume":"5","author":"Haslhofer","year":"2019","journal-title":"J. Cybersecur."},{"key":"ref_27","first-page":"136","article-title":"Ransomware, threat and detection techniques: A review","volume":"19","author":"Kok","year":"2019","journal-title":"Int. J. Comput. Sci. Netw. Secur"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Thakran, E., and Kumari, A. (2023, July 03). Impact of \u201cRansomware\u201d on Critical Infrastructure Due to Pandemic. Available online: https:\/\/ssrn.com\/abstract=4361110.","DOI":"10.2139\/ssrn.4361110"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Ahmed, Y.A., Huda, S., Al-rimy, B.A.S., Alharbi, N., Saeed, F., Ghaleb, F.A., and Ali, I.M. (2022). A weighted minimum redundancy maximum relevance technique for ransomware early detection in industrial IoT. Sustainability, 14.","DOI":"10.3390\/su14031231"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"6249","DOI":"10.1109\/ACCESS.2019.2963724","article-title":"A comprehensive review on malware detection approaches","volume":"8","author":"Aslan","year":"2020","journal-title":"IEEE Access"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Akhtar, M.S., and Feng, T. (2022). Malware Analysis and Detection Using Machine Learning Algorithms. Symmetry, 14.","DOI":"10.3390\/sym14112304"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Yamany, B., Elsayed, M.S., Jurcut, A.D., Abdelbaki, N., and Azer, M.A. (2022). A New Scheme for Ransomware Classification and Clustering Using Static Features. Electronics, 11.","DOI":"10.3390\/electronics11203307"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Yamany, B., Azer, M.A., and Abdelbaki, N. (2022, January 8\u20139). Ransomware Clustering and Classification using Similarity Matrix. Proceedings of the 2022 2nd International Mobile, Intelligent, and Ubiquitous Computing Conference (MIUCC), Cairo, Egypt.","DOI":"10.1109\/MIUCC55081.2022.9781655"},{"key":"ref_34","first-page":"8845833","article-title":"Modified decision tree technique for ransomware detection at runtime through API Calls","volume":"2020","author":"Ullah","year":"2020","journal-title":"Sci. Program."},{"key":"ref_35","first-page":"1653","article-title":"GOSVM: Gannet optimization based support vector machine for malicious attack detection in cloud environment","volume":"15","author":"Arunkumar","year":"2023","journal-title":"Int. J. Inf. Technol."},{"key":"ref_36","first-page":"435","article-title":"Comparison of malware detection techniques using machine learning algorithm","volume":"16","author":"Selamat","year":"2019","journal-title":"Indones. J. Electr. Eng. Comput. Sci."},{"key":"ref_37","unstructured":"Mezquita, Y., Alonso, R.S., Casado-Vara, R., Prieto, J., and Corchado, J.M. (2021). Distributed Computing and Artificial Intelligence, Special Sessions, 17th International Conference, Springer."},{"key":"ref_38","unstructured":"Saadat, S., and Joseph Raymond, V. (2021). Artificial Intelligence Techniques for Advanced Computing Applications: Proceedings of ICACT 2020, Springer."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Noorbehbahani, F., Rasouli, F., and Saberi, M. (2019, January 28\u201329). Analysis of machine learning techniques for ransomware detection. Proceedings of the 2019 16th International ISC (Iranian Society of Cryptology) Conference on Information Security and Cryptology (ISCISC), Mashhad, Iran.","DOI":"10.1109\/ISCISC48546.2019.8985139"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"24522","DOI":"10.1109\/ACCESS.2020.2970466","article-title":"Avoiding future digital extortion through robust protection against ransomware threats using deep learning based adaptive approaches","volume":"8","author":"Sharmeen","year":"2020","journal-title":"IEEE Access"},{"key":"ref_41","first-page":"2581","article-title":"Ransomware Detection System and Analysis Using Latest Tool","volume":"7","author":"Swami","year":"2021","journal-title":"Int. J. Adv. Res. Sci. Commun. Technol."},{"key":"ref_42","unstructured":"Wang, X.b., Yang, G.y., Li, Y.c., and Liu, D. (2008, January 21\u201324). Review on the application of artificial intelligence in antivirus detection system i. Proceedings of the 2008 IEEE Conference on Cybernetics and Intelligent Systems, Chengdu, China."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Yang, B., and Liu, D. (2019, January 15\u201317). Research on Network Traffic Identification based on Machine Learning and Deep Packet Inspection. Proceedings of the 2019 IEEE 3rd Information Technology, Networking, Electronic and Automation Control Conference (ITNEC), Chengdu, China.","DOI":"10.1109\/ITNEC.2019.8729153"},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Pimenta Rodrigues, G.A., de Oliveira Albuquerque, R., Gomes de Deus, F.E., de Sousa Jr, R.T., de Oliveira J\u00fanior, G.A., Garcia Villalba, L.J., and Kim, T.H. (2017). Cybersecurity and network forensics: Analysis of malicious traffic towards a honeynet with deep packet inspection. Appl. Sci., 7.","DOI":"10.3390\/app7101082"},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Song, W., Beshley, M., Przystupa, K., Beshley, H., Kochan, O., Pryslupskyi, A., Pieniak, D., and Su, J. (2020). A software deep packet inspection system for network traffic analysis and anomaly detection. Sensors, 20.","DOI":"10.3390\/s20061637"},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"7","DOI":"10.1007\/s10922-010-9181-x","article-title":"Optimizing deep packet inspection for high-speed traffic analysis","volume":"19","author":"Cascarano","year":"2011","journal-title":"J. Netw. Syst. Manag."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"277","DOI":"10.1007\/s11416-019-00338-7","article-title":"A Cyber-Kill-Chain based taxonomy of crypto-ransomware features","volume":"15","author":"Dargahi","year":"2019","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"108346","DOI":"10.1016\/j.compeleceng.2022.108346","article-title":"R-Sentry: Deception based ransomware detection using file access patterns","volume":"103","author":"Sheen","year":"2022","journal-title":"Comput. Electr. Eng."},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"4770","DOI":"10.1038\/s41598-022-08504-6","article-title":"Classification of ransomware using different types of neural networks","volume":"12","author":"Madani","year":"2022","journal-title":"Sci. Rep."},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"50","DOI":"10.1016\/j.comcom.2019.08.003","article-title":"Malware traffic classification using principal component analysis and artificial neural network for extreme surveillance","volume":"147","author":"Arivudainambi","year":"2019","journal-title":"Comput. Commun."},{"key":"ref_51","first-page":"102646","article-title":"Evaluation metric for crypto-ransomware detection using machine learning","volume":"55","author":"Kok","year":"2020","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Masum, M., Faruk, M.J.H., Shahriar, H., Qian, K., Lo, D., and Adnan, M.I. (2022, January 26\u201329). Ransomware classification and detection with machine learning algorithms. Proceedings of the 2022 IEEE 12th Annual Computing and Communication Workshop and Conference (CCWC), Las Vegas, NV, USA.","DOI":"10.1109\/CCWC54503.2022.9720869"},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"Edis, D., Hayman, T., and Vatsa, A. (2021, January 13). Understanding Complex Malware. Proceedings of the 2021 IEEE Integrated STEM Education Conference (ISEC), Princeton, NJ, USA.","DOI":"10.1109\/ISEC52395.2021.9763932"},{"key":"ref_54","doi-asserted-by":"crossref","first-page":"102490","DOI":"10.1016\/j.cose.2021.102490","article-title":"Ransomware: Recent advances, analysis, challenges and future research directions","volume":"111","author":"Beaman","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_55","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3479393","article-title":"Ransomware mitigation in the modern era: A comprehensive review, research challenges, and future directions","volume":"54","author":"McIntosh","year":"2021","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"ref_56","doi-asserted-by":"crossref","unstructured":"Aboaoja, F.A., Zainal, A., Ghaleb, F.A., Al-rimy, B.A.S., Eisa, T.A.E., and Elnour, A.A.H. (2022). Malware detection issues, challenges, and future directions: A survey. Appl. Sci., 12.","DOI":"10.3390\/app12178482"},{"key":"ref_57","doi-asserted-by":"crossref","unstructured":"Gorment, N.Z., Selamat, A., Cheng, L.K., and Krejcar, O. (2023). Machine Learning Algorithm for Malware Detection: Taxonomy, Current Challenges and Future Directions. IEEE Access, 1.","DOI":"10.1109\/ACCESS.2023.3256979"},{"key":"ref_58","doi-asserted-by":"crossref","unstructured":"Kapoor, A., Gupta, A., Gupta, R., Tanwar, S., Sharma, G., and Davidson, I.E. (2021). Ransomware detection, avoidance, and mitigation scheme: A review and future directions. Sustainability, 14.","DOI":"10.3390\/su14010008"}],"container-title":["Big Data and Cognitive Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2504-2289\/7\/3\/143\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T20:34:47Z","timestamp":1760128487000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2504-2289\/7\/3\/143"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,8,16]]},"references-count":58,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2023,9]]}},"alternative-id":["bdcc7030143"],"URL":"https:\/\/doi.org\/10.3390\/bdcc7030143","relation":{},"ISSN":["2504-2289"],"issn-type":[{"value":"2504-2289","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,8,16]]}}}