{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T15:25:35Z","timestamp":1784301935017,"version":"3.55.0"},"reference-count":52,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2024,1,14]],"date-time":"2024-01-14T00:00:00Z","timestamp":1705190400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"University College Dublin (UCD), School of Computer Science","award":["13\/RC\/2077"],"award-info":[{"award-number":["13\/RC\/2077"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>Ransomware is a type of malicious software that encrypts a victim\u2019s files and demands payment in exchange for the decryption key. It is a rapidly growing and evolving threat that has caused significant damage and disruption to individuals and organizations around the world. In this paper, we propose a comprehensive ransomware classification approach based on the comparison of similarity matrices derived from static, dynamic analysis, and visualization. Our approach involves the use of multiple analysis techniques to extract features from ransomware samples and to generate similarity matrices based on these features. These matrices are then compared using a variety of comparison algorithms to identify similarities and differences between the samples. The resulting similarity scores are then used to classify the samples into different categories, such as families, variants, and versions. We evaluate our approach using a dataset of ransomware samples and demonstrate that it can accurately classify the samples with a high degree of accuracy. One advantage of our approach is the use of visualization, which allows us to classify and cluster large datasets of ransomware in a more intuitive and effective way. In addition, static analysis has the advantage of being fast and accurate, while dynamic analysis allows us to classify and cluster packed ransomware samples. We also compare our approach to other classification approaches based on single analysis techniques and show that our approach outperforms these approaches in terms of classification accuracy. Overall, our study demonstrates the potential of using a comprehensive approach based on the comparison of multiple analysis techniques, including static analysis, dynamic analysis, and visualization, for the accurate and efficient classification of ransomware. It also highlights the importance of considering multiple analysis techniques in the development of effective ransomware classification methods, especially when dealing with large datasets and packed samples.<\/jats:p>","DOI":"10.3390\/info15010046","type":"journal-article","created":{"date-parts":[[2024,1,15]],"date-time":"2024-01-15T07:25:07Z","timestamp":1705303507000},"page":"46","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":22,"title":["A Holistic Approach to Ransomware Classification: Leveraging Static and Dynamic Analysis with Visualization"],"prefix":"10.3390","volume":"15","author":[{"given":"Bahaa","family":"Yamany","sequence":"first","affiliation":[{"name":"School of Information Technology and Computer Science, Nile University, Cairo 12566, Egypt"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2416-7481","authenticated-orcid":false,"given":"Mahmoud Said","family":"Elsayed","sequence":"additional","affiliation":[{"name":"School of Computer Science, University College Dublin, Belfield, D04 V1W8 Dublin, Ireland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2705-1823","authenticated-orcid":false,"given":"Anca D.","family":"Jurcut","sequence":"additional","affiliation":[{"name":"School of Computer Science, University College Dublin, Belfield, D04 V1W8 Dublin, Ireland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2724-6209","authenticated-orcid":false,"given":"Nashwa","family":"Abdelbaki","sequence":"additional","affiliation":[{"name":"School of Information Technology and Computer Science, Nile University, Cairo 12566, Egypt"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8068-5120","authenticated-orcid":false,"given":"Marianne A.","family":"Azer","sequence":"additional","affiliation":[{"name":"School of Information Technology and Computer Science, Nile University, Cairo 12566, Egypt"},{"name":"Computers and Systems Department, National Telecommunication Institute, Cairo 11768, Egypt"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2024,1,14]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"100529","DOI":"10.1016\/j.cosrev.2022.100529","article-title":"A comprehensive survey on deep learning based malware detection techniques","volume":"47","author":"Gopinath","year":"2023","journal-title":"Comput. Sci. Rev."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"103582","DOI":"10.1016\/j.cose.2023.103582","article-title":"Automated machine learning for deep learning based malware detection","volume":"137","author":"Brown","year":"2024","journal-title":"Comput. Secur."},{"key":"ref_3","first-page":"136","article-title":"Ransomware, threat and detection techniques: A review","volume":"19","author":"Kok","year":"2019","journal-title":"Int. J. Comput. Sci. Netw. Secur."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"2354","DOI":"10.3390\/electronics11152354","article-title":"Malware analysis in iot & android systems with defensive mechanism","volume":"11","author":"Yadav","year":"2022","journal-title":"Electronics"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"108693","DOI":"10.1016\/j.comnet.2021.108693","article-title":"Federated learning for malware detection in IoT devices","volume":"204","author":"Rey","year":"2022","journal-title":"Comput. Netw."},{"key":"ref_6","unstructured":"Johnson, S., Gowtham, R., and Nair, A.R. (2022). Inventive Computation and Information Technologies: Proceedings of ICICIT 2021, Springer Nature."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"144","DOI":"10.1016\/j.cose.2018.01.001","article-title":"Ransomware threat success factors, taxonomy, and countermeasures: A survey and research directions","volume":"74","author":"Maarof","year":"2018","journal-title":"Comput. Secur."},{"key":"ref_8","unstructured":"Akhtar, Z. (2021). Malware detection and analysis: Challenges and research opportunities. arXiv."},{"key":"ref_9","first-page":"20","article-title":"A study on malware and malware detection techniques","volume":"8","author":"Tahir","year":"2018","journal-title":"Int. J. Educ. Manag. Eng."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Yamany, B., Elsayed, M.S., Jurcut, A.D., Abdelbaki, N., and Azer, M.A. (2022). A New Scheme for Ransomware Classification and Clustering Using Static Features. Electronics, 11.","DOI":"10.3390\/electronics11203307"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Yamany, B.E.M., and Azer, M.A. (2021, January 5\u20137). SALAM Ransomware Behavior Analysis Challenges and Decryption. Proceedings of the 2021 Tenth International Conference on Intelligent Computing and Information Systems (ICICIS), Cairo, Egypt.","DOI":"10.1109\/ICICIS52592.2021.9694154"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"551","DOI":"10.3390\/iot1020030","article-title":"A study on the evolution of ransomware detection using machine learning and deep learning techniques","volume":"1","author":"Fernando","year":"2020","journal-title":"IoT"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"119710","DOI":"10.1109\/ACCESS.2020.3003785","article-title":"A digital DNA sequencing engine for ransomware detection using machine learning","volume":"8","author":"Khan","year":"2020","journal-title":"IEEE Access"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"124579","DOI":"10.1109\/ACCESS.2020.3006143","article-title":"A review of android malware detection approaches based on machine learning","volume":"8","author":"Liu","year":"2020","journal-title":"IEEE Access"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"e5422","DOI":"10.1002\/cpe.5422","article-title":"Ransomware detection using machine learning algorithms","volume":"32","author":"Bae","year":"2020","journal-title":"Concurr. Comput. Pract. Exp."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"169944","DOI":"10.1109\/ACCESS.2020.3023764","article-title":"Design of intrusion detection honeypot using social leopard algorithm to detect IoT ransomware attacks","volume":"8","author":"Chakkaravarthy","year":"2020","journal-title":"IEEE Access"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"El-Kosairy, A., and Azer, M.A. (2018, January 4\u20136). Intrusion and ransomware detection system. Proceedings of the 2018 1st International Conference on Computer Applications & Information Security (ICCAIS), Riyadh, Saudi Arabia.","DOI":"10.1109\/CAIS.2018.8471688"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Vishwakarma, R., and Jain, A.K. (2019, January 23\u201325). A honeypot with machine learning based detection framework for defending IoT based botnet DDoS attacks. Proceedings of the 2019 3rd International Conference on Trends in Electronics and Informatics (ICOEI), Tirunelveli, India.","DOI":"10.1109\/ICOEI.2019.8862720"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"e5726","DOI":"10.1002\/cpe.5726","article-title":"VoterChoice: A ransomware detection honeypot with multiple voting framework","volume":"32","author":"Rajasegarar","year":"2020","journal-title":"Concurr. Comput. Pract. Exp."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Pont, J., Arief, B., and Hernandez-Castro, J. (2020, January 16\u201318). Why current statistical approaches to ransomware detection fail. Proceedings of the International Conference on Information Security, Bali, Indonesia.","DOI":"10.1007\/978-3-030-62974-8_12"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Yewale, A., and Singh, M. (2016, January 25\u201327). Malware detection based on opcode frequency. Proceedings of the 2016 International Conference on Advanced Communication Control and Computing Technologies (ICACCCT), Ramanathapuram, India.","DOI":"10.1109\/ICACCCT.2016.7831719"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Rezaei, S., Afraz, A., Rezaei, F., and Shamani, M.R. (2016, January 27\u201328). Malware detection using opcodes statistical features. Proceedings of the 2016 8th International Symposium On Telecommunications (IST), Tehran, Iran.","DOI":"10.1109\/ISTEL.2016.7881800"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"101895","DOI":"10.1016\/j.cose.2020.101895","article-title":"Multiclass malware classification via first-and second-order texture statistics","volume":"97","author":"Verma","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"2965","DOI":"10.1109\/TIFS.2018.2833292","article-title":"Statistical estimation of malware detection metrics in the absence of ground truth","volume":"13","author":"Du","year":"2018","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_25","unstructured":"Bijitha, C.V., Sukumaran, R., and Nath, H.V. (2020). Secure Knowledge Management in Artificial Intelligence Era: 8th International Conference, SKM 2019, Goa, India, 21\u201322 December 2019, Springer. Proceedings 8."},{"key":"ref_26","unstructured":"Bello, A., and Maurushat, A. (2023). Cybersecurity Issues, Challenges, and Solutions in the Business World, IGI Global."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"107052","DOI":"10.1016\/j.jbankfin.2023.107052","article-title":"Salience theory and cryptocurrency returns","volume":"159","author":"Cai","year":"2024","journal-title":"J. Bank. Financ."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3514229","article-title":"A survey on ransomware: Evolution, taxonomy, and defense solutions","volume":"54","author":"Oz","year":"2022","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"100178","DOI":"10.1109\/ACCESS.2022.3207757","article-title":"An analysis of conti ransomware leaked source codes","volume":"10","author":"Alzahrani","year":"2022","journal-title":"IEEE Access"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1007\/s10664-021-10064-8","article-title":"Omni: Automated ensemble with unexpected models against adversarial evasion attack","volume":"27","author":"Shu","year":"2022","journal-title":"Empir. Softw. Eng."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"1309","DOI":"10.1016\/j.egyr.2021.11.272","article-title":"Augmenting Zero Trust Network Architecture to enhance security in virtual power plants","volume":"8","author":"Alagappan","year":"2022","journal-title":"Energy Rep."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Whyte, C., and Mazanec, B. (2023). Understanding Cyber-Warfare: Politics, Policy and Strategy, Routledge.","DOI":"10.4324\/9781003246398"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"144925","DOI":"10.1109\/ACCESS.2019.2945839","article-title":"A survey on detection techniques for cryptographic ransomware","volume":"7","author":"Berrueta","year":"2019","journal-title":"IEEE Access"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"116198","DOI":"10.1016\/j.eswa.2021.116198","article-title":"The rise of ransomware: Forensic analysis for windows based ransomware attacks","volume":"190","author":"Kara","year":"2022","journal-title":"Expert Syst. Appl."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"64","DOI":"10.1049\/ise2.12042","article-title":"Inhibiting crypto-ransomware on windows platforms through a honeyfile-based approach with R-Locker","volume":"16","year":"2022","journal-title":"IET Inf. Secur."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Almomani, I., Alkhayer, A., and El-Shafai, W. (2022). A crypto-steganography approach for hiding ransomware within HEVC streams in android IoT devices. Sensors, 22.","DOI":"10.3390\/s22062281"},{"key":"ref_37","first-page":"11","article-title":"An inception V3 approach for malware classification using machine learning and transfer learning","volume":"4","author":"Ahmed","year":"2023","journal-title":"Int. J. Intell. Netw."},{"key":"ref_38","first-page":"103402","article-title":"A multi-view feature fusion approach for effective malware classification using Deep Learning","volume":"72","author":"Chaganti","year":"2023","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Eren, M.E., Bhattarai, M., Rasmussen, K., Alexandrov, B.S., and Nicholas, C. (2023, January 2\u20133). MalwareDNA: Simultaneous Classification of Malware, Malware Families, and Novel Malware. Proceedings of the 2023 IEEE International Conference on Intelligence and Security Informatics (ISI), Charlotte, NC, USA.","DOI":"10.1109\/ISI58743.2023.10297217"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Marques, A.B., Branco, V., Costa, R., and Costa, N. (2022, January 3\u20135). Data Visualization in Hybrid Space\u2014Constraints and Opportunities for Design. Proceedings of the International Conference on Design and Digital Communication, Barcelos, Portugal.","DOI":"10.1007\/978-3-031-20364-0_1"},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Rimon, S.I., and Haque, M.M. (2022, January 27\u201328). Malware Detection and Classification Using Hybrid Machine Learning Algorithm. Proceedings of the International Conference on Intelligent Computing & Optimization, Hua Hin, Thailand.","DOI":"10.1007\/978-3-031-19958-5_39"},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"297","DOI":"10.1007\/s11416-022-00416-3","article-title":"ConRec: Malware classification using convolutional recurrence","volume":"18","author":"Mallik","year":"2022","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"108744","DOI":"10.1016\/j.asoc.2022.108744","article-title":"Behavior-based ransomware classification: A particle swarm optimization wrapper-based approach for feature selection","volume":"121","author":"Abbasi","year":"2022","journal-title":"Appl. Soft Comput."},{"key":"ref_44","first-page":"221","article-title":"Malware Visualization and Similarity via Tracking Binary Execution Path","volume":"29","author":"Kim","year":"2022","journal-title":"Teh. Vjesn."},{"key":"ref_45","unstructured":"Saxe, J., and Sanders, H. (2018). Malware Data Science: Attack Detection and Attribution, No Starch Press."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"349","DOI":"10.1016\/j.future.2022.08.002","article-title":"PMMSA: Security analysis system for android wearable applications based on permission matching and malware similarity analysis","volume":"137","author":"Kong","year":"2022","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_47","unstructured":"Mudgil, P., Gupta, P., Mathur, I., and Joshi, N. Proceedings of the International Conference on Innovative Computing and Communications: Proceedings of ICICC 2022, Springer Nature."},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Abbas, A.R., Mahdi, B.S., and Fadhil, O.Y. (2022). Breast and lung anticancer peptides classification using N-Grams and ensemble learning techniques. Big Data Cogn. Comput., 6.","DOI":"10.3390\/bdcc6020040"},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"114551","DOI":"10.1016\/j.eswa.2020.114551","article-title":"Algorithmically generated malicious domain names detection based on n-grams features","volume":"170","author":"Cucchiarelli","year":"2021","journal-title":"Expert Syst. Appl."},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"2480","DOI":"10.1109\/TNSM.2020.3024225","article-title":"Experimental review of neural-based approaches for network intrusion management","volume":"17","author":"Galatro","year":"2020","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"4197","DOI":"10.1109\/TNSM.2021.3120804","article-title":"Network abnormal traffic detection model based on semi-supervised deep reinforcement learning","volume":"18","author":"Dong","year":"2021","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Pelletier, C., Webb, G.I., and Petitjean, F. (August, January 28). Deep learning for the classification of Sentinel-2 image time series. Proceedings of the IGARSS 2019-2019 IEEE International Geoscience and Remote Sensing Symposium, Yokohama, Japan.","DOI":"10.1109\/IGARSS.2019.8900123"}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/15\/1\/46\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T13:46:23Z","timestamp":1760103983000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/15\/1\/46"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,1,14]]},"references-count":52,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2024,1]]}},"alternative-id":["info15010046"],"URL":"https:\/\/doi.org\/10.3390\/info15010046","relation":{},"ISSN":["2078-2489"],"issn-type":[{"value":"2078-2489","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,1,14]]}}}