{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T06:40:35Z","timestamp":1781073635077,"version":"3.54.1"},"reference-count":33,"publisher":"MDPI AG","issue":"21","license":[{"start":{"date-parts":[[2022,11,4]],"date-time":"2022-11-04T00:00:00Z","timestamp":1667520000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"the Deanship of Scientific Research at Prince Sattam Bin Abdulaziz University under the research project","award":["2021\/01\/17623"],"award-info":[{"award-number":["2021\/01\/17623"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Remote healthcare systems and applications are being enabled via the Internet of Medical Things (IoMT), which is an automated system that facilitates the critical and emergency healthcare services in urban areas, in addition to, bridges the isolated rural communities for various healthcare services. Researchers and developers are, to date, considering the majority of the technological aspects and critical issues around the IoMT, e.g., security vulnerabilities and other cybercrimes. One of such major challenges IoMT has to face is widespread ransomware attacks; a malicious malware that encrypts the patients\u2019 critical data, restricts access to IoMT devices or entirely disable IoMT devices, or uses several combinations to compromise the overall system functionality, mainly for ransom. These ransomware attacks would have several devastating consequences, such as loss of life-threatening data and system functionality, ceasing emergency and life-saving services, wastage of several vital resources etc. This paper presents a ransomware analysis and identification architecture with the objective to detect and validate the ransomware attacks and to evaluate its accuracy using a comprehensive verification process. We first develop a comprehensive experimental environment, to simulate a real-time IoMT network, for experimenting various types of ransomware attacks. Following, we construct a comprehensive set of ransomware attacks and analyze their effects over an IoMT network devices. Furthermore, we develop an effective detection filter for detecting various ransomware attacks (e.g., static and dynamic attacks) and evaluate the degree of damages caused to the IoMT network devices. In addition, we develop a defense system to block the ransomware attacks and notify the backend control system. To evaluate the effectiveness of the proposed framework, we experimented our architecture with 194 various samples of malware and 46 variants, with a duration of sixty minutes for each sample, and thoroughly examined the network traffic data for malicious behaviors. The evaluation results show more than 95% of accuracy of detecting various ransomware attacks.<\/jats:p>","DOI":"10.3390\/s22218516","type":"journal-article","created":{"date-parts":[[2022,11,7]],"date-time":"2022-11-07T03:02:22Z","timestamp":1667790142000},"page":"8516","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":25,"title":["An Effective Self-Configurable Ransomware Prevention Technique for IoMT"],"prefix":"10.3390","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7672-1187","authenticated-orcid":false,"given":"Usman","family":"Tariq","sequence":"first","affiliation":[{"name":"Department of Management Information Systems, CoBA, Prince Sattam bin Abdulaziz University, Al-Khraj 16278, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8188-2601","authenticated-orcid":false,"given":"Imdad","family":"Ullah","sequence":"additional","affiliation":[{"name":"College of Computer Engineering and Sciences, Prince Sattam bin Abdulaziz University, Al-Khraj 16278, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohammed","family":"Yousuf Uddin","sequence":"additional","affiliation":[{"name":"College of Computer Engineering and Sciences, Prince Sattam bin Abdulaziz University, Al-Khraj 16278, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6295-7014","authenticated-orcid":false,"given":"Se Jin","family":"Kwon","sequence":"additional","affiliation":[{"name":"Department of AI Software, Kangwon National University, Samcheok 25913, Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,11,4]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"13345","DOI":"10.1007\/s10489-021-03078-8","article-title":"A framework to evaluate the barriers for adopting the internet of medical things using the extended generalized TODIM method under the hesitant fuzzy environment","volume":"52","author":"Alattas","year":"2022","journal-title":"Appl. Intell."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Zikria, Y.B., Afzal, M.K., and Kim, S.W. (2020). Internet of multimedia things (IoMT): Opportunities, challenges and solutions. Sensors, 20.","DOI":"10.3390\/s20082334"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Manickam, P., Mariappan, S.A., Murugesan, S.M., Hansda, S., Kaushik, A., Shinde, R., and Thipperudraswamy, S. (2022). Artificial Intelligence (AI) and Internet of Medical Things (IoMT) Assisted Biomedical Systems for Intelligent Healthcare. Biosensors, 12.","DOI":"10.3390\/bios12080562"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Pelekoudas-Oikonomou, F., Zachos, G., Papaioannou, M., de Ree, M., Ribeiro, J.C., Mantas, G., and Rodriguez, J. (2022). Blockchain-based security mechanisms for IoMT Edge networks in IoMT-based healthcare monitoring systems. Sensors, 22.","DOI":"10.3390\/s22072449"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"1969","DOI":"10.1109\/JBHI.2021.3101686","article-title":"An intrusion detection mechanism for secured IoMT framework based on swarm-neural network","volume":"26","author":"Nandy","year":"2021","journal-title":"IEEE J. Biomed. Health Inform."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"421","DOI":"10.1049\/cmu2.12301","article-title":"A review on security threats, vulnerabilities, and counter measures of 5G enabled Internet-of-Medical-Things","volume":"16","author":"Hasan","year":"2022","journal-title":"IET Commun."},{"key":"ref_7","unstructured":"(2022, May 31). Record-Breaking DDoS Reportedly Delivered by >145k Hacked Cameras. Available online: https:\/\/arstechnica.com\/information-technology\/2016\/09\/botnet-of-145k-cameras-reportedly-deliver-internets-biggest-ddos-ever\/."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"640","DOI":"10.3390\/jcp2030033","article-title":"Security and Privacy Management in Internet of Medical Things (IoMT): A Synthesis","volume":"2","author":"Hireche","year":"2022","journal-title":"J. Cybersecur. Priv."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Phung, K.A., Kirbas, C., Dereci, L., and Nguyen, T.V. (2022). Pervasive Healthcare Internet of Things: A Survey. Information, 13.","DOI":"10.3390\/info13080360"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Koutras, D., Stergiopoulos, G., Dasaklis, T., Kotzanikolaou, P., Glynos, D., and Douligeris, C. (2020). Security in IoMT communications: A survey. Sensors, 20.","DOI":"10.3390\/s20174828"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3514229","article-title":"A Survey on Ransomware: Evolution, Taxonomy, and Defense Solutions","volume":"54","author":"Oz","year":"2022","journal-title":"ACM Comput. Surv."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Alqahtani, A., and Sheldon, F.T. (2022). A Survey of Crypto Ransomware Attack Detection Methodologies: An Evolving Outlook. Sensors, 22.","DOI":"10.3390\/s22051837"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Lebbie, M., Prabhu, S.R., and Agrawal, A.K. (2022, January 5\u20137). Comparative Analysis of Dynamic Malware Analysis Tools. Proceedings of the International Conference on Paradigms of Communication, Computing and Data Sciences, Virtual.","DOI":"10.1007\/978-981-16-5747-4_31"},{"key":"ref_14","unstructured":"AvePoint (2022, October 15). Ransomware Readiness Checklist | AvePoint. Available online: https:\/\/www.avepoint.com\/ebook\/ransomware-readiness-checklist."},{"key":"ref_15","unstructured":"Mazor, S. (2022, October 15). Ransomware Detection: Techniques and Best Practices. Available online: https:\/\/cloud.netapp.com\/blog\/rps-blg-ransomware-detection-techniques-and-best-practices."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Urooj, U., Al-rimy, B.A.S., Zainal, A., Ghaleb, F.A., and Rassam, M.A. (2021). Ransomware detection using the dynamic analysis and machine learning: A survey and research directions. Appl. Sci., 12.","DOI":"10.3390\/app12010172"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Alrawashdeh, K., and Purdy, C. (2018, January 23\u201326). Ransomware detection using limited precision deep learning structure in fpga. Proceedings of the NAECON 2018-IEEE National Aerospace and Electronics Conference, Dayton, OH, USA.","DOI":"10.1109\/NAECON.2018.8556824"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Al-Hawawreh, M., and Sitnikova, E. (2019, January 12\u201314). Leveraging deep learning models for ransomware detection in the industrial internet of things environment. Proceedings of the 2019 Military Communications and Information Systems Conference (MilCIS), Canberra, ACT, Australia.","DOI":"10.1109\/MilCIS.2019.8930732"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"105","DOI":"10.1016\/j.eij.2020.05.003","article-title":"Internet of things and ransomware: Evolution, mitigation and prevention","volume":"22","author":"Humayun","year":"2021","journal-title":"Egypt. Inform. J."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"1141","DOI":"10.1007\/s12652-017-0558-5","article-title":"Detecting crypto-ransomware in IoT networks based on energy consumption footprint","volume":"9","author":"Azmoodeh","year":"2018","journal-title":"J. Ambient Intell. Humaniz. Comput."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Hatzivasilis, G., Soultatos, O., Ioannidis, S., Verikoukis, C., Demetriou, G., and Tsatsoulis, C. (2019, January 29\u201331). Review of security and privacy for the Internet of Medical Things (IoMT). Proceedings of the 2019 15th International Conference on Distributed Computing in Sensor Systems (DCOSS), Santorini, Greece.","DOI":"10.1109\/DCOSS.2019.00091"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"84352","DOI":"10.1109\/ACCESS.2020.2984376","article-title":"Solutions for mitigating Cybersecurity risks caused by legacy software in medical devices: A scoping review","volume":"8","author":"Tervoort","year":"2020","journal-title":"IEEE Access"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Fernandez Maimo, L., Huertas Celdran, A., Perales Gomez, A.L., Garcia Clemente, F.J., Weimer, J., and Lee, I. (2019). Intelligent and dynamic ransomware spread detection and mitigation in integrated clinical environments. Sensors, 19.","DOI":"10.3390\/s19051114"},{"key":"ref_24","first-page":"2021","article-title":"Two-stage hybrid malware detection using deep learning","volume":"11","author":"Baek","year":"2021","journal-title":"Hum.-Centric Comput. Inf. Sci."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"102659","DOI":"10.1016\/j.cose.2022.102659","article-title":"FeSA: Feature selection architecture for ransomware detection under concept drift","volume":"116","author":"Fernando","year":"2022","journal-title":"Comput. Secur."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"285","DOI":"10.1007\/s11416-021-00414-x","article-title":"A novel approach for ransomware detection based on PE header using graph embedding","volume":"18","author":"Manavi","year":"2022","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"13941","DOI":"10.1007\/s10489-022-03244-6","article-title":"Zero-day Ransomware Attack Detection using Deep Contractive Autoencoder and Voting based Ensemble Classifier","volume":"52","author":"Zahoora","year":"2022","journal-title":"Appl. Intell."},{"key":"ref_28","first-page":"301314","article-title":"RanSAP: An open dataset of ransomware storage access patterns for training machine learning models","volume":"40","author":"Hirano","year":"2022","journal-title":"Forensic Sci. Int. Digit. Investig."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Li, M., Zhang, X., He, Y., and Li, Z. (2022). Defeat Magic with Magic: A Novel Ransomware Attack Method to Dynamically Generate Malicious Payloads Based on PLC Control Logic. Appl. Sci., 12.","DOI":"10.3390\/app12178408"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Yeng, P.K., Fauzi, M.A., Yang, B., and Nimbe, P. (2022). Investigation into Phishing Risk Behaviour among Healthcare Staff. Information, 13.","DOI":"10.2196\/preprints.37393"},{"key":"ref_31","unstructured":"Deslandes, N. (2022, October 15). Internet of Things: Key Stats for 2022\u2014TechInformed. Available online: https:\/\/techinformed.com\/internet-of-things-key-stats-for-2022\/."},{"key":"ref_32","unstructured":"(2022, May 31). Tizen Developers. Available online: https:\/\/developer.tizen.org\/development\/tizen-studio\/download."},{"key":"ref_33","unstructured":"(2022, May 31). Cuckoo Sandbox\u2014Automated Malware Analysis. Available online: https:\/\/cuckoosandbox.org\/."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/21\/8516\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T01:11:03Z","timestamp":1760145063000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/21\/8516"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,4]]},"references-count":33,"journal-issue":{"issue":"21","published-online":{"date-parts":[[2022,11]]}},"alternative-id":["s22218516"],"URL":"https:\/\/doi.org\/10.3390\/s22218516","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,11,4]]}}}