Ransomware Detection with Machine Learning: Techniques, Challenges, and Future Directions - A Systematic Review
Ransomware Detection with Machine Learning: Techniques, Challenges, and Future Directions - A Systematic Review
Jonathan Ismael Zapata Sandoval,Elian Garcés,Walter Fuertes
2025 · DOI: 10.58346/jisis.2025.i1.017
Journal of Internet Services and Information Security · 0 Citations
TLDR
It is found that techniques such as hybrid analysis, digital DNA sequencing, and supervised learning, although less frequently, show their potential in ransomware detection, and Dynamic, static, and network traffic analysis are the most used methods.
Abstract
Ransomware attacks are one of the most common and dangerous threats in cybersecurity. It prevents
users from accessing their systems or personal files and extorts them by demanding a ransompayment. This study aims to identify the most effective machine-learning methods and techniquesfor detecting and mitigating ransomware attacks. Furthermore, it seeks to determine which featuresare essential to locate ransomware and which attributes are most effective in achieving this goal. Todo so, we conducted a systematic literature review using the PRISMA methodological guide. Wefocused on selecting only primary empirical studies that will evaluate their effectiveness. The mainfindings revealed that the studies focus on the analysis of existing datasets, followed by API callsand executable file analysis. Dynamic, static, and network traffic analysis are the most used methods.Furthermore, we found that techniques such as hybrid analysis, digital DNA sequencing, andsupervised learning, although less frequently, show their potential in ransomware detection. Thisresearch also indicates the limitations of their application, challenges, and future research directions.The results can be beneficial for researchers to learn about the variety of ransomware detectionmethods to identify ransomware infection at an earlier stage before an attack occurs and develophighly effective solutions.