Open Access

A Survey on Ransomware Detection and Prevention Using Machine Learning Models

4 Assistant Professor, Computer Engineering, Sankalchand Patel College of Engineering, Sankalchand Patel University, Visnagar, India

Abstract

Ransomware is one of the most serious cyber-security threats to both individuals and organizations, causing fairly serious financial losses and operational disruption. Ransomware attacks are getting increasingly sophisticated, making it more difficult for traditional signature-based security mechanisms to work effectively, which is why intelligent detection and prevention are needed. The predominant approach used for the detection of ransomware is via pattern recognition and behavior analysis, which is the domain of machine learning. This work provides an in-depth analysis of ransomware, its variants, attack cycles, and the idea of ransomware-as-a-service (RaaS). Furthermore, it discusses both traditional and deep learning approaches to ransomware detection, such as Decision Tree (DT), Random Forest (RF), Support Vector Machine (SVM), K-Nearest Neighbors (KNN), Logistic Regression (LR), Deep Neural Networks (DNN), Convolutional Neural Networks (CNN), and Long Short-Term Memory (LSTM) networks. Further, traditional and AI-based ransomware prevention methods, recovery procedures, and a comparative review of recent papers are discussed to identify the existing challenges and potential research directions in ransomware detection and prevention using machine learning.

Keywords

References

V. Rohilla, K. Rohilla, P. Kumar, and N. Jain, “Intrusion Detection in Network Traffic Using Feature Selection and Optuna-Based Machine Learning Optimization,” in 2026 3rd International Conference on Research Methodologies in Knowledge Management, Artificial Intelligence and Telecommunication Engineering (RMKMATE), Chennai, India: IEEE, Apr. 2026, pp. 1–6. doi: 10.1109/RMKMATE69073.2026.11518834.
Monika, P. Zavarsky, and D. Lindskog, “Experimental Analysis of Ransomware on Windows and Android Platforms: Evolution and Characterization,” Procedia Comput. Sci., vol. 94, pp. 465–472, 2016, doi: 10.1016/j.procs.2016.08.072.
U. Urooj, B. A. S. Al-rimy, A. Zainal, F. A. Ghaleb, and M. A. Rassam, “Ransomware Detection Using the Dynamic Analysis and Machine Learning: A Survey and Research Directions,” Appl. Sci., vol. 12, no. 1, 2022, doi: 10.3390/app12010172.
J. A. Abraham and S. M. George, “A Survey on Preventing Crypto Ransomware Using Machine Learning,” in 2019 2nd International Conference on Intelligent Computing, Instrumentation and Control Technologies (ICICICT), IEEE, Jul. 2019, pp. 259–263. doi: 10.1109/ICICICT46008.2019.8993137.
V. Pahuja, A. Khanna, and I. Sharma, “RansomSheild: Novel Framework for Effective Data Recovery in Ransomware Recovery Process,” in 2024 IEEE International Conference on Big Data & Machine Learning (ICBDML), IEEE, Feb. 2024, pp. 240–245. doi: 10.1109/ICBDML60909.2024.10577365.
M. Aljabri et al., “Ransomware detection based on machine learning using memory features,” Egypt. Informatics J., vol. 25, p. 100445, Mar. 2024, doi: 10.1016/j.eij.2024.100445.
R. E. Asma A.Alhashmi, Abdulbasit A. Darem, Ahmed B. Alshammari, Laith A. Darem, Huda K. Sheatah, “Ransomware Early Detection Techniques,” Eng. Technol. Appl. Sci., vol. 14, no. 3, pp. 14497–14503, 2024.
M. Cen, F. Jiang, X. Qin, Q. Jiang, and R. Doss, “Ransomware early detection: A survey,” Comput. Networks, vol. 239, p. 110138, Feb. 2024, doi: 10.1016/j.comnet.2023.110138.
R. T. Da-Yu KAO , Shou-Ching HSIO, “Analyzing WannaCry Ransomware Considering the Weapons and Exploits,” ICACT Trans. Adv. Commun. Technol., vol. 7, no. 2, pp. 1098–1108, 2018.
A. Zimba, L. Simukonda, and M. Chishimba, “Demystifying Ransomware Attacks: Reverse Engineering and Dynamic Malware Analysis of WannaCry for Network and Information Security,” Zambia ICT J., vol. 1, no. 1, pp. 35–40, Dec. 2017, doi: 10.33260/zictjournal.v1i1.19.
M. S. Hosain, “Ransomware: Are We Safe on the Web?,” Inf. Secur. Technol., vol. 1, no. 103, pp. 1–9, 2022.
S. C. Pallaprolu, “Zero-day Attack Identification in Streaming Data: Nearest Neighbor Heuristics and Dynamic Semantic Network Generation in the Spark Eco-system,” University of Maryland, Baltimore County, 2017.
G. Nagar, “The evolution of ransomware: tactics, techniques, and mitigation strategies,” Int. J. Sci. Res. Manag., vol. 12, pp. 1282--1298, 2024.
S. P.Sivashanmugam, S. Kumara, A. Mohile, and D. R. Suram, “Improving Detection Accuracy of Phishing Attacks with Feature Selection and Machine learning Techniques in Cybersecurity,” in 2026 1st International Conference on Emerging Trends in Advancements and Applications of Computational Intelligence Techniques (ETAACT), Bhubaneswar, India: IEEE, Apr. 2026, pp. 1–6. doi: 10.1109/ETAACT69135.2026.11542138.
M. Najafabadi, F. Villanustre, T. Khoshgoftaar, N. Seliya, R. Wald, and E. Muharemagic, “Deep learning applications and challenges in big data analytics,” J. Big Data, vol. 2, 2015, doi: 10.1186/s40537-014-0007-7.
S. Debnath, S. A. Devanira Poovaiah, N. Khurramov, S. A. Chikop, and S. Sadullaeva, “KEDenNet-MEO: A Knowledge-Driven Deep Intrusion Detection Framework for VANETs with Realistic Mobility Simulation,” in 2025 International Conference on Innovations in Intelligent Systems: Advancements in Computing, Communication, and Cybersecurity (ISAC3), IEEE, Jul. 2025, pp. 1–6. doi: 10.1109/ISAC364032.2025.11156856.
J. Ferdous, R. Islam, A. Mahboubi, and M. Zahidul Islam, “AI-Based Ransomware Detection: A Comprehensive Review,” IEEE Access, vol. 12, pp. 136666–136695, 2024, doi: 10.1109/ACCESS.2024.3461965.
R. Soni, A. Kumar, A. Vashisth, and G. Kaur, “Next-Generation AI-Driven Ransomware Detection: Trends, Taxonomy, and Their Limitations,” in 2026 3rd International Conference on Emerging Trends in Engineering and Medical Sciences (ICETEMS), 2026, pp. 1–6. doi: 10.1109/ICETEMS66917.2026.11469261.
A. Azmoodeh, A. Dehghantanha, M. Conti, and K.-K. R. Choo, “Detecting crypto-ransomware in IoT networks based on energy consumption footprint,” J. Ambient Intell. Humaniz. Comput., vol. 9, no. 4, pp. 1141–1152, 2018, doi: 10.1007/s12652-017-0558-5.
M. Mittal, “Quantum Machine Learning: Harnessing Quantum Algorithms for Supervised and Unsupervised Learning,” Int. J. Innov. Res. Sci. Eng. Technol., vol. 11, no. 09, Sep. 2022, doi: 10.15680/IJIRSET.2022.1109004.
A. Alraizza and A. Algarni, “Ransomware Detection Using Machine Learning: A Survey,” Big Data Cogn. Comput., vol. 7, no. 3, p. 143, Aug. 2023, doi: 10.3390/bdcc7030143.
M. S. Akhtar and T. Feng, “Detection of Malware by Deep Learning as CNN-LSTM Machine Learning Techniques in Real Time,” Symmetry (Basel)., vol. 14, no. 11, 2022, doi: 10.3390/sym14112308.
S. Kakkar, S. Janarthanan, B. Makkena, and A. Kakkar, “Deep Learning Approaches for Predicting Attack Vulnerabilities in Quantum-Secure Financial Networks,” in 2026 International Conference on Emerging Systems and Intelligent Computing (ESIC), IEEE, Feb. 2026, pp. 780–785. doi: 10.1109/ESIC68176.2026.11496277.
M. Davidian, M. Kiperberg, and N. Vanetik, “Early Ransomware Detection with Deep Learning Models,” Futur. Internet, vol. 16, no. 8, 2024, doi: 10.3390/fi16080291.
T. Jabid et al., “Pre-Print Ransomware Prevention Strategies: Building Robust Cyber Defenses,” 2025.
K. S. Anjani Gupta, “Malware Analysis on AI Technique,” 2022.
M. Jabid, Taskeed and Rashid, Mohammad Rifat Ahmmad and Ferdaus, Md Hasanul and Ali, Md Sawkat and Islam, Mohammad Manzurul and Hasan, Mahamudul and Islam, “Ransomware prevention strategies: Building robust cyber defenses,” Ransomware Evol., pp. 141–171, 2024.
K. J. Hole, “Robustness to Malware Reinfections,” in Anti-fragile ICT Systems, Cham: Springer International Publishing, 2016, pp. 93–98. doi: 10.1007/978-3-319-30070-2_9.
D. P. Marius-Constantin Ilau, Adriam Baldwin, Tristan Caulfield, “Modelling and simulating organizational ransomware recovery: structure, methodology, and decisions,” J. Cybersecurity, vol. 11, no. 1, p. 45, 2025.
D. Manivannan, “A Comprehensive and Critical Analysis of Ransomware Detection, Prevention, Mitigation, and Recovery Approaches,” J. Cybersecurity, vol. 8, p. 397, 2026.
R. Kakadiya, K. Vora, A. Bambharoliya, and H. Kag, “AI-Driven Cyber Defense for Malware and Ransomware Protection,” in 2026 18th International Conference on Electronics, Computers and Artificial Intelligence (ECAI), IEEE, Jul. 2026, pp. 1–7. doi: 10.1109/ECAI69016.2026.11613710.
V. S. Vivek, V. Lokesh, T. Kaushik, U. Kumaran, B. Umah, and G. G. Devarajan, “Ransome Ware Detection Using Machine Learning and Deep Learning Models,” in Proceedings of International Conference on Recent Trends in Computing, R. P. Mahapatra, S. Roy, and P. Parwekar, Eds., Singapore: Springer Nature Singapore, 2025, pp. 105–117.
M. Rele, J. Samuel, D. Patil, and U. Krishnan, “Exploring Ransomware Detection Based on Artificial Intelligence and Machine Learning,” Procedia Comput. Sci., vol. 252, pp. 548–556, 2025, doi: 10.1016/j.procs.2025.01.014.
W. F. Elsersy, A. ElShamy, and M. Samy, “Ransomware Detection Using Machine Learning Algorithms,” in 2024 Intelligent Methods, Systems, and Applications (IMSA), IEEE, Jul. 2024, pp. 186–192. doi: 10.1109/IMSA61967.2024.10652659.

Similar Articles

21-30 of 39

You may also start an advanced similarity search for this article.