MARATTO

article

Ransomware File System Behavior Patterns for Improved Cybersecurity Defense

Abstract

Ransomware remains one of the most destructive cybersecurity threats, driven by its high success rate and increasing sophistication. Conventional detection approaches—such as static and signature-based analysis—often fail to identify novel or obfuscated variants. To address these limitations, this study presents an in-depth behavioral analysis of ransomware at the file system level. A corpus of 500 ransomware samples was executed in a controlled sandbox environment, yielding 334 functionally active instances. Detailed API-level traces related to file access, modification, encryption, and deletion were extracted and analyzed, resulting in dataset containing 48 distinct file-related API types. These traces were used to characterize ransomware behavior across five key operational stages: discovery, access, modification, obfuscation, and destruction. Through statistical profiling, co-occurrence analysis, and unsupervised clustering, we identified consistent operational patterns and distinct behavioral archetypes. This work provides both a publicly available dataset and a comprehensive analytical framework, offering actionable insights for behavior-based ransomware detection, forensic investigations, and real-time threat mitigation. The findings also lay the groundwork for cross-platform behavioral comparisons, temporal activity tracking, and the development of adaptive machine learning-based detection models.

Research topics

  • Advanced Malware Detection Techniques
  • Digital and Cyber Forensics
  • Cybercrime and Law Enforcement Studies

Sustainable Development Goals

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1109/iconat66879.2025.11362732

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.