Analyzing early indicators of ransomware: pre-encryption behavior patterns

Mujeeb ur Rehman*, M. Fadzil Hassan, Rehan Akbar, Bander Ali Saleh Al-rimy, K. S. Savita, Rafi Ullah, Zymul Zafar

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Ransomware attacks are a growing threat, impacting individuals, businesses, and organizations globally. Understanding the tactics used by ransomware operators in the pre-encryption phase is essential for developing effective defenses. This research investigates the pre-encryption tactics, techniques, and procedures (TTPs) employed by attackers before they encrypted data. Through a comprehensive analysis of real-world incidents and malware samples, the study identifies common attack patterns across various stages of the attack lifecycle, including initial access, reconnaissance, privilege escalation, and lateral movement. By studying these patterns, organizations can enhance their threat intelligence and strengthen their defenses. The research introduces a heuristic-based pre-encryption ransomware detection (HB-PERD) method, leveraging machine learning to improve detection rates and reduce false positives and negatives. This approach offers valuable insights for cybersecurity professionals, incident responders, and policymakers to implement proactive measures and reinforce access controls, ultimately aiding in the defense against evolving ransomware threats.

Original languageEnglish
Title of host publicationProceedings of the International Conference on Smart Cities - Volume 2 - ICSC 2024
EditorsHisham Mohamad, Mohd Hilmi Hasan, Said Jadid Abdulkadir, Nasir Shafiq
PublisherSpringer Nature
Pages566-578
Number of pages13
ISBN (Electronic)9789819658480
ISBN (Print)9789819658473, 9789819658503
DOIs
Publication statusPublished - 26 Jul 2025
Event1st International Conference on Smart Cities, ICSC 2024 - Kota Kinabalu, Malaysia
Duration: 10 Sept 202411 Sept 2024

Publication series

NameLecture Notes in Electrical Engineering
Volume1417
ISSN (Print)1876-1100
ISSN (Electronic)1876-1119

Conference

Conference1st International Conference on Smart Cities, ICSC 2024
Country/TerritoryMalaysia
CityKota Kinabalu
Period10/09/2411/09/24

Keywords

  • Cybersecurity
  • Heuristic Approach
  • Machine Learning
  • Pre-Encryption
  • Prediction
  • Ransomware Detection

Fingerprint

Dive into the research topics of 'Analyzing early indicators of ransomware: pre-encryption behavior patterns'. Together they form a unique fingerprint.

Cite this