Skip to main navigation Skip to search Skip to main content

Ransomware Detection Using Executable Header Features and Machine Learning Techniques

Research output: Chapter in Book/Report/Conference proceedingPaper (Conference contribution)peer-review

Abstract

This study presents a machine learning-based approach for ransomware detection through the header feature of executable files. A dataset was constructed consisting of 2,497 samples, including 962 benign files and 1,535 ransomware samples belonging to 19 active families identified since 2020. The samples were collected from specialized sources and processed within a controlled virtual environment, ensuring safe conditions throughout the analysis. Various internal features were extracted from the samples and subsequently subjected to preparation, cleaning, and balancing procedures to ensure proper interpretation by the predictive models. Four widely used classification algorithms were trained: LightGBM, XGBoost, Random Forest, and MLP. After hyperparameter tuning and stratified cross-validation, each model's performance was evaluated using standard metrics such as precision, recall, and F1-score. The results showed outstanding performance from Random Forest and XGBoost, both achieving an F1-score close to 97.68%, followed closely by LightGBM. The MLP model yielded slightly lower, yet acceptable, performance. These findings confirm that static analysis, combined with machine learning techniques, is an effective alternative for detecting ransomware, enabling the accurate identification of malicious files without executing them.

Original languageEnglish
Title of host publicationProceedings of 8th International Conference on Systems Engineering - Cybersecurity and AI
Subtitle of host publicationBuilding a reliable digital future, CIIS 2025
PublisherAssociation for Computing Machinery, Inc
Pages87-97
Number of pages11
ISBN (Electronic)9798400718809
DOIs
StatePublished - 22 Nov 2025
Event8th International Conference on Systems Engineering, CIIS 2025 - Hybrid, Lima, Peru
Duration: 1 Oct 20253 Oct 2025

Publication series

NameProceedings of 8th International Conference on Systems Engineering - Cybersecurity and AI: Building a reliable digital future, CIIS 2025

Conference

Conference8th International Conference on Systems Engineering, CIIS 2025
Country/TerritoryPeru
CityHybrid, Lima
Period1/10/253/10/25

Keywords

  • Cybersecurity
  • File Structure
  • Machine learning
  • Malware detection
  • Portable Executable
  • Ransomware

Fingerprint

Dive into the research topics of 'Ransomware Detection Using Executable Header Features and Machine Learning Techniques'. Together they form a unique fingerprint.

Cite this