TY - GEN
T1 - Ransomware Detection Using Executable Header Features and Machine Learning Techniques
AU - Monsalve Obregon, Valeria A.
AU - Rios Diaz, Jean P.
AU - Torres Paredes, Carlos M.
N1 - Publisher Copyright:
© 2025 Copyright held by the owner/author(s).
PY - 2025/11/22
Y1 - 2025/11/22
N2 - This study presents a machine learning-based approach for ransomware detection through the header feature of executable files. A dataset was constructed consisting of 2,497 samples, including 962 benign files and 1,535 ransomware samples belonging to 19 active families identified since 2020. The samples were collected from specialized sources and processed within a controlled virtual environment, ensuring safe conditions throughout the analysis. Various internal features were extracted from the samples and subsequently subjected to preparation, cleaning, and balancing procedures to ensure proper interpretation by the predictive models. Four widely used classification algorithms were trained: LightGBM, XGBoost, Random Forest, and MLP. After hyperparameter tuning and stratified cross-validation, each model's performance was evaluated using standard metrics such as precision, recall, and F1-score. The results showed outstanding performance from Random Forest and XGBoost, both achieving an F1-score close to 97.68%, followed closely by LightGBM. The MLP model yielded slightly lower, yet acceptable, performance. These findings confirm that static analysis, combined with machine learning techniques, is an effective alternative for detecting ransomware, enabling the accurate identification of malicious files without executing them.
AB - This study presents a machine learning-based approach for ransomware detection through the header feature of executable files. A dataset was constructed consisting of 2,497 samples, including 962 benign files and 1,535 ransomware samples belonging to 19 active families identified since 2020. The samples were collected from specialized sources and processed within a controlled virtual environment, ensuring safe conditions throughout the analysis. Various internal features were extracted from the samples and subsequently subjected to preparation, cleaning, and balancing procedures to ensure proper interpretation by the predictive models. Four widely used classification algorithms were trained: LightGBM, XGBoost, Random Forest, and MLP. After hyperparameter tuning and stratified cross-validation, each model's performance was evaluated using standard metrics such as precision, recall, and F1-score. The results showed outstanding performance from Random Forest and XGBoost, both achieving an F1-score close to 97.68%, followed closely by LightGBM. The MLP model yielded slightly lower, yet acceptable, performance. These findings confirm that static analysis, combined with machine learning techniques, is an effective alternative for detecting ransomware, enabling the accurate identification of malicious files without executing them.
KW - Cybersecurity
KW - File Structure
KW - Machine learning
KW - Malware detection
KW - Portable Executable
KW - Ransomware
UR - https://www.scopus.com/pages/publications/105025368292
U2 - 10.1145/3771678.3771690
DO - 10.1145/3771678.3771690
M3 - Articulo (Contribución a conferencia)
AN - SCOPUS:105025368292
T3 - Proceedings of 8th International Conference on Systems Engineering - Cybersecurity and AI: Building a reliable digital future, CIIS 2025
SP - 87
EP - 97
BT - Proceedings of 8th International Conference on Systems Engineering - Cybersecurity and AI
PB - Association for Computing Machinery, Inc
T2 - 8th International Conference on Systems Engineering, CIIS 2025
Y2 - 1 October 2025 through 3 October 2025
ER -