0% found this document useful (0 votes)
2 views5 pages

Dynamic Ransomware Detection Using Time-Based API

This study presents a machine learning approach for dynamic ransomware detection using a Random Forest classifier that analyzes API call data to differentiate between benign and malicious software. The system achieves over 95% accuracy by focusing on behavioral dynamics rather than static signatures, making it resilient against obfuscation techniques. Deployed as a Flask-based web application, it provides real-time classification and a user-friendly interface for cybersecurity professionals.

Uploaded by

22wj1a05b6
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views5 pages

Dynamic Ransomware Detection Using Time-Based API

This study presents a machine learning approach for dynamic ransomware detection using a Random Forest classifier that analyzes API call data to differentiate between benign and malicious software. The system achieves over 95% accuracy by focusing on behavioral dynamics rather than static signatures, making it resilient against obfuscation techniques. Deployed as a Flask-based web application, it provides real-time classification and a user-friendly interface for cybersecurity professionals.

Uploaded by

22wj1a05b6
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

International Journal of Scientific Research in Engineering and Management (IJSREM)

Volume: 10 Issue: 03 | March - 2026 SJIF Rating: 8.659 ISSN: 2582-3930

Dynamic Ransomware Detection Using Time-Based API

Jatin Choudhary, Department of Computer Science and Engineering, GNITC, siyagjatin@[Link]

K. Sankeerthana, Department of Computer Science and Engineering, GNITC, 22wj1a05d2@[Link]

Rajashree Sutrawe, Department of Computer Science and Engineering, Assistant Professor, GNITC,
[Link]@[Link]

---------------------------------------------------------------------***---------------------------------------------------------------------
Abstract to input feature data and receive real-time classification
Ransomware attacks are increasingly sophisticated, results.
evading traditional signature-based detection. This study By combining ensemble learning with behavioral
proposes a machine learning approach using API call data analysis, the system delivers a scalable, adaptive
to analyze dynamic program behavior. A Random Forest framework for early ransomware detection, strengthening
classifier processes features from temporal intervals, API cybersecurity resilience against continuously evolving
call frequencies, and sequential patterns to distinguish threats
ransomware from benign software.
The model achieves over 95% accuracy by capturing 2. LITERATURE REVIEW
behavioral dynamics rather than static signatures, making Ransomware detection has increasingly shifted toward
it resilient against obfuscation techniques. Integrated into behavioral and dynamic analysis approaches. Roohi
a Flask-based web application, it enables real-time, (2023) demonstrates that API call sequences and system
interactive detection. interactions effectively identify obfuscated and unknown
Key strengths include scalability, handling high- ransomware variants through machine learning classifiers
dimensional data, and ensemble learning robustness. By including Random Forest and Support Vector Machines.
focusing on behavioral analysis, this approach effectively Song (2023) reinforces this by showing that Windows
identifies evolving ransomware variants, offering API call frequency and sequence patterns, processed
cybersecurity professionals a practical, automated tool for through Random Forest models, achieve high precision
early threat detection and mitigation. even when code obfuscation is present. Singh (2024)
further advances this by incorporating temporal features
[Link] such as inter-call intervals and frequency distributions,
Ransomware has emerged as a critical cybersecurity demonstrating that temporal analysis significantly
threat, targeting individuals and organizations by improves ransomware classification accuracy.
encrypting data and demanding ransom. Advanced
variants employ polymorphism, encryption, and dynamic Zuba (2024) compares Random Forest against deep
execution to evade traditional signature-based detection, learning models, concluding that Random Forest offers
necessitating smarter, behavior-driven approaches. comparable accuracy with faster training and inference,
Dynamic analysis through API call monitoring offers a making it ideal for real-time deployment. Al-Mohannadi
promising detection foundation. API call patterns reveal (2023) validates real-time applicability, showing that
execution flows, exposing ransomware-characteristic ensemble-based monitoring of temporal API patterns
behaviors such as repetitive file encryption, registry enables early ransomware detection before significant
modifications, and abnormal process creation. However, damage occurs.
high dimensionality and temporal complexity make
analysis challenging. Collectively, these studies confirm behavioral, temporal,
This project proposes a Random Forest classifier trained and ensemble-based approaches as robust foundations for
on temporal features extracted from API call sequences, effective ransomware detection.
including time intervals, call frequencies, and sequential
patterns. This enables accurate differentiation between
benign and malicious software. The solution is deployed
as a Flask web application, allowing authenticated users

© 2026, IJSREM | [Link] DOI: 10.55041/IJSREM57715 | Page 1


International Journal of Scientific Research in Engineering and Management (IJSREM)
Volume: 10 Issue: 03 | March - 2026 SJIF Rating: 8.659 ISSN: 2582-3930

3. System Architecture Temporal characteristics including call sequences,


frequency distributions, and inter-call intervals are
The diagram illustrates the ensemble learning mechanism carefully engineered to capture behavioral patterns
of a Random Forest classifier, demonstrating how distinguishing ransomware from legitimate software.
multiple decision trees collaborate to produce accurate These extracted features feed directly into the model
predictions. training component, where a Random Forest Classifier
The process begins by splitting input data into training learns to differentiate malicious from benign behavior.
and testing sets. The training set is divided into multiple The trained model is persistently saved, enabling
subsets — Training Data 1, Training Data 2, through consistent and reliable predictions whenever new inputs
Training Data n — using bootstrapping techniques. Each are submitted by users.
subset trains an independent Decision Tree, resulting in n The Flask-based web interface ties everything together,
individual trees operating in parallel. offering an intuitive front-end built with HTML templates.
Both training and testing data feed into their respective Seamless navigation across registration, login, prediction,
decision trees simultaneously. Each tree independently and result pages is maintained through session-based
analyzes the input features and generates its own access control, ensuring both usability and security remain
classification output. These individual predictions are uncompromised.
then forwarded to the Voting (Aggregating) stage, where At the heart of the system lies the prediction component,
majority voting consolidates all tree outputs. which receives user-submitted feature values, applies
Finally, the aggregated result produces the Prediction, consistent feature scaling matching the training process,
representing the most frequently occurring class across all and invokes the pre-trained model to classify software
trees. This ensemble approach significantly reduces behavior as either ransomware or benign with high
overfitting, improves generalization, and enhances confidence.
classification accuracy — making Random Forest Finally, the result display component communicates
particularly effective for ransomware detection tasks. outcomes clearly and interpretably to users. Accompanied
by appropriate feedback messages and navigation options,
it ensures prediction results are immediately
understandable, allowing users to efficiently continue
their threat assessment workflows without confusion or
disruption.

5. RESULTS AND DISCUSSION

The proposed ransomware detection system, built upon a


Random Forest classifier trained on temporal API call
features, demonstrates strong and reliable performance.
The model achieves an accuracy exceeding 95% in
distinguishing ransomware from benign software,
4. PROPOSED METHODOLOGY validating the effectiveness of behavioral and temporal
The ransomware detection system is built around six well- feature extraction over traditional signature-based
defined functional modules that work collaboratively to methods.
deliver accurate, secure, and user-friendly ransomware The system successfully captures critical behavioral
classification. indicators including API call frequencies, sequential
User authentication forms the foundation of the system, patterns, and inter-call time intervals, enabling accurate
managing registration, login, and logout through Flask- classification even against obfuscated or previously
Login and SQLite integration. Hashed passwords and unseen ransomware variants. The ensemble nature of
session management ensure only authorized users can Random Forest effectively reduces overfitting while
access prediction functionalities, maintaining strict maintaining high generalization across diverse samples.
application security throughout. Integration into the Flask-based web application further
Once authenticated, users interact with the data confirms practical applicability, enabling real-time
preprocessing and feature extraction component, which predictions through an authenticated, user-friendly
converts raw API call logs into structured inputs. interface. Overall, results demonstrate that combining

© 2026, IJSREM | [Link] DOI: 10.55041/IJSREM57715 | Page 2


International Journal of Scientific Research in Engineering and Management (IJSREM)
Volume: 10 Issue: 03 | March - 2026 SJIF Rating: 8.659 ISSN: 2582-3930

temporal dynamic analysis with ensemble machine


learning provides a scalable, efficient, and robust
framework for early ransomware detection and mitigation
in real-world cybersecurity environments.

6. Quantitative Security Analysis

The Random Forest classifier achieved over 95%


accuracy in ransomware classification, with precision and
recall rates confirming minimal false positives and
negatives. The model processed high-dimensional API
call features across temporal intervals, demonstrating a
detection rate superior to traditional signature-based
methods. Ensemble learning across multiple decision
trees reduced misclassification errors, ensuring reliable
threat identification with measurable performance
metrics validating the system's cybersecurity
effectiveness.

[Link]

This project successfully demonstrates the effectiveness


of machine learning, specifically the Random Forest
algorithm, in classifying ransomware through temporal
API call pattern analysis. By extracting meaningful
behavioral features from API sequences, the system
achieves high accuracy in distinguishing ransomware
from benign applications, overcoming limitations of
traditional signature-based detection methods.

The Flask-based web interface enhances practical


usability, providing security professionals and
researchers an interactive, authenticated environment for
© 2026, IJSREM | [Link] DOI: 10.55041/IJSREM57715 | Page 3
International Journal of Scientific Research in Engineering and Management (IJSREM)
Volume: 10 Issue: 03 | March - 2026 SJIF Rating: 8.659 ISSN: 2582-3930

real-time threat classification. The modular architecture Information Solutions Pvt. Ltd, India, Mumbai, 2023, pp.
ensures scalability and efficient prediction workflows, 1–3.
laying a strong foundation for future development.
[8] J. Porter, ‘‘Wolverine part of massive insomniac
Looking ahead, integrating deep learning models, real- games leak afterransomware deadline passes,’’ Verge
time threat monitoring, and enriched dynamic analysis New York City, USA, Tech. Rep.,2023.
features will further strengthen detection capabilities.
Overall, this approach validates behavioral machine [9] B. Yamany, M. S. Elsayed, A. D. Jurcut, N.
learning as a powerful, adaptable strategy for proactive Abdelbaki, and M. A. Azer,‘‘A holistic approach to
ransomware detection, significantly contributing to ransomware classification: Leveraging static and
advancing intelligent and resilient cybersecurity defense dynamic analysis with visualization,’’ Information, vol.
systems. 15, no. 1, p. 46,Jan. 2024.

8. FUTURE SCOPE [10] Y. Wang, Z. Li, and Y. Zhang, ‘‘Optimized


ransomware detection through reverse Bayer analysis of
In the future, This project develops a machine learning file system activities,’’ OSF Preprints, 2024.
system detecting ransomware through temporal API call
pattern analysis. A Random Forest classifier trained on [11] C. Beaman, A. Barkworth, T. D. Akande, S. Hakak,
behavioral features distinguishes benign from malicious and M. K. Khan, ‘‘Ransomware: Recent advances,
software, including unknown variants and zero-day analysis, challenges and future research directions,’’
attacks. Integrated into a secure Flask web application, Comput. Secur., vol. 111, Dec. 2021, Art. no. 102490.
the system delivers real-time classification, scalable [12] H. N. Nguyen, F. Abri, V. Pham, M. Chatterjee, A.
architecture, and a foundation for future enhancements S. Namin, and T. Dang, ‘‘MalView: Interactive visual
including batch processing, real-time monitoring, and analytics for comprehending malware behavior,’’ IEEE
threat intelligence integration. Access, vol. 10, pp. 99909–99930, 2022.
REFERENCES [13] M. Alazab, S. Venkataraman, and P. Watters,
[1] P. O’Kane, S. Sezer, and D. Carlin, ‘‘Evolution of ‘‘Towards understanding malware behaviour by the
ransomware,’’ IET Netw.,vol. 7, no. 5, pp. 321–327, Jun. extraction of API calls,’’ in Proc. 2nd Cybercrime
2018. Trustworthy Comput. Workshop, Jul. 2010, pp. 52–59.

[2] G. O. Gorman and G. McDonald, ‘‘Ransomware : A [14] D. Sgandurra, L. Muñoz-González, R. Mohsen, and
growing menace,’’Symantec, vol. 1, p. 16, Aug. 2012. E. C. Lupu, ‘‘Automated dynamic analysis of
ransomware: Benefits, limitations and use for detection,’’
[3] H. Tuttle, ‘‘Ransomware attacks pose growing 2016, arXiv:1609.03020.
threat,’’ Risk Manage.,vol. 63, no. 4, pp. 4–7, 2016.
[15] T. Munzner, ‘‘Visualization analysis and design-
[4] Threat of Ransomware Remains at Peak With Half of presentation,’’ Vis. Anal. Design, vol. 16, pp. 1–3, Aug.
Organizations FallingVictim in the Last Year, Athena Inf. 2014.
Solutions Pvt. Ltd, India, New Delhi,2023, pp. 1–4.
[16] M. Wagner, A. Rind, N. Thür, and W. Aigner, ‘‘A
[5] P. Chakraborty, ‘‘Ransomware remains major threat knowledge-assisted visual malware analysis system:
as Sophos reports stateof cyber security in 2023,’’ Design, validation, and reflection of KAMAS,’’ Comput.
Gurgaon Athena Information Solutions [Link], India, Secur., vol. 67, pp. 1–15, Jun. 2017.
Tech. Rep., 2023, pp. 2023–2024.
[17] B. C. M. Cappers, P. N. Meessen, S. Etalle, and J. J.
[6] M. Sunidhi, ‘‘Elastic global threat report 2023 reveals Van Wijk, ‘‘Eventpad: Rapid malware analysis and
dominance ofransomware,’’ Athena Information reverse engineering using visual analytics,’’ in Proc.
Solutions Pvt. Ltd, India, Mumbai,Tech. Rep., 2023, pp. IEEE Symp. Vis. Cyber Secur. (VizSec), Oct. 2018, pp.
3–5. 1–8.

[7] CISO Research Reveals 90 % of Organisations [18] M. Wagner, F. Fischer, R. Luh, A. Haberson, A.
Suffered at Least One Major Cyber Attack in the Last Rind, D. A. Keim, and W. Aigner, ‘‘A survey of
Year; 83 % Report Ransomware Payments, Athena visualization systems for malware analysis,’’in Proc.
© 2026, IJSREM | [Link] DOI: 10.55041/IJSREM57715 | Page 4
International Journal of Scientific Research in Engineering and Management (IJSREM)
Volume: 10 Issue: 03 | March - 2026 SJIF Rating: 8.659 ISSN: 2582-3930

Eurograph. Conf. Vis.-State Art Rep., EuroVis-STAR, [29] H. Sistemas. (2019). Virustotal Public API V2.0.
Jan. 2015,pp. 105–125. Accessed: Apr. 7, 2024. [Online]. Available:
[Link]
[19] S. Poudyal, K. P. Subedi, and D. Dasgupta, ‘‘A [30] IPStack API. Accessed: Jul. 5, 2024. [Online].
framework for analyzing ransomware using machine Available: [Link] com/documentation
learning,’’ in Proc. IEEE Symp. Ser. Comput. Intell.
(SSCI), Nov. 2018, pp. 1692–1699. [31] Tshark. Accessed: Apr. 5, 2024. [Online]. Available:
[Link] [Link]/docs/man-pages/[Link]
[20] J. Rafapa and A. Konokix, ‘‘Ransomware detection
using aggregated random forest technique with recent [32] H. Dornhackl, K. Kadletz, R. Luh, and P. Tavolato,
variants,’’ Authorea, pp. 1–8,Aug. 2024. ‘‘Malicious behavior patterns,’’ in Proc. IEEE 8th Int.
Symp. Service Oriented Syst. Eng., Apr. 2014, pp. 384–
[21] S. Razaulla, C. Fachkha, C. Markarian, A. 389.
Gawanmeh, W. Mansoor, B. C. M. Fung, and C. Assi,
‘‘The age of ransomware: A survey on the evolution, [33] A. Singh, R. A. Ikuesan, and H. S. Venter,
taxonomy, and research directions,’’ IEEE Access, vol. ‘‘Ransomware detection using process memory,’’ in
11, pp. 40698–40723, 2023. Proc. Int. Conf. Cyber Warfare Secur., vol. 17, Mar. 2022,
pp. 413–422.
[22] V. Cobilean, H. S. Mavikumbure, B. J. Mcbride, B.
Vaagensmith, V. K. Singh, R. Li, C. Rieger, and M. [34] T. R. Dendere and A. Singh, ‘‘Ransomware
Manic, ‘‘A review of visualization methods for cyber- detection using portable executable imports,’’ in Proc.
physical security: Smart grid case study,’’ IEEE Access, Int. Conf. Cyber Warfare Secur., Mar. 2024, vol. 19, no.
vol. 11, pp. 59788–59803, 2023. 1, pp. 66–74.

[23] G. Richer, A. Pister, M. Abdelaal, J.-D. Fekete, M. [35] J. Ferdous, R. Islam, A. Mahboubi, and M. Z. Islam,
Sedlmair, and D. Weiskopf, ‘‘Scalability in ‘‘AI-based ransomware detection: A comprehensive
visualization,’’ IEEE Trans. Vis. Comput. Graph., vol. review,’’ IEEE Access, vol. 12, pp. 136666–136695,
30, no. 7, pp. 3314–3330, Jul. 2024. 2024.

[24] A. Ulmer, M. Angelini, J.-D. Fekete, J. [36] Corvus Forensics. (2019). Virus Share. Accessed:
Kohlhammer, and T. May, ‘‘A survey on rogressive Apr. 4, 2024. [Online]. Available: [Link]
visualization,’’ IEEE Trans. Vis. Comput. Graph., vol.
30, no. 9, pp. 6447–6467, Sep. 2024. [37] N. Naik, P. Jenkins, N. Savage, L. Yang, T.
Boongoen, N. Iam-On, K. Naik, and J. Song, ‘‘Embedded
[25] A. Singh, A. Ikuesan, and H. Venter, ‘‘A context- YARA rules: Strengthening YARA rules utilizing fuzzy
aware trigger mechanism for ransomware forensics,’’ in hashing and fuzzy rules for malware analysis,’’ Complex
Proc. 14th Int. Conf. Cyber Warfare Secur. (ICCWS), Intell. Syst., vol. 7, no. 2, pp. 687–702, Apr. 2021.
2019, pp. 629–638.
[38] A. Panaras, B. Silverstein, and S. Edwards,
[26] A. Patel and J. Tailor, ‘‘A malicious activity ‘‘Automated cooperative clustering for proactive
monitoring mechanism to detect and prevent ransomware detection and mitigation using machine
ransomware,’’ Comput. Fraud Secur., vol. 2020, no. 1, learning,’’ TechRxiv, pp. 1–9, Sep. 2024.
pp. 14–19, Jan. 2020.
[39] S. Zhang, T. Du, P. Shi, X. Su, and Y. Han, ‘‘Early
[27] R. Richardson and M. M. North, ‘‘Ransomware: detection and defense countermeasure inference of
Evolution, mitigation and prevention,’’ Authorized ransomware based on API sequence,’’ Int. J. Adv.
Administrator Digit. Commons Kennesaw State Univ., Comput. Sci. Appl., vol. 14, no. 10, pp. 632–641, 2023.
vol. 13, no. 1, pp. 10–21, 2017.
[40] I. Gulrajani, F. Ahmed, M. Arjovsky, V. Dumoulin,
[28] K. Hammadeh and M. Kavitha, ‘‘Unraveling and A. Courville, ‘‘Improved training of Wasserstein
ransomware: Detecting threats with advanced machine GANs,’’ in Proc. Adv. Neural Inf. Process. Syst., vol. 30,
learning algorithms,’’ Int. J. Adv. Comput. Sci. Appl., Dec. 2017, pp. 5769–5779.
vol. 14, no. 9, pp. 484–491, 2023.
[41] Python. Accessed: Apr. 4, 2024. [Online]. Available:
[Link] org/
© 2026, IJSREM | [Link] DOI: 10.55041/IJSREM57715 | Page 5

You might also like