Evolution of Windows Ransomware Detection from Machine Learning to Transfer Learning
摘要
Ransomware attacks have emerged as one of the most severe cybersecurity threats, with Windows systems being particularly targeted due to their widespread usage. The evolving sophistication of these attacks, including file encryption, data exfiltration, and ransom demands, necessitates advanced detection and analysis methods. This survey provides an overview of ransomware threats on the Windows Operating system. It also provides an in-depth coverage of the current techniques employed in the analysis and detection of Windows ransomware. We categorize existing methods into static analysis, dynamic analysis, and hybrid analysis for feature extraction. Additionally, we explore machine learning and deep learning-based detection, as well as the role of transfer learning in enhancing ransomware detection. Finally, we present a comprehensive evaluation of state-of-the-art solutions, future research directions, and the development of more resilient Windows ransomware defense mechanisms.