Mathematical Models for Early Ransomware Detection
摘要
Ransomware is a growing threat that disrupts individuals and organizations by encrypting critical data and demanding ransom payments for its release. Its rapid evolution and increasing sophistication pose significant challenges to traditional detection methods, which often rely on signature-based or heuristic approaches. This research focuses on developing a theoretical framework for early ransomware detection based on system resource utilization metrics. The proposed framework introduces key metrics such as the Malicious Score and the System Anomaly Ratio (SAR). To further enhance detection accuracy, the framework incorporates insights from honeypot interactions, using data from decoy systems to refine anomaly detection. This study contributes to the field of cybersecurity by introducing a novel, metric-based approach to ransomware detection, laying the groundwork for advanced and effective detection systems.