Enhancing Ransomware Detection: A Registry Analysis-Based Approach
Khalid Zirari, Hamza Kamal Idrissi, Ahmed El-Yahyaoui, Hicham Bensaid, Abdeslam En‐Nouaary · 2023
The rise of ransomware poses a significant and widespread threat to both organizations and individuals. The financial impact of ransomware attacks is staggering, with billions of dollars lost in revenue and recovery costs. Therefore, it is imperative to revise conventional malware detection methods that rely on signatures to identify zero-day ransomware. However, these methods may not be sufficient in protecting users’ files against attacks caused by unknown and risky ransomware. Thus, it is essential to develop a novel security mechanism specifically designed to protect against ransomware. This mechanism should focus on ransomware-specific activities and behavior to differentiate ransomware from other categories of malicious software and legitimate files. In this paper, we present a novel approach to identifying and detecting ransomware by analyzing the registry and investigating all changes made to the system during the ransomware infection process.