Efficient Ransomware Detection through Process Memory Analysis in Operating Systems
William Koyirar, Benjamin Harris, Jonathan Williams, Alejandro Moreno, Elizabeth Davis · 2024
Ransomware attacks have become one of the most pervasive threats in cybersecurity, capable of inflicting severe damage on both individual and enterprise systems by encrypting valuable data and demanding ransom payments. The traditional reliance on static signatures and heuristic-based detection methods has proven inadequate in addressing the sophisticated and rapidly evolving nature of modern ransomware variants. A novel approach is introduced through process memory analysis, enabling the detection of ransomware in real-time without the need for predefined signatures. By monitoring memory access patterns and using machine learning classifiers, the system identifies anomalous behaviors that distinguish ransomware from benign processes with a high degree of accuracy. The proposed system's robustness is demonstrated through rigorous testing, revealing its efficiency in handling large-scale memory operations while maintaining low false positive rates. Furthermore, the research contributes to the field of ransomware detection by introducing a scalable, machine learning-driven framework capable of adapting to new and previously unseen ransomware variants.