iCNN-LSTM+: A Batch-Based Incremental Ransomware Detection System Using Sysmon
Jamil Ispahany, Rafiqul Islam, M. Arif Khan, Md Zahidul Islam · IEEE Access · 2025
Ransomware remains a persistent and evolving cyber threat, requiring adaptive and efficient detection mechanisms. This study presents a novel CNN-LSTM-based detection system that leverages Sysmon logs for real-time analysis on Windows endpoints. Through the integration of batch-based incremental learning, the model achieves continuous adaptation to previously unseen ransomware variants, eliminating the necessity for full retraining and effectively addressing the constraints associated with conventional static detection methodologies. The proposed framework achieves an average F2-score of 99.65%, with false positive and false negative rates of 0.16% and 3.96%, respectively, even in a highly imbalanced dataset. To comprehensively evaluate its performance, we introduce the Weighted Efficiency Score (WES), a novel metric that balances detection accuracy and throughput. The iCNN-LSTM+ model attains the highest WES among CNN-LSTM architectures, demonstrating its efficiency in real-world applications. Furthermore, parallel LSTM processing with attention mechanisms enhances throughput, making the system scalable for large-scale deployments. These findings establish the iCNN-LSTM+ framework as a resilient and adaptable solution for real-time ransomware detection, effectively mitigating the risks posed by emerging threats.