Content area

Abstract

Problem statement

Ransomware attacks pose a severe threat to organizations by exploiting security weaknesses, most often leading to colossal economic and information loss. There is a growing need for efficient and accurate predictive models to detect and prevent such attacks in real-time cybersecurity applications.

Methodology

This paper utilizes the UGRansome dataset, which is a large-scale ransomware and zero-day attack detector. The F-measure method is employed in this paper as a novel method for enhancing model interpretability and preventing redundancy. The Histogram Gradient Boosting classifier, which is optimized, is subsequently enhanced with three advanced metaheuristic optimizers. Sensitivity analysis provides transparent insights into the effects of individual attributes through explainable AI. Finally, the Wilcoxon ranking test is applied to ensure the statistical significance of the performance gain, and K-fold cross-validation ensures robustness and generalizability of the reported models. In addition, Recursive Feature Elimination (RFE) is also applied to rank the features to identify the most important predictors methodically. Sensitivity analysis is also performed utilizing SHapley Additive exPlanations (SHAP) values to present explainable and transparent perspectives on individual feature impacts on the model’s output.

Results

The hybrid models proposed here exhibit significant gains in prediction accuracy, precision, and recall. The feature importance analysis indicates that economic and behavioral features of the network equally contribute to correct ransomware identification.

Contributions

This work introduces an evaluation of a strong and scalable model for ransomware forecasting that enables organizations to predict threats ahead of time and improve their general cybersecurity capabilities. The integration of cutting-edge feature selection with nature-inspired optimization enables the framework to create more accurate models while maintaining interpretability and efficiency. The method is directly translatable to real-world scenarios, including enhancing cloud security, detecting zero-day attacks, and supporting mass-scale automated threat scanning in fluctuating cybersecurity environments.

Details

1009240
Title
Enhanced ransomware attacks detection using feature selection, sensitivity analysis, and optimized hybrid model
Author
Zhang, Kun 1 ; Wang, Yetong 2 ; Bhatti, Uzair Aslam 3 ; Zhou, Yu 4 ; Jin, Ming 5 

 Hainan Normal University, School of Information Science and Technology, Haikou, China (GRID:grid.440732.6) (ISNI:0000 0000 8551 5345); Hainan University, School of Information and Communication Engineering, Haikou, China (GRID:grid.428986.9) (ISNI:0000 0001 0373 6302); Hainan Normal University, Hainan Engineering Research Center for Smart Education Technology, Haikou, China (GRID:grid.440732.6) (ISNI:0000 0000 8551 5345) 
 Hainan Vocational University of Science and Technology, Hainan Engineering Research Center for Virtual Reality Technology and Systems, Haikou, China (GRID:grid.440732.6) 
 Hainan University, School of Information and Communication Engineering, Haikou, China (GRID:grid.428986.9) (ISNI:0000 0001 0373 6302) 
 Hainan Normal University, School of Information Science and Technology, Haikou, China (GRID:grid.440732.6) (ISNI:0000 0000 8551 5345); Hainan Normal University, Hainan Engineering Research Center for Smart Education Technology, Haikou, China (GRID:grid.440732.6) (ISNI:0000 0000 8551 5345) 
 Hainan Normal University, School of Foreign Languages, Haikou, China (GRID:grid.440732.6) (ISNI:0000 0000 8551 5345) 
Publication title
Volume
12
Issue
1
Pages
245
Publication year
2025
Publication date
Nov 2025
Publisher
Springer Nature B.V.
Place of publication
Heidelberg
Country of publication
Netherlands
e-ISSN
21961115
Source type
Scholarly Journal
Language of publication
English
Document type
Journal Article
Publication history
 
 
Online publication date
2025-11-03
Milestone dates
2025-09-07 (Registration); 2025-04-08 (Received); 2025-09-07 (Accepted)
Publication history
 
 
   First posting date
03 Nov 2025
ProQuest document ID
3268285494
Document URL
https://www.proquest.com/scholarly-journals/enhanced-ransomware-attacks-detection-using/docview/3268285494/se-2?accountid=208611
Copyright
© The Author(s) 2025. This work is published under http://creativecommons.org/licenses/by-nc-nd/4.0/ (the “License”). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.
Last updated
2025-11-14
Database
2 databases
  • Coronavirus Research Database
  • ProQuest One Academic