Bibliographic Details
| Title: |
Real time ransomware detection in cloud VMS using behavioral biometrics homomorphic encryption and GMM based anomaly detection. |
| Authors: |
Mahmoud, Haitham A.1 (AUTHOR) hmahmoud@ksu.edu.sa, Abdelgawad, Abdelaty Edrees1 (AUTHOR) Aesayed@ksu.edu.sa, Soliman, Ahmed T.1 (AUTHOR) Asoluman@ksu.edu.sa, El-Meligy, Mohammed A.2 (AUTHOR) melmeligy@ksu.edu.sa |
| Source: |
International Journal of Information Security. Dec2025, Vol. 24 Issue 6, p1-12. 12p. |
| Abstract: |
Ransomware poses a huge danger to cloud Virtual Machines (VM) because cloud infrastructures are scalable and multitenant giving attackers a huge attack surface. It swiftly propagates across the cloud infrastructure encrypting key data and preventing services from causing severe operational and financial losses once a VM is compromised. Traditional detection approaches like signature-based techniques fail to identify new or updated ransomware strains in dynamic cloud settings. A real time ransomware detection system for cloud VMs that combines behavioral biometrics, Homomorphic Encryption (HE) and anomaly detection based on Gaussian Mixture Model (GMM) to improve security and privacy is proposed. HE guarantees the safe processing of encrypted data without the need for decryption while GMM professionally simulates both typical and unusual actions in real time. The detection process improves the feature extraction and selection using advanced methods like Gated Recurrent Unit (GRU), Deep Feature Selection (DFS), and Variational Autoencoder (VAE). It obtained 99.1 percent accuracy and 97.4 percent precision with a remarkably low False Positive Rate (FPR) and False Negative Rate (FNR) of 0.01 and 0.02 respectively when tested on the CICIDS 2018 dataset. This shows that it performs better than current techniques and is suitable for large-scale, real time cloud environments while maintaining data privacy. The result proves that the proposed method is stable and expandable in identifying ransomware attacks in cloud VMs. [ABSTRACT FROM AUTHOR] |
|
Copyright of International Journal of Information Security is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) |
| Database: |
Engineering Source |