Real time ransomware detection in cloud VMS using behavioral biometrics homomorphic encryption and GMM based anomaly detection.

Saved in:
Bibliographic Details
Title: Real time ransomware detection in cloud VMS using behavioral biometrics homomorphic encryption and GMM based anomaly detection.
Authors: Mahmoud, Haitham A.1 (AUTHOR) hmahmoud@ksu.edu.sa, Abdelgawad, Abdelaty Edrees1 (AUTHOR) Aesayed@ksu.edu.sa, Soliman, Ahmed T.1 (AUTHOR) Asoluman@ksu.edu.sa, El-Meligy, Mohammed A.2 (AUTHOR) melmeligy@ksu.edu.sa
Source: International Journal of Information Security. Dec2025, Vol. 24 Issue 6, p1-12. 12p.
Abstract: Ransomware poses a huge danger to cloud Virtual Machines (VM) because cloud infrastructures are scalable and multitenant giving attackers a huge attack surface. It swiftly propagates across the cloud infrastructure encrypting key data and preventing services from causing severe operational and financial losses once a VM is compromised. Traditional detection approaches like signature-based techniques fail to identify new or updated ransomware strains in dynamic cloud settings. A real time ransomware detection system for cloud VMs that combines behavioral biometrics, Homomorphic Encryption (HE) and anomaly detection based on Gaussian Mixture Model (GMM) to improve security and privacy is proposed. HE guarantees the safe processing of encrypted data without the need for decryption while GMM professionally simulates both typical and unusual actions in real time. The detection process improves the feature extraction and selection using advanced methods like Gated Recurrent Unit (GRU), Deep Feature Selection (DFS), and Variational Autoencoder (VAE). It obtained 99.1 percent accuracy and 97.4 percent precision with a remarkably low False Positive Rate (FPR) and False Negative Rate (FNR) of 0.01 and 0.02 respectively when tested on the CICIDS 2018 dataset. This shows that it performs better than current techniques and is suitable for large-scale, real time cloud environments while maintaining data privacy. The result proves that the proposed method is stable and expandable in identifying ransomware attacks in cloud VMs. [ABSTRACT FROM AUTHOR]
Copyright of International Journal of Information Security is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 189222886
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Real time ransomware detection in cloud VMS using behavioral biometrics homomorphic encryption and GMM based anomaly detection.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Mahmoud%2C+Haitham+A%2E%22">Mahmoud, Haitham A.</searchLink><relatesTo>1</relatesTo> (AUTHOR)<i> hmahmoud@ksu.edu.sa</i><br /><searchLink fieldCode="AR" term="%22Abdelgawad%2C+Abdelaty+Edrees%22">Abdelgawad, Abdelaty Edrees</searchLink><relatesTo>1</relatesTo> (AUTHOR)<i> Aesayed@ksu.edu.sa</i><br /><searchLink fieldCode="AR" term="%22Soliman%2C+Ahmed+T%2E%22">Soliman, Ahmed T.</searchLink><relatesTo>1</relatesTo> (AUTHOR)<i> Asoluman@ksu.edu.sa</i><br /><searchLink fieldCode="AR" term="%22El-Meligy%2C+Mohammed+A%2E%22">El-Meligy, Mohammed A.</searchLink><relatesTo>2</relatesTo> (AUTHOR)<i> melmeligy@ksu.edu.sa</i>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22International+Journal+of+Information+Security%22">International Journal of Information Security</searchLink>. Dec2025, Vol. 24 Issue 6, p1-12. 12p.
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: Ransomware poses a huge danger to cloud Virtual Machines (VM) because cloud infrastructures are scalable and multitenant giving attackers a huge attack surface. It swiftly propagates across the cloud infrastructure encrypting key data and preventing services from causing severe operational and financial losses once a VM is compromised. Traditional detection approaches like signature-based techniques fail to identify new or updated ransomware strains in dynamic cloud settings. A real time ransomware detection system for cloud VMs that combines behavioral biometrics, Homomorphic Encryption (HE) and anomaly detection based on Gaussian Mixture Model (GMM) to improve security and privacy is proposed. HE guarantees the safe processing of encrypted data without the need for decryption while GMM professionally simulates both typical and unusual actions in real time. The detection process improves the feature extraction and selection using advanced methods like Gated Recurrent Unit (GRU), Deep Feature Selection (DFS), and Variational Autoencoder (VAE). It obtained 99.1 percent accuracy and 97.4 percent precision with a remarkably low False Positive Rate (FPR) and False Negative Rate (FNR) of 0.01 and 0.02 respectively when tested on the CICIDS 2018 dataset. This shows that it performs better than current techniques and is suitable for large-scale, real time cloud environments while maintaining data privacy. The result proves that the proposed method is stable and expandable in identifying ransomware attacks in cloud VMs. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of International Journal of Information Security is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=189222886
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1007/s10207-025-01151-8
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 12
        StartPage: 1
    Titles:
      – TitleFull: Real time ransomware detection in cloud VMS using behavioral biometrics homomorphic encryption and GMM based anomaly detection.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Mahmoud, Haitham A.
      – PersonEntity:
          Name:
            NameFull: Abdelgawad, Abdelaty Edrees
      – PersonEntity:
          Name:
            NameFull: Soliman, Ahmed T.
      – PersonEntity:
          Name:
            NameFull: El-Meligy, Mohammed A.
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 12
              Text: Dec2025
              Type: published
              Y: 2025
          Identifiers:
            – Type: issn-print
              Value: 16155262
          Numbering:
            – Type: volume
              Value: 24
            – Type: issue
              Value: 6
          Titles:
            – TitleFull: International Journal of Information Security
              Type: main
ResultId 1