Enhanced Ransomware Detection Using CNN2D and Voting Ensemble Models
DOI:
https://doi.org/10.62643/Keywords:
Ransomware Detection, Virtual Machines, Host-Based Monitoring, Processor Events, Disk I/O Events, Random Forest Classifier, Machine Learning, Lightweight Monitoring, Data Contamination, User Workloads AdaptabilityAbstract
This extension enhances ransomware detection for virtual machines by integrating a powerful CNN2D architecture with a voting ensemble classifier, significantly improving accuracy to 99%. The system converts processor and disk I/O behavior into structured feature maps, enabling CNN2D to learn deep ransomware activity patterns that traditional models often miss. The ensemble model further strengthens reliability by combining predictions from multiple classifiers, ensuring consistent performance across diverse workloads. To support real-world usability, Flask and SQLite are incorporated to provide secure, lightweight user authentication and testing interfaces. This extended framework minimizes monitoring overhead, increases adaptability, and delivers rapid, robust ransomware detection suitable for modern virtualized environments.
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.













