Prioritizing ransomware indicators of compromise using algorithmic scoring for enhanced threat detection

Krishna Prasad D. Subramanya, Prasanna Kumar H. Ramakrishna

Abstract


Ransomware is a very serious cybersecurity threat. Its attack methods are continually evolving, which means that it is not very easy to detect it quickly. A big challenge faced in the ransomware defense is how to prioritize indicators of compromise (IoC) efficiently. This paper introduces a hybrid IoC ranking scheme based on static and dynamic analysis of the behavior of commonly circulating ransomware variants. Each IoC is given a weighted score according to its significance for investigations based on actual patterns of occurrence and contextual behavior. Experimental results clearly separate high-confidence indicators from low-confidence ones. Deleting shadow copy and connecting to Tor2web receive the highest rank scores of about 99.99, while older behaviors like locking screen show lower relevance, around 73.11. The proposed algorithm has a linear time complexity of O(n·m) for score calculation and a bounded space complexity of O(n·m), allowing it to scale for large IoC sets. The findings show that this ranked IoC framework enhances early ransomware detection and helps prioritize responses based on evidence in current security systems.

Keywords


Dynamic analysis; Hybrid analysis; Indicators of compromise; Ranking indicators of compromise; Ransomware; Static analysis

Full Text:

PDF


DOI: http://doi.org/10.11591/ijai.v15.i4.pp3865-3877

Refbacks

  • There are currently no refbacks.


Copyright (c) 2026 Krishna Prasad D. Subramanya, Prasanna Kumar H. Ramakrishna

Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

IAES International Journal of Artificial Intelligence (IJ-AI)
ISSN/e-ISSN 2089-4872/2252-8938 
This journal is published by the Institute of Advanced Engineering and Science (IAES).

View IJAI Stats