Deep Learning Driven Ransomware Detection: A Bibliometric Analysis of Research Trends, Knowledge Structure, and Future Directions

DOI: https://doi.org/10.33650/jeecom.v8i1.17163
Authors

(1) * Guntoro Guntoro   (Universitas Lancang Kuning)  
        Indonesia
(2)  Lisnawita Lisnawita   (Universitas Lancang Kuning)  
        Indonesia
(3)  Loneli Costaner   (Universitas Lancang Kuning)  
        Indonesia
(4)  Wenni Syafitri   (Universitas Lancang Kuning)  
        Indonesia
(*) Corresponding Author

Abstract


Ransomware has become a major cybersecurity threat because it encrypts data, disrupts services, and evolves rapidly beyond conventional signature-based detection. This study presents a bibliometric analysis of deep learning-driven ransomware detection research, with emphasis on behavioral and dynamic analysis, API-call sequences, system calls, and future research directions. A total of 481 records were retrieved from the Web of Science Core Collection; after screening one retracted publication and two editorial materials, 478 eligible records remained. The eligible corpus was analyzed using Biblioshiny and Bibliometrix. Results show rapid growth from 2022 to 2025, with IEEE Access, Computers & Security, Sensors, Scientific Reports, and International Journal of Information Security among the prominent sources. Keyword and thematic analyses indicate a shift from static detection toward behavior-aware, sequence-based, explainable, and real-time ransomware detection. The findings highlight the need for robust datasets, cross-dataset validation, low-latency inference, explainable deep learning, and integrated detection systems for practical cybersecurity deployment.


Keywords

Ransomware detection; Deep learning; Machine learning; Behavioral analysis; Bibliometric analysis



Full Text: PDF



References


E. Berrueta, D. Morato, E. Magaña, and M. Izal, “Crypto-ransomware detection using machine learning models in file-sharing network scenarios with encrypted traffic,” Expert Syst. Appl., vol. 209, p. 118299, Dec. 2022, doi: 10.1016/j.eswa.2022.118299.

D. W. Fernando, N. Komninos, and T. Chen, “A Study on the Evolution of Ransomware Detection Using Machine Learning and Deep Learning Techniques,” IoT, vol. 1, no. 2, pp. 551–604, Dec. 2020, doi: 10.3390/iot1020030.

C.-M. Hsu, C.-C. Yang, H.-H. Cheng, P. E. Setiasabda, and J.-S. Leu, “Enhancing File Entropy Analysis to Improve Machine Learning Detection Rate of Ransomware,” IEEE Access, vol. 9, pp. 138345–138351, 2021, doi: 10.1109/ACCESS.2021.3114148.

S. H. Kok, A. Azween, and N. Jhanjhi, “Evaluation metric for crypto-ransomware detection using machine learning,” J. Inf. Secur. Appl., vol. 55, p. 102646, Dec. 2020, doi: 10.1016/j.jisa.2020.102646.

D. W. Fernando and N. Komninos, “FeSAD ransomware detection framework with machine learning using adaption to concept drift,” Comput. Secur., vol. 137, p. 103629, Feb. 2024, doi: 10.1016/j.cose.2023.103629.

S. Gulmez, A. Gorgulu Kakisim, and I. Sogukpinar, “XRan: Explainable deep learning-based ransomware detection using dynamic analysis,” Comput. Secur., vol. 139, p. 103703, Apr. 2024, doi: 10.1016/j.cose.2024.103703.

T.-L. Lin et al., “Ransomware Detection by Distinguishing API Call Sequences through LSTM and BERT Models,” Comput. J., vol. 67, no. 2, pp. 632–641, Feb. 2024, doi: 10.1093/comjnl/bxad005.

C. J. W. Chew, V. Kumar, P. Patros, and R. Malik, “Real-time system call-based ransomware detection,” Int. J. Inf. Secur., vol. 23, no. 3, pp. 1839–1858, Jun. 2024, doi: 10.1007/s10207-024-00819-x.

M. Masum et al., “Ransomware Classification and Detection With Machine Learning Algorithms,” presented at the 2022 IEEE 12TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE (CCWC), 2022, pp. 316–322. doi: 10.1109/CCWC54503.2022.9720869.

A. Hussain, A. Saadia, and F. M. Alserhani, “Ransomware detection and family classification using fine-tuned BERT and RoBERTa models,” Egypt. Inform. J., vol. 30, p. 100645, Jun. 2025, doi: 10.1016/j.eij.2025.100645.

M. Davidian, M. Kiperberg, and N. Vanetik, “Early Ransomware Detection with Deep Learning Models,” Future Internet, vol. 16, no. 8, p. 291, Aug. 2024, doi: 10.3390/fi16080291.

J. Zhu, J. Jang-Jaccard, A. Singh, I. Welch, H. Al-Sahaf, and S. Camtepe, “A few-shot meta-learning based siamese neural network using entropy features for ransomware classification,” Comput. Secur., vol. 117, Jun. 2022, doi: 10.1016/j.cose.2022.102691.

T. Dam, N. Nguyen, T. Le, T. Le, S. Uwizeyemungu, and T. Le-Dinh, “Visualizing Portable Executable Headers for Ransomware Detection: A Deep Learning-Based Approach,” J. Univers. Comput. Sci., vol. 30, no. 2, pp. 262–286, 2024, doi: 10.3897/jucs.104901.

M. Gazzan, B. Alobaywi, M. Almutairi, and F. T. Sheldon, “A Deep Learning Framework for Enhanced Detection of Polymorphic Ransomware,” Future Internet, vol. 17, no. 7, p. 311, Jul. 2025, doi: 10.3390/fi17070311.

M. Gazzan and F. T. Sheldon, “Novel Ransomware Detection Exploiting Uncertainty and Calibration Quality Measures Using Deep Learning,” Information, vol. 15, no. 5, p. 262, 2024, doi: 10.3390/info15050262.

J. Lee, J. Kim, H. Jeong, and K. Lee, “A Machine Learning-Based Ransomware Detection Method for Attackers’ Neutralization Techniques Using Format-Preserving Encryption,” Sensors, vol. 25, no. 8, p. 2406, Apr. 2025, doi: 10.3390/s25082406.

N. Donthu, S. Kumar, D. Mukherjee, N. Pandey, and W. M. Lim, “How to conduct a bibliometric analysis: An overview and guidelines,” J. Bus. Res., vol. 133, pp. 285–296, Sep. 2021, doi: https://doi.org/10.1016/j.jbusres.2021.04.070.

M. Aria and C. Cuccurullo, “bibliometrix : An R-tool for comprehensive science mapping analysis,” J. Informetr., vol. 11, no. 4, pp. 959–975, Nov. 2017, doi: https://doi.org/10.1016/j.joi.2017.08.007.

A. Alqahtani, M. O. Ohemeng, and F. T. Sheldon, “An Intelligent Sensing Framework for Early Ransomware Detection Using MHSA-LSTM Machine Learning,” Sensors, vol. 26, no. 3, p. 952, Feb. 2026, doi: 10.3390/s26030952.

Ö. Aslan, S. S. Aktuğ, M. Ozkan-Okay, A. A. Yilmaz, and E. Akin, “A Comprehensive Review of Cyber Security Vulnerabilities, Threats, Attacks, and Solutions,” Electronics, vol. 12, no. 6, p. 1333, Mar. 2023, doi: 10.3390/electronics12061333.

S. Razaulla et al., “The Age of Ransomware: A Survey on the Evolution, Taxonomy, and Research Directions,” IEEE ACCESS, vol. 11, pp. 40698–40723, 2023, doi: 10.1109/access.2023.3268535.

K. Higuchi and R. Kobayashi, “Real-time open-file backup system with machine-learning detection model for ransomware,” Int. J. Inf. Secur., vol. 24, no. 1, p. 54, Feb. 2025, doi: 10.1007/s10207-024-00966-1.

M. Maghanaki, S. Keramati, F. F. Chen, and M. Shahin, “Systematic Evaluation of Machine Learning and Deep Learning Models for IoT Malware Detection Across Ransomware, Rootkit, Spyware, Trojan, Botnet, Worm, Virus, and Keylogger,” Sensors, vol. 26, no. 6, p. 1750, Mar. 2026, doi: 10.3390/s26061750.

M. Gopinath and S. Sethuraman, “A comprehensive survey on deep learning based malware detection techniques,” Comput. Sci. Rev., vol. 47, Feb. 2023, doi: 10.1016/j.cosrev.2022.100529.

A. Alqahtani and F. T. Sheldon, “A Survey of Crypto Ransomware Attack Detection Methodologies: An Evolving Outlook,” Sensors, vol. 22, no. 5, p. 1837, 2022, doi: 10.3390/s22051837.

U. Urooj, B. Al-rimy, A. Zainal, F. Ghaleb, and M. Rassam, “Ransomware Detection Using the Dynamic Analysis and Machine Learning: A Survey and Research Directions,” Appl. Sci.-BASEL, vol. 12, no. 1, Jan. 2022, doi: 10.3390/app12010172.

M. Wazid, A. Das, and S. Shetty, “BSFR-SH: Blockchain-Enabled Security Framework Against Ransomware Attacks for Smart Healthcare,” IEEE Trans. Consum. Electron., vol. 69, no. 1, pp. 18–28, Feb. 2023, doi: 10.1109/TCE.2022.3208795.

S. Kok, A. Abdullah, and N. Jhanjhi, “Early detection of crypto-ransomware using pre-encryption detection algorithm,” J. KING SAUD Univ. Comput. Inf. Sci., vol. 34, no. 5, pp. 1984–1999, May 2022, doi: 10.1016/j.jksuci.2020.06.012.

A. Djenna, A. Bouridane, S. Rubab, and I. Marou, “Artificial Intelligence-Based Malware Detection, Analysis, and Mitigation,” SYMMETRY-BASEL, vol. 15, no. 3, Mar. 2023, doi: 10.3390/sym15030677.

M. Hirano and R. Kobayashi, “RanSMAP: Open dataset of Ransomware Storage and Memory Access Patterns for creating deep learning based ransomware detectors,” Comput. Secur., vol. 150, p. 104202, Mar. 2025, doi: 10.1016/j.cose.2024.104202.


Dimensions, PlumX, and Google Scholar Metrics

10.33650/jeecom.v8i1.17163


Refbacks

  • There are currently no refbacks.


Copyright (c) 2026 Guntoro Guntoro, Lisnawita Lisnawita, Lonel Costaner, Wenni Syafitri

 
This work is licensed under a Creative Commons Attribution License (CC BY-SA 4.0)

Journal of Electrical Engineering and Computer (JEECOM)
Published by LP3M Nurul Jadid University, Indonesia, Probolinggo, East Java, Indonesia.