[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-122854-en":3,"doc-seo-122854-105":30,"detail-sidebar-cat-0-en-105":87},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},122854,4398048949847,"Eliana","https://ap-avatar.wpscdn.com/avatar/400002536579ef2da7f?_k=1778318612642679267",8,"Research & Report","Hypervisor-Level Ransomware Detection in Cloud Using Machine Learning","Ransomware incidents have increased in recent years, and their impact has intensified in the cloud era as attacks evolve to target cloud storage and synchronized data. The work reviews ransomware evolution and summarizes existing detection approaches, then provides a dataset-generation methodology for cloud ransomware detection with feature selection and normalization. A hypervisor-level virtualized-environment detection system using machine learning models is proposed and evaluated, achieving 96.6% accuracy for ransomware attack detection in virtualized environments.","Hypervisor-Level Ransomware Detection in Cloud Using Machine Learning  \n[1]Prasad Purnaye, [1]Anuj Singh, [1]Mayank Singh, [1]Suprabhath Nair, [1]Devanshu Mehta  \n[1] Dr Vishwanath Karad MIT World Peace University, Pune, India  \n[prasad.purnaye@mitwpu.edu.in](prasad.purnaye@mitwpu.edu.in), [anujsingh2409@gmail.com](anujsingh2409@gmail.com), [mayank.singh011@gmail.com](mayank.singh011@gmail.com), [suprabhathnair@gmail.com](suprabhathnair@gmail.com),  \n[devanshumehta8@gmail.com](devanshumehta8@gmail.com).  \nAbstract—Ransomware attack incidences have been on the rise for a few years. The attacks have evolved over the years. The severity of these attacks has only increased in the cloud era. This article discusses the evolution of ransomware attacks targeting cloud storage and explores existing ransomware detection solutions. It also presents a methodology for generating a dataset for detecting ransomware in the cloud and discusses the results, including feature selection and normalization. The article proposes a system for detecting attacks in virtualized environments using machine learning models and evaluates the performance of different classification models. The proposed system is shown to have high accuracy of 96.6% in detecting ransomware attacks in virtualized environments at the hypervisor level.  \nIndex Terms—cybersecurity, cloud computing, virtualization, ransomware detection.  \nI. INTRODUCTION  \nRansomware encrypts an organization's crucial data and files that are stored on servers, storage area networks, and endpoint devices. It has recently been named one of the most popular and successful viruses targeted against enterprises. After encrypting the crucial data, the attacker demands a ransom from the victim, and if payment is not made by the specified date, the victim's data would be permanently lost. Given the fast growth of cloud computing, it is not surprising that ransomware has been targeting cloud storage. Often, a user sets up their computer so that the files stored on their computer are synchronized with their other devices via cloud-based storage. Once a file is encrypted by ransomware, all copies of the file that are synchronized with the encrypted file also become encrypted. So, ifa user has multiple devices the copy of the file on each device and the cloud storage all become encrypted.  \nII. LITERATURE SURVEY  \nA. Most Common Attacks  \nAccording to the technique used to extort the victim, there are two major categories of ransomware. These two varieties are Ransomware-locker and Ransomware-crypto (also known as cryptographic malware) . A ransomware-locker stops the victim from accessing his or her device, i.e. The user is not permitted to use their system or device until the specified ransom is paid. Attacks using cryptocurrency-based ransomware prohibit victims from accessing files or data. This is also called a data locker since it locks data. A few of the most common ransomware attacks are discussed as follows.  \na) WannaCry: The WannaCry ransomware attack was a global cyberattack that occurred in May 2017. It took advantage of aflaw in Microsoft Windows operating systems that the National Security Agency (NSA) had identified and released online. The malware encrypted files on infected computers and demanded a ransom payment in Bitcoin to restore access to the files[2] .  \nb) Crypto Locker: It encrypts the user's files and demands payment in exchange for the decryption key to unlock the files. The attackers typically ask for payment in Bitcoin. If the ransom is not paid within the given time frame, the decryption key is permanently deleted, and the user's files remain encrypted and inaccessible. The most common ways that Cryptolocker distributes are through email attachments, dangerous links, or drive-by downloads from infected websites [3] .  \nc) NotPetya: In June 2017, a widespread hack known as\"NotPetya\" took place. The attack spread across networks using a technique akin to a worm, infecting machines","cbCaioGbo2dKirGd","https://ap.wps.com/l/cbCaioGbo2dKirGd","pdf",315709,1,5,"English","en",105,"# Abstract\n# I. Introduction\n# II. Literature Survey\n## A. Most Common Attacks\n## B. Existing Ransomware detection solutions","[{\"question\":\"What detection approach is proposed for virtualized environments?\",\"answer\":\"The method reports 96.6% accuracy for detecting ransomware attacks in virtualized environments at the hypervisor level.\"},{\"question\":\"How do existing defenses help against ransomware?\",\"answer\":\"The document summarizes defenses such as repositories and data sharing for rapid restoration, and behavior-based detection by analyzing system events and network traffic for suspicious patterns.\"}]","Hypervisor-Level Ransomware Detection in Cloud Using Machine Learning | PDF",1785813306,13,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":82,"head_meta":84,"extra_data":86,"updated_unix":28},"hypervisor-level-ransomware-detection-in-cloud-using-machine-learning","",{"@graph":36,"@context":81},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/hypervisor-level-ransomware-detection-in-cloud-using-machine-learning/122854/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77],{"name":72,"@type":73,"acceptedAnswer":74},"What detection approach is proposed for virtualized environments?","Question",{"text":75,"@type":76},"The method reports 96.6% accuracy for detecting ransomware attacks in virtualized environments at the hypervisor level.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How do existing defenses help against ransomware?",{"text":80,"@type":76},"The document summarizes defenses such as repositories and data sharing for rapid restoration, and behavior-based detection by analyzing system events and network traffic for suspicious patterns.","https://schema.org",{"og:url":52,"og:type":83,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":85,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":88},[89,93,97,101,105,110,115,118,123,126,130],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":90,"show_sort_weight":91,"slug":92},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Exam",70,"exam",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Comic",60,"comic",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},6,"Technology",50,"technology",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":116,"slug":117},30,"research-report",{"id":119,"doc_module":4,"doc_module_name":46,"category_name":120,"show_sort_weight":121,"slug":122},9,"Religion & Spirituality",20,"religion-spirituality",{"id":121,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":121,"slug":125},"World Cup","world-cup",{"id":127,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":127,"slug":129},10,"Lifestyle","lifestyle",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":21,"slug":133},19,"General","general"]