Home > Published Issues > 2026 > Volume 17, No. 8, 2026 >
JAIT 2026 Vol.17(8): 1598-1609
doi: 10.12720/jait.17.8.1598-1609

A Hybrid Feature-based Approach for Early Ransomware Detection: Leveraging Behavioral, Network, and Static Characteristics

Shuaib Ahmed Wadho 1,*, Aun Yichiet 1, Asma Ahmed A. Mohammed 2,3, Ming Lee Gan 1,
and Chen Kang Lee 1
1. Faculty of Information and Communication Technology, University of Tunku Abdul Rahman, Kampar, Malaysia
2. Department of Computer Science, University of Tabuk, Tabuk, Saudi Arabia
3. Department of Computer Science, University of Kassala, Kassala, Sudan
Email: shuaib@1utar.my (S.A.W.); aunyc@utar.edu.my (A.Y.); a.amohammed@ut.edu.sa (A.A.A.M); ganml@utar.edu.my (M.L.G.); lckang@utar.edu.my (C.K.L.)
*Corresponding author

Manuscript received February 28, 2026; revised April 4, 2026; accepted June 30, 2026; published August 26, 2026.

Abstract—The growing difficulty of ransomware attacks highlights the urgent need for intelligent, real-time detection strategies that can mitigate threats before data encryption occurs. Traditional single-source detection methods often fail to identify rapidly evolving ransomware variants during their early encryption stages. This paper presents a hybrid ransomware detection framework that integrates behavioral system Application Programming Interface (API) call sequences, network traffic features from Canadian Institute for Cybersecurity Intrusion Detection System dataset (CICIDS), and static Portable Executable (PE) attributes from the Elastic Malware Benchmark for Empowering Researchers dataset (EMBER). A time-windowed data modeling technique is used to capture early-stage ransomware behavior within the first few seconds of execution. The proposed framework employs a hybrid Recurrent Neural Network (RNN) and Bidirectional Long Short-Term Memory (BiLSTM) deep learning model to learn both sequential and contextual patterns across the fused feature space. Experimental results demonstrate high accuracy (0.96) and early detection capability within 3 s, significantly outperforming traditional machine learning baselines. The system effectively detects known and unknown ransomware families by leveraging a multi-perspective view of ransomware activity. This study demonstrates the potential of hybrid feature integration and time-sensitive learning in enhancing early ransomware detection, contributing to the development of robust, real-time cybersecurity defense systems.
 
Keywords—ransomware, detection, framework, portable executable, hybrid, dataset, deep learning
 
Cite: Shuaib Ahmed Wadho, Aun Yichiet, Asma Ahmed A. Mohammed, Ming Lee Gan, and Chen Kang Lee, "A Hybrid Feature-based Approach for Early Ransomware Detection: Leveraging Behavioral, Network, and Static Characteristics," Journal of Advances in Information Technology, Vol. 17, No. 8, pp. 1598-1609, 2026. doi: 10.12720/jait.17.8.1598-1609

Copyright © 2026 by the authors. This is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited (CC BY 4.0).

Article Metrics in Dimensions