{"id":"https://openalex.org/W4396506305","doi":"https://doi.org/10.1109/access.2024.3395491","title":"Ransomware Classification Using Hardware Performance Counters on a Non-Virtualized System","display_name":"Ransomware Classification Using Hardware Performance Counters on a Non-Virtualized System","publication_year":2024,"publication_date":"2024-01-01","ids":{"openalex":"https://openalex.org/W4396506305","doi":"https://doi.org/10.1109/access.2024.3395491"},"language":"en","primary_location":{"id":"doi:10.1109/access.2024.3395491","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2024.3395491","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/10510438.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/10510438.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5048058923","display_name":"J. Hill","orcid":"https://orcid.org/0000-0003-0674-154X"},"institutions":[{"id":"https://openalex.org/I189158971","display_name":"United States Naval Academy","ror":"https://ror.org/00znex860","country_code":"US","type":"education","lineage":["https://openalex.org/I1330347796","https://openalex.org/I189158971","https://openalex.org/I3130687028"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Jennie E. Hill","raw_affiliation_strings":["Department of Electrical and Computer Engineering, United States Naval Academy, Annapolis, MD, USA"],"raw_orcid":"https://orcid.org/0000-0003-0674-154X","affiliations":[{"raw_affiliation_string":"Department of Electrical and Computer Engineering, United States Naval Academy, Annapolis, MD, USA","institution_ids":["https://openalex.org/I189158971"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5063837246","display_name":"T. Owens Walker","orcid":"https://orcid.org/0000-0001-9709-5090"},"institutions":[{"id":"https://openalex.org/I189158971","display_name":"United States Naval Academy","ror":"https://ror.org/00znex860","country_code":"US","type":"education","lineage":["https://openalex.org/I1330347796","https://openalex.org/I189158971","https://openalex.org/I3130687028"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"T. Owens Walker","raw_affiliation_strings":["Department of Electrical and Computer Engineering, United States Naval Academy, Annapolis, MD, USA"],"raw_orcid":"https://orcid.org/0000-0001-9709-5090","affiliations":[{"raw_affiliation_string":"Department of Electrical and Computer Engineering, United States Naval Academy, Annapolis, MD, USA","institution_ids":["https://openalex.org/I189158971"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5091622588","display_name":"Justin A. Blanco","orcid":"https://orcid.org/0000-0003-1101-2608"},"institutions":[{"id":"https://openalex.org/I189158971","display_name":"United States Naval Academy","ror":"https://ror.org/00znex860","country_code":"US","type":"education","lineage":["https://openalex.org/I1330347796","https://openalex.org/I189158971","https://openalex.org/I3130687028"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Justin A. Blanco","raw_affiliation_strings":["Department of Electrical and Computer Engineering, United States Naval Academy, Annapolis, MD, USA"],"raw_orcid":"https://orcid.org/0000-0003-1101-2608","affiliations":[{"raw_affiliation_string":"Department of Electrical and Computer Engineering, United States Naval Academy, Annapolis, MD, USA","institution_ids":["https://openalex.org/I189158971"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5007146911","display_name":"Robert W. Ives","orcid":"https://orcid.org/0000-0003-0411-0541"},"institutions":[{"id":"https://openalex.org/I189158971","display_name":"United States Naval Academy","ror":"https://ror.org/00znex860","country_code":"US","type":"education","lineage":["https://openalex.org/I1330347796","https://openalex.org/I189158971","https://openalex.org/I3130687028"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Robert W. Ives","raw_affiliation_strings":["Department of Electrical and Computer Engineering, United States Naval Academy, Annapolis, MD, USA"],"raw_orcid":"https://orcid.org/0000-0003-0411-0541","affiliations":[{"raw_affiliation_string":"Department of Electrical and Computer Engineering, United States Naval Academy, Annapolis, MD, USA","institution_ids":["https://openalex.org/I189158971"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5081739050","display_name":"Ryan Rakvic","orcid":null},"institutions":[{"id":"https://openalex.org/I189158971","display_name":"United States Naval Academy","ror":"https://ror.org/00znex860","country_code":"US","type":"education","lineage":["https://openalex.org/I1330347796","https://openalex.org/I189158971","https://openalex.org/I3130687028"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ryan Rakvic","raw_affiliation_strings":["Department of Electrical and Computer Engineering, United States Naval Academy, Annapolis, MD, USA"],"raw_orcid":"https://orcid.org/0000-0001-9668-5507","affiliations":[{"raw_affiliation_string":"Department of Electrical and Computer Engineering, United States Naval Academy, Annapolis, MD, USA","institution_ids":["https://openalex.org/I189158971"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5047597896","display_name":"Bruce Jacob","orcid":"https://orcid.org/0009-0005-3493-8245"},"institutions":[{"id":"https://openalex.org/I189158971","display_name":"United States Naval Academy","ror":"https://ror.org/00znex860","country_code":"US","type":"education","lineage":["https://openalex.org/I1330347796","https://openalex.org/I189158971","https://openalex.org/I3130687028"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Bruce Jacob","raw_affiliation_strings":["Department of Cyber Science, United States Naval Academy, Annapolis, MD, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Cyber Science, United States Naval Academy, Annapolis, MD, USA","institution_ids":["https://openalex.org/I189158971"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":{"value":1850,"currency":"USD","value_usd":1850},"apc_paid":{"value":1850,"currency":"USD","value_usd":1850},"fwci":5.503,"has_fulltext":false,"cited_by_count":18,"citation_normalized_percentile":{"value":0.96655891,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":100},"biblio":{"volume":"12","issue":null,"first_page":"63865","last_page":"63884"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9926999807357788,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9750999808311462,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/ransomware","display_name":"Ransomware","score":0.8969064950942993},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8172825574874878},{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.545173168182373},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.5240949988365173},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.48125383257865906},{"id":"https://openalex.org/keywords/virtual-machine","display_name":"Virtual machine","score":0.480258971452713},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.420159250497818},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.4067077934741974},{"id":"https://openalex.org/keywords/computer-hardware","display_name":"Computer hardware","score":0.33942529559135437},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.25141555070877075}],"concepts":[{"id":"https://openalex.org/C2777667771","wikidata":"https://www.wikidata.org/wiki/Q926331","display_name":"Ransomware","level":3,"score":0.8969064950942993},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8172825574874878},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.545173168182373},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.5240949988365173},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.48125383257865906},{"id":"https://openalex.org/C25344961","wikidata":"https://www.wikidata.org/wiki/Q192726","display_name":"Virtual machine","level":2,"score":0.480258971452713},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.420159250497818},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.4067077934741974},{"id":"https://openalex.org/C9390403","wikidata":"https://www.wikidata.org/wiki/Q3966","display_name":"Computer hardware","level":1,"score":0.33942529559135437},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.25141555070877075}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/access.2024.3395491","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2024.3395491","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/10510438.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},{"id":"pmh:oai:doaj.org/article:0ac05952e84641cb9927b77d5634ec3e","is_oa":true,"landing_page_url":"https://doaj.org/article/0ac05952e84641cb9927b77d5634ec3e","pdf_url":null,"source":{"id":"https://openalex.org/S4306401280","display_name":"DOAJ (DOAJ: Directory of Open Access Journals)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IEEE Access, Vol 12, Pp 63865-63884 (2024)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.1109/access.2024.3395491","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2024.3395491","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/10510438.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4396506305.pdf"},"referenced_works_count":55,"referenced_works":["https://openalex.org/W1647124656","https://openalex.org/W1827822366","https://openalex.org/W2057787526","https://openalex.org/W2088503757","https://openalex.org/W2108557980","https://openalex.org/W2142145056","https://openalex.org/W2170467352","https://openalex.org/W2315350509","https://openalex.org/W2319159802","https://openalex.org/W2562036180","https://openalex.org/W2595350342","https://openalex.org/W2625408821","https://openalex.org/W2768516003","https://openalex.org/W2787744061","https://openalex.org/W2802164016","https://openalex.org/W2883173712","https://openalex.org/W2890909432","https://openalex.org/W2900633536","https://openalex.org/W2921770285","https://openalex.org/W2922354075","https://openalex.org/W2950774332","https://openalex.org/W2951172748","https://openalex.org/W2956019498","https://openalex.org/W2965574698","https://openalex.org/W2996806689","https://openalex.org/W2998074434","https://openalex.org/W3007346474","https://openalex.org/W3024340288","https://openalex.org/W3036401269","https://openalex.org/W3087990352","https://openalex.org/W3107251728","https://openalex.org/W3127601194","https://openalex.org/W3133819097","https://openalex.org/W3147804620","https://openalex.org/W3161004246","https://openalex.org/W3169311144","https://openalex.org/W3188588464","https://openalex.org/W3197098979","https://openalex.org/W4200569302","https://openalex.org/W4210937029","https://openalex.org/W4211030792","https://openalex.org/W4224300905","https://openalex.org/W4238607753","https://openalex.org/W4243762858","https://openalex.org/W4281725204","https://openalex.org/W4283708239","https://openalex.org/W4285212536","https://openalex.org/W4293503742","https://openalex.org/W4383981974","https://openalex.org/W6687356291","https://openalex.org/W6748263364","https://openalex.org/W6779882417","https://openalex.org/W6786500554","https://openalex.org/W6838733255","https://openalex.org/W6884871261"],"related_works":["https://openalex.org/W3201228709","https://openalex.org/W2922354075","https://openalex.org/W4389157351","https://openalex.org/W4232561318","https://openalex.org/W3202245533","https://openalex.org/W4253977752","https://openalex.org/W2942879794","https://openalex.org/W2964829536","https://openalex.org/W2904586340","https://openalex.org/W3120595989"],"abstract_inverted_index":{"Ransomware":[0],"is":[1,174],"a":[2,10,20,33,60],"type":[3],"of":[4,17,24,26,71,79,83,122,131,140,164],"malicious":[5],"software":[6],"designed":[7],"to":[8,57,62,103,127,147,154],"encrypt":[9],"user\u2019s":[11],"important":[12],"data":[13],"for":[14,184],"the":[15,40,77,105,123,129,141,185],"purpose":[16],"extortion,":[18],"with":[19,120,170,176],"global":[21],"annual":[22],"impact":[23],"billions":[25],"dollars":[27],"in":[28,108,166],"damages.":[29],"This":[30],"research":[31],"proposes":[32],"side-channel-based":[34],"ransomware":[35,50,89,111,165],"detection":[36],"method":[37],"that":[38,162],"utilizes":[39],"microarchitectural":[41],"side-channel":[42],"accessed":[43],"through":[44],"hardware":[45,75,95,102,125,150,181],"performance":[46,134,151],"counters.":[47],"Unlike":[48],"most":[49,110],"research,":[51],"which":[52,109,149],"relies":[53],"on":[54,74,99],"virtual":[55],"machines":[56],"easily":[58],"restore":[59],"system":[61],"its":[63],"uncompromised,":[64],"pre-encrypted":[65],"state,":[66],"this":[67,159],"work":[68,160],"leverages":[69],"thousands":[70],"trials":[72],"collected":[73,98],"without":[76],"use":[78],"virtualization.":[80],"Trials":[81],"consist":[82],"both":[84],"benign":[85],"operations":[86],"and":[87,133,137,188],"real-world":[88,106],"executables.":[90],"Over":[91,114],"two":[92,168],"hundred":[93],"distinct":[94],"events":[96,126],"were":[97,117,145],"(non-virtualized)":[100],"computer":[101],"replicate":[104],"scenario":[107],"attacks":[112],"occur.":[113],"30":[115],"classifiers":[116,132],"systematically":[118],"trained":[119],"each":[121],"200+":[124],"reduce":[128],"number":[130],"counters":[135,152],"considered,":[136],"then":[138],"five":[139],"top":[142],"classification":[143,156,163],"algorithms":[144],"evaluated":[146],"rank":[148],"contributed":[153],"best":[155],"results.":[157],"Overall,":[158],"showed":[161],"under":[167],"seconds":[169],"over":[171],"95%":[172],"accuracy":[173],"viable":[175],"as":[177,179],"few":[178],"3":[180],"event":[182],"features":[183],"Neural":[186],"Network":[187],"Bagged":[189],"Tree":[190],"classifiers.":[191]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":14},{"year":2024,"cited_by_count":2}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
