A Sandbox-Driven Machine Learning Framework for Ransomware Detection in Healthcare Systems
DOI:
https://doi.org/10.70917/ijcisim-2026-3259Keywords:
Ransomware detection, Healthcare cybersecurity, Sandbox analysis, Machine learning, Behavioral analysis, Internet of Medical Things (IoMT)Abstract
Ransomware attacks pose escalating risks to healthcare delivery by disrupting clinical workflows, encrypting sensitive data, and compromising patient safety. Traditional defenses such as signaturebased antivirus and ruledriven intrusion detection are inadequate against polymorphic and zeroday ransomware variants. This study proposes a sandboxdriven machine learning framework tailored for healthcare environments. A healthcareoriented sandbox generates controlled execution traces that capture entropy fluctuations, process activity, network communication, and domainspecific anomalies. From these traces, a multidimensional feature set is extracted and evaluated using Support Vector Machines (SVM), Random Forest (RF), Convolutional Neural Networks (CNN), and Long ShortTerm Memory (LSTM) models. Experimental results demonstrate that classical classifiers (SVM and RF) achieve perfect separation between ransomware and benign healthcare operations, while LSTM models provide strong temporal detection capability with reduced latency. Feature importance analysis highlights entropy and behavioral dynamics as key discriminators. The framework emphasizes interpretability, scalability, and deployment feasibility, enabling early ransomware identification without disrupting medical workflows. Although synthetic data was used for reproducibility, integration with real ransomware datasets is outlined as future work. Overall, the proposed approach establishes a robust, adaptive defense mechanism for healthcare systems, contributing to proactive cybersecurity in clinical practice.