Completed Computing & AI Engineering

CipherGrit: Real-time ransomware detection system using transfer-learning

In plain English

AI plain-English summary

A piece of software watches a computer's hardware—its processor, memory, and input-output activity—to catch ransomware before it locks up files. Traditional antivirus tools rely on spotting known signatures or monitoring network traffic, but sophisticated ransomware can disable those defences or hide inside encrypted traffic. CipherGrit sidesteps that problem by analysing real-time hardware metrics using machine learning, making it much harder for malware to evade detection. It can flag an attack both before and after infection, giving systems a chance to respond before critical data gets encrypted. If the system works at scale, it could add a resilient detection layer to existing cybersecurity frameworks—one that operates independently of software that attackers might disable. Financial institutions could use it to protect transactions, healthcare providers to keep patient records and critical systems running, and defence agencies to guard classified networks. The next phase involves real-world testing to confirm the approach holds up across diverse environments. This is applied research with a clear practical target: stopping ransomware from paralysing the organisations that keep society running.

View original technical description
Ransomware attacks continue to evolve, circumventing traditional security measures and inflicting significant financial and operational harm across various industries. These attacks encrypt critical data, demanding ransom payments while debilitating businesses, healthcare systems, and government institutions. Current detection methods, such as signature-based and network-based approaches, often fall short against sophisticated ransomware variants that utilise obfuscation and evasion techniques. **CipherGrit** is an innovative, **software-based** solution for ransomware detection, offering an advanced layer of cyber security defence. Unlike conventional methods that depend on file activity or network traffic, CipherGrit harnesses the power of machine learning (ML) to analyse real-time multi-dimensional system metrics. By monitoring key hardware indicators, such as _CPU execution patterns, memory consumption, hardware I/O, and network activity,_ our solution can identify the presence of ransomware at both pre-and post-infection stages, ensuring a proactive response before critical damage ensues. Traditional anti-malware software can frequently be disabled by attackers, rendering it ineffective once a system is compromised. CipherGrit operates at the hardware level, making it considerably more challenging for ransomware to evade detection or manipulate its functions. This stealthy and resilient approach enhances existing cyber security frameworks by adding a novel detection layer that can function independently of software-based solutions. By integrating with Intrusion Detection Systems (IDS), **CipherGrit** provides a comprehensive cyber security solution. The combination of host-based hardware monitoring and network-based threat analysis ensures holistic protection against ransomware, significantly improving detection speed and accuracy while minimising false positives. **CipherGrit** has an extensive potential impact. Financial institutions can use it to secure customer transactions and prevent data breaches. Healthcare organisations can safeguard critical medical systems and patient records, ensuring uninterrupted care delivery. The defence and national security sectors can deploy it to protect classified systems from ransomware threats, aligning with strategic cyber security priorities. Our preliminary research has demonstrated CipherGrit's ability to distinguish ransomware activity from normal applications accurately. The next development phase involves extensive real-world testing and refinement to validate its effectiveness in diverse cyber security environments. By leveraging cutting-edge hardware monitoring and ML-driven analysis, **CipherGrit** represents a transformative advancement in ransomware defence, offering resilience, speed, and precision in combating one of today's most pressing cyber threats.

View the original record at the funder ↗

Related Research

Grants with similar aims, by meaning.

CipherGrit: Real-time ransomware detection system using transfer-learning (Phase 2)
Classifying Advanced Malware into Families based on Instruction Link Analysis - project name: RAPTOR
Countering HArms caused by Ransomware in the Internet Of Things (CHARIOT)
Internet Forensic platform for tracking the money flow of financially-motivated malware
iCyberPlatform - An innovative cybersecurity platform that uses AI, ML, Bayesian statistical models and the LDA algorithm to provide enhanced cyber defence against breaches

Original classification

Collaborative R&D

Plain English summaries and category classifications on this site are generated by AI and may not perfectly reflect the original research.