A Hybrid Endpoint-Network Correlation Framework for Ransomware-Oriented Analysis
DOI:
https://doi.org/10.62146/ijecbe.v4i1.243Keywords:
ransomware-oriented analysis, endpoint analysis, network analysis, multi-log correlation, incident context, hybrid security analyticsAbstract
Ransomware-oriented incidents often leave suspicious traces across both endpoint and network domains, yet these observations are still commonly examined in isolation. This makes incident interpretation difficult, since host-level and communication-level evidence may remain fragmented even when they originate from the same attack sequences. To address this problem, this paper presents a hybrid endpoint-network correlation framework built around three analytical stages: endpoint-side suspicious activity analysis, network-side suspicious activity analysis, and multi-log correlation. The framework combines rule-based indicators with machine-learning-based suspiciousness support to preserve relevant evidence and then links the resulting candidates through temporal proximity, entity consistency, and behavioral relevance. Experiments on public attack scenarios show that the framework retained 16 endpoint candidates and 3 network candidates in a successful Drupal exploitation case, 11 endpoint candidates and 3 network candidates in a Samba known-creds scenario, and preserved a network-only context in a reconnaissance-dominant case. These retained candidates then serve as the basis for identifying cross-log relations, allowing suspicious observations from different sources to be interpreted within the same incident context. These results suggest that the framework can construct incident-oriented context without forcing unsupported cross-source relations.
References
A. Kharraz, S. Arshad, C. Mulliner, W. Robertson, and E. Kirda, “UNVEIL: A Large-Scale, Automated Approach to Detecting Ransomware,” in Proc. 25th USENIX Security Symposium, 2016, pp. 757–772.
D. Sgandurra, L. Muñoz-González, R. Mohsen, and E. C. Lupu, “Automated Dynamic Analysis of Ransomware: Benefits, Limitations and Use for Detection,” arXiv preprint arXiv:1609.03020, 2016.
H. Alraizza and A. Algarni, “Ransomware Detection Using Machine Learning: A Survey,” Big Data and Cognitive Computing, vol. 7, no. 3, art. 143, 2023.
R. Hofstede, P. Čeleda, B. Trammell, I. Drago, R. Sadre, A. Sperotto, and A. Pras, “Flow Monitoring Explained: From Packet Capture to Data Analysis with NetFlow and IPFIX,” IEEE Communications Surveys & Tutorials, vol. 16, no. 4, pp. 2037–2064, 2014.
M. Du, F. Li, G. Zheng, and V. Srikumar, “DeepLog: Anomaly Detection and Diagnosis from System Logs through Deep Learning,” in Proc. ACM CCS, 2017, pp. 1285–1298.
T. Jirsík and P. Velan, “Host Behavior in Computer Network: One-Year Study,” IEEE Transactions on Network and Service Management, vol. 18, no. 1, pp. 822–838, 2021.
M. Ring, D. Landes, D. Wunderlich, S. Scheuring, D. Landes, and A. Hotho, “A Survey of Network-Based Intrusion Detection Data Sets,” Computers & Security, vol. 86, pp. 147–167, 2019.
E. Raftopoulos, M. Egli, and X. Dimitropoulos, “Shedding Light on Log Correlation in Network Forensics Analysis,” in Detection of Intrusions and Malware, and Vulnerability Assessment, 2012, pp. 232–241.
S. Špaček and P. Čeleda, “Threat Detection Through Correlation of Network Flows and Logs,” in Proc. AIMS, 2018.
T. van Ede, H. Aghakhani, N. Spahn, R. Bortolameotti, M. Cova, A. Continella, M. van Steen, A. Peter, C. Kruegel, and G. Vigna, “DEEPCASE: Semi-Supervised Contextual Analysis of Security Events,” in Proc. IEEE Symposium on Security and Privacy, 2022.
S. M. Milajerdi, B. Eshete, R. Gjomemo, W. Enck, N. Venkatakrishnan, and V. N. Venkatakrishnan, “HOLMES: Real-Time APT Detection Through Correlation of Suspicious Information Flows,” arXiv preprint arXiv:1810.01594, 2018.
D. Levshun and I. Kotenko, “A Survey on Artificial Intelligence Techniques for Security Event Correlation: Models, Challenges, and Opportunities,” Artificial Intelligence Review, vol. 56, pp. 8547–8590, 2023.
M. Cermak and T. Jirsik, D3.2 Annotated Dataset. SAPPAN Consortium, 2020.
M. Cermák, T. Jirsík, P. Velan, J. Komárková, S. Špaček, M. Drašar, and T. Plešník, “Towards Provable Network Traffic Measurement and Analysis via Semi-Labeled Trace Datasets,” in Proc. TMA, 2018.
N. Capuano, G. Fenza, V. Loia, and C. Stanzione, “Explainable Artificial Intelligence in Cybersecurity: A Survey,” IEEE Access, vol. 10, pp. 93575–93600, 2022.
I. H. Sarker, H. Janicke, A. Mohsin, A. Gill, and L. Maglaras, “Explainable AI for Cybersecurity Automation, Intelligence and Trustworthiness in Digital Twin: Methods, Taxonomy, Challenges and Prospects,” ICT Express, 2024.
S. Khraisat, I. Gondal, P. Vamplew, and J. Kamruzzaman, “Survey of Intrusion Detection Systems: Techniques, Datasets and Challenges,” Cybersecurity, vol. 2, no. 1, pp. 1–22, 2019.
M. Ring, S. Wunderlich, D. Landes, and A. Hotho, “Flow-Based Network Traffic Generation Using Generative Adversarial Networks,” Computers & Security, vol. 82, pp. 156–172, 2019.
H. Maosa, K. Ouazzane, and M. C. Ghanem, “A Hierarchical Security Event Correlation Model for Real-Time Threat Detection and Response,” Network, vol. 4, no. 1, pp. 68–90, 2024.
I. Kotenko, A. Fedorchenko, and E. Doynikova, “Data Analytics for Security Management of Complex Heterogeneous Systems: Event Correlation and Security Assessment Tasks,” in Advances in Cyber Security Analytics and Decision Systems, 2020, pp. 79–116.
A. Ghafouri, W. Abbas, A. Laszka, Y. Vorobeychik, and X. Koutsoukos, “Optimal Thresholds for Anomaly-Based Intrusion Detection in Dynamical Environments,” in Decision and Game Theory for Security, 2016, pp. 415–434.
K. Z. Bai and J. M. Fossaceca, “EM-AUC: A Novel Algorithm for Evaluating Anomaly Based Network Intrusion Detection Systems,” Sensors, vol. 25, no. 1, art. 78, 2025.
“System for Continuous Collection of Contextual Information for Network Security Management,” Proceedings of ACM CoNEXT Student Workshop, 2021.
Z. Yang, X. Liu, T. Li, D. Wu, J. Wang, Y. Zhao, and H. Han, “A Systematic Literature Review of Methods and Datasets for Anomaly-Based Network Intrusion Detection,” Computers & Security, vol. 116, art. 102675, 2022.
E. Chuah, H. Kalutarage, K. Tasdemir, A. Abrham, and C. Maple, “A Systematic Literature Review of Log-Correlation Tools for Cyberattack Detection and Prediction in Large Networks,” Journal of Information Security and Applications, vol. 92, art. 104096, 2025.
X. Wang, X. Yang, X. Liang, X. Zhang, W. Zhang, and X. Gong, “Combating Alert Fatigue with AlertPro: Context-Aware Alert Prioritization Using Reinforcement Learning for Multi-Step Attack Detection,” Computers & Security, vol. 138, art. 103583, 2024.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 International Journal of Electrical, Computer, and Biomedical Engineering

This work is licensed under a Creative Commons Attribution 4.0 International License.



