Predictive Moving Target Defense for Ransomware Using Temporal Transformers and Uncertainty-Aware Risk Estimation

Main Article Content

Snehal R. Shinde, Jagdish W. Bakal

Abstract

Ransomware has evolved into one of the most disruptive cyber threats, leading to prolonged service outages and irreversible data loss. Conventional static defense mechanisms and signature-based detection methods are no longer sufficient to counter adaptive attack strategies and rapidly evolving ransomware variants. Moving Target Defense (MTD) has attracted considerable interest as a proactive defense paradigm by continuously varying system configurations for increasing attacker uncertainty. However, existing MTD mechanisms are often reactive, rule-based, or weakly synchronized with detection engines, resulting in unnecessary and potentially disruptive reconfigurations, delayed responses, and degraded system performance. To address these limitations, a machine learning–driven, behaviour-aware MTD framework is proposed for ransomware defense. The behavioral traces are processed through sliding-window analysis and hybrid feature encoding that integrates statistical descriptors with categorical embeddings. A time-series Transformer encoder models temporal attack patterns, whereas uncertainty-aware risk estimation, together with Monte Carlo Dropout, facilitates confidence-guided MTD triggering. Defense actions are activated only when predicted risk surpasses predefined thresholds with low uncertainty, minimizing false alarms and redundant system reconfigurations. Moreover, a feedback-driven self-supervised adaptive learning mechanism enables the model to handle behavioural drift over time. The MLRan dataset is used for simulations, which demonstrate high ransomware detection reliability with timely MTD activation, reduced false positives, and improved system resilience, proving the efficacy of the proposed framework for real-time capable ransomware mitigation.

Article Details

Section
Articles