Lightweight Crypto-Ransomware Detection in Android Based on Reactive Honeyfile Monitoring Gómez Hernández, José Antonio García Teodoro, Pedro Crypto-ransomware Early detection Deception Reactive monitoring Honeyfile Android This publication results from the project NetSEA-GPT (C-ING-300-UGR23), funded by Consejería de Universidad, Investigación e Innovación and the European Union through the ERDF Andalusia Program 2021–2027, and the project C025/24 INCIBE-UGR, funded with European NextGeneration Funds. Given the high relevance and impact of ransomware in companies, organizations, and individuals around the world, coupled with the widespread adoption of mobile and IoT-related devices for both personal and professional use, the development of effective and efficient ransomware mitigation schemes is a necessity nowadays. Although a number of proposals are available in the literature in this line, most of them rely on machine-learning schemes that usually involve high computational cost and resource consumption. Since current personal devices are small and limited in capacities and resources, the mentioned schemes are generally not feasible and usable in practical environments. Based on a honeyfile detection solution previously introduced by the authors for Linux and Window OSs, this paper presents a ransomware detection tool for Android platforms where the use of trap files is combined with a reactive monitoring scheme, with three main characteristics: (I) the trap files are properly deployed around the target file system, (II) the FileObserver service is used to early alert events that access the traps following certain suspicious sequences, and (III) the experimental results show high performance of the solution in terms of detection accuracy and efficiency. 2024-04-24T06:57:02Z 2024-04-24T06:57:02Z 2024-04-23 journal article Gómez-Hernández, J.A.; García-Teodoro, P. Lightweight Crypto-Ransomware Detection in Android Based on Reactive Honeyfile Monitoring. Sensors 2024, 24, 2679. https://doi.org/10.3390/s24092679 https://hdl.handle.net/10481/91093 10.3390/s24092679 eng info:eu-repo/grantAgreement/EC/NextGenerationEU/C025/24 INCIBE-UGR open access MDPI