Ransomware and other destructive cyber events increasingly threaten the availability and integrity of mission-critical financial information systems. Modern banking infrastructures are no longer confined to a single storage or compute platform. Enterprise applications increasingly span virtual machines, containerized workloads, object-storage platforms, block and file storage, backup repositories, replication systems, and geographically separated recovery environments. This heterogeneity creates an important security limitation: platform-specific monitoring can identify local anomalies while failing to recognize a coordinated attack whose evidence is distributed across multiple infrastructure layers.
This paper proposes CART, a Cross-platform Anomaly and Recovery Trust framework for mission-critical banking data infrastructure. CART combines heterogeneous telemetry from container orchestration platforms, virtualization environments, enterprise storage, object storage, backup systems, replication services, and recovery repositories. A context-aware temporal anomaly-detection layer identifies deviations from workload-specific behavioral baselines and a cross-platform correlation engine combines weak signals across infrastructure domains. Following detection, a Recovery Trust Score (RTS) evaluates candidate recovery points according to integrity evidence, temporal consistency, behavioral exposure, provenance, protection status, and observed anomaly propagation. The framework therefore extends ransomware detection from a binary classification problem— “attack or no attack” —to a detection-to-recovery decision problem: detect the attack, estimate its cross-platform exposure, and identify the most trustworthy recovery state.
The proposed methodology addresses several limitations in existing ransomware research, including dependence on single-layer telemetry, insufficient consideration of legitimate high-volume enterprise workloads, concept drift, severe class imbalance, and the assumption that the latest available backup is necessarily the safest recovery point. The study defines a reproducible evaluation protocol using public ransomware datasets, container-security datasets, and controlled synthetic enterprise-storage telemetry. Evaluation will compare conventional threshold detection, individual machine-learning models, platform-specific models, and the proposed cross-platform framework using precision, recall, F1-score, PR-AUC, false-positive rate, mean time to detection, recovery-point selection accuracy, false-safe recovery rate, and estimated recovery-point and recovery-time objectives.
The intended contribution is a platform-independent architecture for AI-assisted cyber resilience in heterogeneous financial data infrastructure. Rather than claiming that artificial intelligence can eliminate ransomware, the framework aims to provide measurable improvements in early anomaly detection and evidence-based recovery-point selection.
Introduction
The text describes the development and evaluation of a herbal oral gel containing Curcuma longa, Glycyrrhiza glabra, and eugenol for the management of oral diseases such as gingivitis, periodontitis, dental caries, mouth ulcers, and oral mucosal inflammation.
Background
Oral diseases are common health problems caused largely by microbial biofilms and pathogenic organisms. Conventional antimicrobial and antiseptic treatments can cause problems such as mucosal irritation, altered taste, and antimicrobial resistance when used for long periods. Therefore, herbal medicines are being explored as safer alternatives because of their potential antimicrobial, antioxidant, anti-inflammatory, analgesic, and wound-healing properties.
The three main herbal ingredients have complementary functions:
Curcuma longa (turmeric): Provides antimicrobial, antioxidant, and wound-healing effects. Curcumin may help control oral pathogens and reduce tissue damage.
Glycyrrhiza glabra (licorice): Contains glycyrrhizin and flavonoids that may provide antimicrobial, soothing, and anti-inflammatory effects and help against cariogenic bacteria.
Eugenol: A major component of clove oil, widely used in dentistry for its analgesic and antiseptic properties and its ability to relieve dental pain.
Combining these ingredients may produce a synergistic effect by targeting several mechanisms involved in oral disease.
Materials and Methods
The study used authenticated plant materials and pharmaceutical excipients. Carbopol 934 was used as the gelling agent, while propylene glycol functioned as a solvent and humectant. Methyl paraben was used as a preservative, triethanolamine for pH adjustment, and peppermint oil as a flavoring agent.
Preparation of Extracts
Three extraction methods were used:
Curcuma longa rhizomes were powdered and extracted with ethanol using Soxhlet extraction for approximately 6–8 hours.
Glycyrrhiza glabra roots were extracted using a 70:30 ethanol-water mixture through maceration for 24–48 hours.
Eugenol-rich clove oil was obtained from powdered clove buds through hydro-distillation using a Clevenger apparatus for approximately 3–4 hours.
The resulting extracts were filtered, concentrated, and stored for formulation.
Herbal Oral Gel Formulation
The gel was prepared using the dispersion method. Carbopol 934 was hydrated in water, while the herbal extracts were dissolved or mixed with propylene glycol. Eugenol was incorporated into the mixture, followed by preservatives and peppermint oil. Triethanolamine was then added to neutralize the Carbopol and adjust the formulation to an oral-compatible pH of approximately 6.0–7.5.
Three formulations were prepared:
F1: Lower concentration of herbal extracts and gelling agent.
F2: Intermediate/optimized formulation.
F3: Higher concentration of herbal extracts and gelling agent.
F2 contained approximately 1.5% each of Curcuma longa and Glycyrrhiza glabra extract, 0.3% eugenol, and 1.2% Carbopol 934.
Evaluation of the Formulation
The prepared gel was evaluated through several tests to determine its quality, stability, uniformity, and suitability for oral application.
Main evaluation parameters
Organoleptic properties: Color, odor, taste, appearance, texture, homogeneity, and consistency were examined.
Phytochemical tests: Chemical identification tests were performed to confirm characteristic constituents of turmeric, licorice, and eugenol.
pH: Measured using a calibrated digital pH meter, with the desired oral-gel range maintained at 6.0–7.5.
Viscosity: Measured using a Brookfield viscometer to determine the gel's flow behavior. The formulation showed pseudoplastic behavior, which is suitable for oral topical application.
Spreadability: Determined using the glass-slide method. Good spreadability indicates that the gel can be easily and uniformly applied to oral tissues.
Extrudability: Evaluated to determine how easily the gel could be removed from its tube under pressure.
Drug content uniformity: UV-visible spectrophotometry was used to determine whether the active ingredients were uniformly distributed throughout the gel.
Stability studies: The formulations were evaluated under different temperature and humidity conditions following ICH stability-testing principles.
Conclusion
This paper proposed CART, an AI-driven cross-platform anomaly-detection and recovery-trust framework for mission-critical banking data infrastructure.
Unlike conventional ransomware detection approaches that primarily classify activity as malicious or benign, CART treats cyber resilience as a continuous detection-to-recovery problem.
The framework combines telemetry from containers, virtualization, enterprise storage, object storage, backup, and replication systems. It introduces context-aware temporal anomaly detection, cross-platform behavioral correlation, concept-drift monitoring, explainable decision support, and a Recovery Trust Score for candidate recovery points.
The central research proposition is that ransomware resilience should not end when an attack is detected. A financial institution must also determine whether its available recovery states remain trustworthy.
The proposed experimental methodology is designed to test whether cross-platform behavioral correlation can improve early detection and whether recovery-point trust scoring can reduce unsafe recovery decisions compared with conventional recovery selection.
The empirical claims of the final publication must be based exclusively on the results of the proposed experiments. This is essential for scientific validity and publication integrity.
References
[1] Souppaya, M., Barker, W., Fisher, W., & Kent, K. (2026). Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile. NIST IR 8374 Rev. 1.
[2] McBride, T., Ekstrom, M., Lusty, L. N., Sexton, J., & Townsend, A. (2020). Data Integrity: Recovering from Ransomware and Other Destructive Events. NIST Special Publication 1800-11. DOI: 10.6028/NIST.SP.1800-11.
[3] Hirano, M., & Kobayashi, R. (2024). RanSMAP: Open Dataset of Ransomware Storage and Memory Access Patterns for Creating Deep Learning Based Ransomware Detectors. Computers & Security, 104202. DOI: 10.1016/j.cose.2024.104202.
[4] Onwuegbuche, F. C., Adelodun, S. O., Jurcut, A. D., & Pasquale, L. (2026). MLRan: A behavioural dataset for ransomware analysis and detection. Journal of Network and Computer Applications, 250, 104475. DOI: 10.1016/j.jnca.2026.104475.
[5] Fernando, D. W., & Komninos, N. (2024). FeSAD ransomware detection framework with machine learning using adaption to concept drift. Computers & Security, 137, 103629. DOI: 10.1016/j.cose.2023.103629.
[6] Tayouri, D., Sgan Cohen, O., Maimon, I., Mimran, D., Elovici, Y., & Shabtai, A. (2025). CORAL: Container Online Risk Assessment with Logical attack graphs. Computers & Security, 150, 104296. DOI: 10.1016/j.cose.2024.104296.
[7] [Containerized intrusion-detection study]. (2025). Enhancing intrusion detection in containerized services: Assessing machine learning models and an advanced representation for system call data. Computers & Security, 154, 104438. DOI: 10.1016/j.cose.2025.104438.
[8] [Adversarial ransomware study]. (2026). GUARD: Graph-based utility for adversarial ransomware detection using structural and behavioural characteristics. Array, 30, 100911.
[9] Kubernetes Documentation. Observability: Metrics, Logs and Audit Information. Kubernetes Project.
[10] [Software/container anomaly detection study]. (2025). Software anomaly detection technology based on deep learning. Procedia Computer Science, 259, 1123–1129.
[11] Tayouri, D., Sgan Cohen, O., Maimon, I., Mimran, D., Elovici, Y., & Shabtai, A. (2025). CORAL: Container Online Risk Assessment with Logical attack graphs. Computers & Security, 150, 104296.
[12] Red Hat. OpenShift Container Platform: Backup and Restore Documentation. Red Hat Documentation.
[13] Pascoe, C., Quinn, S., & Scarfone, K. (2024). The NIST Cybersecurity Framework (CSF) 2.0. NIST Cybersecurity White Paper CSWP 29. DOI: 10.6028/NIST.CSWP.29.