Intermittent File Encryption in Ransomware: Measurement, Modeling, and Detection

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Ineza, Ynes, Jackson, Gerald, Niyonkuru, Prince, Kevil, Jaden, Serwadda, Abdul
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866915810579054592
author Ineza, Ynes
Jackson, Gerald
Niyonkuru, Prince
Kevil, Jaden
Serwadda, Abdul
author_facet Ineza, Ynes
Jackson, Gerald
Niyonkuru, Prince
Kevil, Jaden
Serwadda, Abdul
contents File encrypting ransomware increasingly employs intermittent encryption techniques, encrypting only parts of files to evade classical detection methods. These strategies, exemplified by ransomware families like BlackCat, complicate file structure based detection techniques due to diverse file formats exhibiting varying traits under partial encryption. This paper provides a systematic empirical characterization of byte level statistics under intermittent encryption across common file types, establishing a comprehensive baseline of how partial encryption impacts data structure. We specialize a classical KL divergence upper bound on a tailored mixture model of intermittent encryption, yielding filetype specific detectability ceilings for histogram-based detectors. Leveraging insights from this analysis, we empirically evaluate convolutional neural network (CNN) based detection methods using realistic intermittent encryption configurations derived from leading ransomware variants. Our findings demonstrate that localized analysis via chunk level CNNs consistently outperforms global analysis methods, highlighting their practical effectiveness and establishing a robust baseline for future detection systems.
format Preprint
id arxiv_https___arxiv_org_abs_2510_15133
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Intermittent File Encryption in Ransomware: Measurement, Modeling, and Detection
Ineza, Ynes
Jackson, Gerald
Niyonkuru, Prince
Kevil, Jaden
Serwadda, Abdul
Cryptography and Security
File encrypting ransomware increasingly employs intermittent encryption techniques, encrypting only parts of files to evade classical detection methods. These strategies, exemplified by ransomware families like BlackCat, complicate file structure based detection techniques due to diverse file formats exhibiting varying traits under partial encryption. This paper provides a systematic empirical characterization of byte level statistics under intermittent encryption across common file types, establishing a comprehensive baseline of how partial encryption impacts data structure. We specialize a classical KL divergence upper bound on a tailored mixture model of intermittent encryption, yielding filetype specific detectability ceilings for histogram-based detectors. Leveraging insights from this analysis, we empirically evaluate convolutional neural network (CNN) based detection methods using realistic intermittent encryption configurations derived from leading ransomware variants. Our findings demonstrate that localized analysis via chunk level CNNs consistently outperforms global analysis methods, highlighting their practical effectiveness and establishing a robust baseline for future detection systems.
title Intermittent File Encryption in Ransomware: Measurement, Modeling, and Detection
topic Cryptography and Security
url https://arxiv.org/abs/2510.15133