Casino, Fran, Hurley-Smith, Darren, Hernandez-Castro, Julio, Patsakis, Constantinos (2025) Not on my watch: ransomware detection through classification of high-entropy file segments. Journal of Cybersecurity, 11 (1). Article Number tyaf009. ISSN 2057-2085. (doi:10.1093/cybsec/tyaf009) (KAR id:110567)
|
PDF
Publisher pdf
Language: English
This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
|
|
|
Download this file (PDF/2MB) |
Preview |
| Request a format suitable for use with assistive technology e.g. a screenreader | |
| Official URL: https://doi.org/10.1093/cybsec/tyaf009 |
|
Abstract
The double-edged sword of continuous digitization of services and systems opens the door to a myriad of beneficial opportunities, as well as challenging threats. Currently, ransomware is catalogued as the first threat in cybersecurity due to its impact on organizations, critical infrastructure, industry, and society as a whole. Thus, devoting efforts toward developing methodologies to effectively prevent and mitigate ransomware is crucial. In this article, we present an accurate method to identify encrypted bit streams by differentiating them from other high-entropy streams (e.g. compressed files), which is a critical task to detect potentially malicious file write events on the file system in current operating systems. After extensive evaluation, our findings demonstrate that the proposed solution outperforms the current state of the art in both adaptability and accuracy, enabling it to be integrated into current Endpoint Detection and Response systems.
| Item Type: | Article |
|---|---|
| DOI/Identification number: | 10.1093/cybsec/tyaf009 |
| Projects: | SAFEHORIZON, LAZARUS, ALUNA |
| Uncontrolled keywords: | ransomware; high-entropy sources; endpoint detection and response systems; randomness; encryption |
| Subjects: | Q Science > QA Mathematics (inc Computing science) > QA 76 Software, computer programming, |
| Institutional Unit: | Schools > School of Computing |
| Former Institutional Unit: |
There are no former institutional units.
|
| Funders: |
Commission européenne (https://ror.org/00k4n6c32)
European Union (https://ror.org/019w4f821) |
| Depositing User: | Darren Hurley-Smith |
| Date Deposited: | 09 Jul 2025 11:27 UTC |
| Last Modified: | 22 Jul 2025 09:23 UTC |
| Resource URI: | https://kar.kent.ac.uk/id/eprint/110567 (The current URI for this page, for reference purposes) |
- Link to SensusAccess
- Export to:
- RefWorks
- EPrints3 XML
- BibTeX
- CSV
- Depositors only (login required):

https://orcid.org/0000-0002-9896-9308
Altmetric
Altmetric