Skip to main content
Kent Academic Repository

Not on my watch: ransomware detection through classification of high-entropy file segments

Casino, Fran, Hurley-Smith, Darren, Hernandez-Castro, Julio, Patsakis, Constantinos (2025) Not on my watch: ransomware detection through classification of high-entropy file segments. Journal of Cybersecurity, 11 (1). Article Number tyaf009. ISSN 2057-2085. (doi:10.1093/cybsec/tyaf009) (KAR id:110567)

Abstract

The double-edged sword of continuous digitization of services and systems opens the door to a myriad of beneficial opportunities, as well as challenging threats. Currently, ransomware is catalogued as the first threat in cybersecurity due to its impact on organizations, critical infrastructure, industry, and society as a whole. Thus, devoting efforts toward developing methodologies to effectively prevent and mitigate ransomware is crucial. In this article, we present an accurate method to identify encrypted bit streams by differentiating them from other high-entropy streams (e.g. compressed files), which is a critical task to detect potentially malicious file write events on the file system in current operating systems. After extensive evaluation, our findings demonstrate that the proposed solution outperforms the current state of the art in both adaptability and accuracy, enabling it to be integrated into current Endpoint Detection and Response systems.

Item Type: Article
DOI/Identification number: 10.1093/cybsec/tyaf009
Projects: SAFEHORIZON, LAZARUS, ALUNA
Uncontrolled keywords: ransomware; high-entropy sources; endpoint detection and response systems; randomness; encryption
Subjects: Q Science > QA Mathematics (inc Computing science) > QA 76 Software, computer programming,
Institutional Unit: Schools > School of Computing
Former Institutional Unit:
There are no former institutional units.
Funders: Commission européenne (https://ror.org/00k4n6c32)
European Union (https://ror.org/019w4f821)
Depositing User: Darren Hurley-Smith
Date Deposited: 09 Jul 2025 11:27 UTC
Last Modified: 22 Jul 2025 09:23 UTC
Resource URI: https://kar.kent.ac.uk/id/eprint/110567 (The current URI for this page, for reference purposes)

University of Kent Author Information

Hurley-Smith, Darren.

Creator's ORCID: https://orcid.org/0000-0002-9896-9308
CReDIT Contributor Roles: Validation, Software, Writing - original draft
  • Depositors only (login required):

Total unique views of this page since July 2020. For more details click on the image.