Hierarchical Cryptographic Signature Mapping for Ransomware Classification: A Structural Decomposition Approach
Dominic Abernethy, Nathaniel Weatherstone, Tristan Ravensdale, Lafedi Svet

TL;DR
This paper introduces a hierarchical cryptographic signature mapping framework that decomposes encryption workflows to improve ransomware classification accuracy and robustness against evolving threats.
Contribution
It presents a novel structural decomposition approach for cryptographic analysis, enhancing detection of malicious encryption beyond traditional signature-based methods.
Findings
High classification precision across multiple attack families
Outperforms conventional techniques in accuracy and efficiency
Facilitates forensic analysis and threat attribution
Abstract
Encryption-based cyber threats continue to evolve, leveraging increasingly sophisticated cryptographic techniques to evade detection and persist within compromised systems. A hierarchical classification framework designed to analyze structural cryptographic properties provides a novel approach to distinguishing malicious encryption from legitimate cryptographic operations. By systematically decomposing encryption workflows into hierarchical layers, the classification method enhances the ability to recognize distinct patterns across diverse threat variants, reducing the dependence on predefined signatures that often fail against rapidly mutating threats. The study examines how cryptographic feature mapping facilitates improved classification accuracy, highlighting the role of entropy, key exchange mechanisms, and algorithmic dependencies in distinguishing harmful encryption activities.…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Spam and Phishing Detection · Network Security and Intrusion Detection
