Neural Encrypted State Transduction for Ransomware Classification: A Novel Approach Using Cryptographic Flow Residuals
Barnaby Fortescue, Edmund Hawksmoor, Alistair Wetherington, Frederick Marlowe, Kevin Pekepok

TL;DR
This paper introduces NEST, a neural transduction framework analyzing cryptographic flow residuals to classify ransomware effectively without decrypting execution traces, demonstrating high accuracy and robustness against obfuscation techniques.
Contribution
The paper presents a novel neural encrypted state transduction method that improves ransomware detection by analyzing encrypted flow residuals, resilient to evasion tactics and obfuscation.
Findings
Achieves higher detection accuracy across multiple ransomware families.
Demonstrates robustness against adversarial perturbations and unseen variants.
Maintains efficient processing suitable for large-scale deployment.
Abstract
Encrypted behavioral patterns provide a unique avenue for classifying complex digital threats without reliance on explicit feature extraction, enabling detection frameworks to remain effective even when conventional static and behavioral methodologies fail. A novel approach based on Neural Encrypted State Transduction (NEST) is introduced to analyze cryptographic flow residuals and classify threats through their encrypted state transitions, mitigating evasion tactics employed through polymorphic and obfuscated attack strategies. The mathematical formulation of NEST leverages transduction principles to map state transitions dynamically, enabling high-confidence classification without requiring direct access to decrypted execution traces. Experimental evaluations demonstrate that the proposed framework achieves improved detection accuracy across multiple ransomware families while…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Chaos-based Image/Signal Encryption · Network Security and Intrusion Detection
