Hierarchical Entropy Disruption for Ransomware Detection: A Computationally-Driven Framework
Hayden Srynn, Gilbert Pomeroy, Florence Lytton, Godfrey Ashcombe, Valentine Harcourt, Duncan Pettigrew

TL;DR
This paper presents a hierarchical entropy disruption framework for ransomware detection that effectively identifies malicious encryption activities by analyzing entropy deviations across system levels, offering high accuracy with low computational cost.
Contribution
It introduces a novel entropy-based detection framework that captures behavioral anomalies at multiple system levels, improving early detection of ransomware variants over traditional methods.
Findings
High detection accuracy across multiple ransomware variants
Low computational overhead suitable for real-time deployment
Resilience against obfuscation techniques in ransomware detection
Abstract
The rapid evolution of encryption-based threats has rendered conventional detection mechanisms increasingly ineffective against sophisticated attack strategies. Monitoring entropy variations across hierarchical system levels offers an alternative approach to identifying unauthorized data modifications without relying on static signatures. A framework leveraging hierarchical entropy disruption was introduced to analyze deviations in entropy distributions, capturing behavioral anomalies indicative of malicious encryption operations. Evaluating the framework across multiple ransomware variants demonstrated its capability to achieve high detection accuracy while maintaining minimal computational overhead. Entropy distributions across different system directories revealed that encryption activities predominantly targeted user-accessible files, aligning with observed attacker strategies.…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Network Security and Intrusion Detection · Spam and Phishing Detection
