Intermittent File Encryption in Ransomware: Measurement, Modeling, and Detection
Systematic analysis of intermittent file encryption reveals why modern ransomware evades classical entropy-based detection, and proposes statistical models for more resilient identification.
Summary written by editorial AI · Source link below
arXiv:2510.15133v3 Announce Type: replace Abstract: File-encrypting ransomware increasingly employs intermittent encryption techniques, encrypting only parts of files to evade classical detection methods.This paper provides a systematic empirical characterization of byte-level statistics under intermittent encryption across common file types, establishing a baseline for how partial encryption reshapes data structure. Guided by these measurements, we model intermittent encryption as a convex m
Editorial Analysis
Intermittent encryption is becoming the norm in ransomware; enterprises relying on legacy entropy-based detection face growing blind spots that this research helps address.
Evaluate your endpoint detection stack against intermittent encryption scenarios and integrate updated statistical detection models.
Modern ransomware increasingly uses partial file encryption to evade detection—security teams need updated detection approaches.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at arXiv Crypto & Security in a new tab.
More from the Research Desk
- 39 New Methods That Compromise Passkey Authentication3d
- Security Vulnerability in a Voting System3d
- Selfie-Capture Dynamics as an Auxiliary Signal Against Deepfakes and Injection Attacks for Mobile Identity Verification4d
- How Reliable Is the Multi-Input Heuristic for Bitcoin Address Clustering in Law Enforcement Contexts?4d
- Privacy Leakage in Federated Learning: Gradient-Based Client Identity Inference and Defenses for Inertial Sensing in Vehicular Edge Networks4d