LIMITS OF ENTROPY-BASED RANSOMWARE DETECTION: SEPARATING ENCRYPTED FROM COMPRESSED FRAGMENTS
DOI:
https://doi.org/10.37943/HOJD6191Keywords:
ransomware detection; Shannon entropy; chi-square test; encrypted data; compressed data; file fragment classification; intermittent encryption; digital forensics; random forestAbstract
Ransomware detectors and forensic tools often treat a file or disk block as encrypted when its Shannon entropy approaches 8 bits per byte. Compressed formats reach almost the same entropy, which causes false alarms, and partial encryption or text encoding of the ciphertext can lower entropy below common thresholds. This study measures how far byte-level statistics separate encrypted from compressed data and how the answer depends on fragment size. A corpus of 595 files in 17 formats, including Deflate, bzip2 and LZMA compressed archives, documents and images, was built from the Govdocs1 collection and encrypted with AES-256 or ChaCha20; evasion variants used intermittent encryption, Base64 encoding and encryption of the first megabyte. Fragments of 512 bytes, 4 kilobytes and 64 kilobytes were described by entropy, the chi-square statistic and four further byte statistics, and threshold rules, logistic regression and random forest were evaluated with cross-validation grouped by file. Entropy and chi-square ranked fragments almost identically, as expected from their known asymptotic equivalence, so chi-square did not separate the classes better; its advantage was a size-independent threshold. A fixed entropy threshold of 7.9 bits per byte missed every encrypted 512-byte fragment and flagged 73% of unencrypted 64-kilobyte fragments. Deflate-based formats became separable only with large fragments, whereas xz and 7z archives remained close to chance for every method. Base64 encoding removed detection completely, and intermittent encryption was rarely detected in large fragments of uncompressed files. Byte statistics can therefore show that data are not plaintext but cannot confirm that compressed data are encrypted; detectors need size-aware thresholds, decoding of text encodings and format validation.
References
Oz, H., Aris, A., Levi, A., & Uluagac, A. S. (2022). A survey on ransomware: Evolution, taxonomy, and defense solutions. ACM Computing Surveys, 54(11s), Article 238. https://doi.org/10.1145/3514229
McIntosh, T., Susnjak, T., Liu, T., Xu, D., Watters, P., Liu, D., Hao, Y., Ng, A., & Halgamuge, M. (2024). Ransomware reloaded: Re-examining its trend, research and mitigation in the era of data exfiltration. ACM Computing Surveys, 57(1), Article 18. https://doi.org/10.1145/3691340
Begovic, K., Al-Ali, A., & Malluhi, Q. (2023). Cryptographic ransomware encryption detection: Survey. Computers & Security, 132, Article 103349. https://doi.org/10.1016/j.cose.2023.103349
Cen, M., Jiang, F., Qin, X., Jiang, Q., & Doss, R. (2024). Ransomware early detection: A survey. Computer Networks, 239, Article 110138. https://doi.org/10.1016/j.comnet.2023.110138
McIntosh, T., Kayes, A. S. M., Chen, Y.-P. P., Ng, A., & Watters, P. (2021). Ransomware mitigation in the modern era: A comprehensive review, research challenges, and future directions. ACM Computing Surveys, 54(9), Article 197. https://doi.org/10.1145/3479393
Scaife, N., Carter, H., Traynor, P., & Butler, K. R. B. (2016). CryptoLock (and drop it): Stopping ransomware attacks on user data. In 2016 IEEE 36th International Conference on Distributed Computing Systems (ICDCS) (pp. 303-312). IEEE. https://doi.org/10.1109/ICDCS.2016.46
Continella, A., Guagnelli, A., Zingaro, G., De Pasquale, G., Barenghi, A., Zanero, S., & Maggi, F. (2016). ShieldFS: A self-healing, ransomware-aware filesystem. In Proceedings of the 32nd Annual Conference on Computer Security Applications (ACSAC '16) (pp. 336-347). Association for Computing Machinery. https://doi.org/10.1145/2991079.2991110
Kharraz, A., Arshad, S., Mulliner, C., Robertson, W., & Kirda, E. (2016). UNVEIL: A large-scale, automated approach to detecting ransomware. In Proceedings of the 25th USENIX Security Symposium (pp. 757-772). USENIX Association. https://www.usenix.org/conference/usenixsecurity16/technical-sessions/presentation/kharaz
Lee, K., Lee, J., Lee, S.-Y., & Yim, K. (2023). Effective ransomware detection using entropy estimation of files for cloud services. Sensors, 23(6), Article 3023. https://doi.org/10.3390/s23063023
Skračić, K., Petrović, J., & Pale, P. (2023). Classification of low- and high-entropy file fragments using randomness measures and discrete Fourier transform coefficients. Vietnam Journal of Computer Science, 10(4), 433-462. https://doi.org/10.1142/S2196888823500070
Pont, J., Arief, B., & Hernandez-Castro, J. (2020). Why current statistical approaches to ransomware detection fail. In W. Susilo, R. H. Deng, F. Guo, Y. Li, & R. Intan (Eds.), Information security: 23rd International Conference, ISC 2020, proceedings (Lecture Notes in Computer Science, Vol. 12472, pp. 199-216). Springer. https://doi.org/10.1007/978-3-030-62974-8_12
Davies, S. R., Macfarlane, R., & Buchanan, W. J. (2021). Differential area analysis for ransomware attack detection within mixed file datasets. Computers & Security, 108, Article 102377. https://doi.org/10.1016/j.cose.2021.102377
Davies, S. R., Macfarlane, R., & Buchanan, W. J. (2022). Comparison of entropy calculation methods for ransomware encrypted file identification. Entropy, 24(10), Article 1503. https://doi.org/10.3390/e24101503
Davies, S. R., Macfarlane, R., & Buchanan, W. J. (2022). NapierOne: A modern mixed file data set alternative to Govdocs1. Forensic Science International: Digital Investigation, 40, Article 301330. https://doi.org/10.1016/j.fsidi.2021.301330
Casino, F., Choo, K.-K. R., & Patsakis, C. (2019). HEDGE: Efficient traffic classification of encrypted and compressed packets. IEEE Transactions on Information Forensics and Security, 14(11), 2916-2926. https://doi.org/10.1109/TIFS.2019.2911156
Casino, F., Hurley-Smith, D., Hernandez-Castro, J., & Patsakis, C. (2025). Not on my watch: Ransomware detection through classification of high-entropy file segments. Journal of Cybersecurity, 11(1), Article tyaf009. https://doi.org/10.1093/cybsec/tyaf009
De Gaspari, F., Hitaj, D., Pagnotta, G., De Carli, L., & Mancini, L. V. (2022). Reliable detection of compressed and encrypted data. Neural Computing and Applications, 34(22), 20379-20393. https://doi.org/10.1007/s00521-022-07586-7
Kurumathur, S. K., Hooker, A., Huang, W., Pataci, H., Vishwamitra, N., & Choo, K.-K. R. (2026). The classification of encrypted and compressed data containers: A systematic survey. Information and Software Technology, 198, Article 108236. https://doi.org/10.1016/j.infsof.2026.108236
Mittal, G., Korus, P., & Memon, N. (2021). FiFTy: Large-scale file fragment type identification using convolutional neural networks. IEEE Transactions on Information Forensics and Security, 16, 28-41. https://doi.org/10.1109/TIFS.2020.3004266
Skračić, K., Petrović, J., & Pale, P. (2023). ByteRCNN: Enhancing file fragment type identification with recurrent and convolutional neural networks. IEEE Access, 11, 138176-138187. https://doi.org/10.1109/ACCESS.2023.3340441
Haque, M. E., & Tozal, M. E. (2022). Byte embeddings for file fragment classification. Future Generation Computer Systems, 127, 448-461. https://doi.org/10.1016/j.future.2021.09.019
Zou, B., & Liu, H. (2026). Hierarchical deep learning for file fragment classification. Electronics, 15(7), Article 1507. https://doi.org/10.3390/electronics15071507
Loman, M. (2021, August 27). LockFile ransomware's box of tricks: Intermittent encryption and evasion. Sophos. https://www.sophos.com/en-us/blog/lockfile-ransomwares-box-of-tricks-intermittent-encryption-and-evasion
Milenkoski, A., & Walter, J. (2022, September 8). Crimeware trends: Ransomware developers turn to intermittent encryption to evade detection. SentinelLabs. https://www.sentinelone.com/labs/crimeware-trends-ransomware-developers-turn-to-intermittent-encryption-to-evade-detection/
Mahboubi, A., Aboutorab, H., Camtepe, S., Bui, H. T., Luong, K., Ansari, K., Wang, S., & Barry, B. (2025). Ransomware encryption detection: Adaptive file system analysis against evasive encryption tactics. In W. Susilo & J. Pieprzyk (Eds.), Information security and privacy: 30th Australasian Conference, ACISP 2025, proceedings, part III (Lecture Notes in Computer Science, Vol. 15660, pp. 399-414). Springer. https://doi.org/10.1007/978-981-96-9101-2_21
Lee, J., & Lee, K. (2022). A method for neutralizing entropy measurement-based ransomware detection technologies using encoding algorithms. Entropy, 24(2), Article 239. https://doi.org/10.3390/e24020239
Lee, J., Lee, S.-Y., Yim, K., & Lee, K. (2023). Neutralization method of ransomware detection technology using format preserving encryption. Sensors, 23(10), Article 4728. https://doi.org/10.3390/s23104728
Bang, J., Kim, J. N., & Lee, S. (2024). Entropy sharing in ransomware: Bypassing entropy-based detection of cryptographic operations. Sensors, 24(5), Article 1446. https://doi.org/10.3390/s24051446
Lee, J., Yun, J., & Lee, K. (2024). A study on countermeasures against neutralizing technology: Encoding algorithm-based ransomware detection methods using machine learning. Electronics, 13(6), Article 1030. https://doi.org/10.3390/electronics13061030
De Gaspari, F., Hitaj, D., Pagnotta, G., De Carli, L., & Mancini, L. V. (2022). Evading behavioral classifiers: A comprehensive analysis on evading ransomware detection techniques. Neural Computing and Applications, 34(14), 12077-12096. https://doi.org/10.1007/s00521-022-07096-6
Digital Corpora. (n.d.). Govdocs1 [Data set]. Retrieved September 19, 2026, from https://digitalcorpora.org/corpora/file-corpora/files/
Shannon, C. E. (1948). A mathematical theory of communication. Bell System Technical Journal, 27(3), 379-423. https://doi.org/10.1002/j.1538-7305.1948.tb01338.x
Agresti, A. (2018). An introduction to categorical data analysis (3rd ed.). Wiley.
Contreras Rodríguez, L., Madarro-Capó, E. J., Legón-Pérez, C. M., Rojas, O., & Sosa-Gómez, G. (2021). Selecting an effective entropy estimator for short sequences of bits and bytes with Metric Entropy. Entropy, 23(5), Article 561. https://doi.org/10.3390/e23050561
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Articles are open access under the Creative Commons License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Authors who publish a manuscript in this journal agree to the following terms:
- The authors reserve the right to authorship of their work and transfer to the journal the right of first publication under the terms of the Creative Commons Attribution License, which allows others to freely distribute the published work with a mandatory link to the the original work and the first publication of the work in this journal.
- Authors have the right to conclude independent additional agreements that relate to the non-exclusive distribution of the work in the form in which it was published by this journal (for example, to post the work in the electronic repository of the institution or publish as part of a monograph), providing the link to the first publication of the work in this journal.
- Other terms stated in the Copyright Agreement.