LIMITS OF ENTROPY-BASED RANSOMWARE DETECTION: SEPARATING ENCRYPTED FROM COMPRESSED FRAGMENTS

Authors

DOI:

https://doi.org/10.37943/HOJD6191

Keywords:

ransomware detection; Shannon entropy; chi-square test; encrypted data; compressed data; file fragment classification; intermittent encryption; digital forensics; random forest

Abstract

Ransomware detectors and forensic tools often treat a file or disk block as encrypted when its Shannon entropy approaches 8 bits per byte. Compressed formats reach almost the same entropy, which causes false alarms, and partial encryption or text encoding of the ciphertext can lower entropy below common thresholds. This study measures how far byte-level statistics separate encrypted from compressed data and how the answer depends on fragment size. A corpus of 595 files in 17 formats, including Deflate, bzip2 and LZMA compressed archives, documents and images, was built from the Govdocs1 collection and encrypted with AES-256 or ChaCha20; evasion variants used intermittent encryption, Base64 encoding and encryption of the first megabyte. Fragments of 512 bytes, 4 kilobytes and 64 kilobytes were described by entropy, the chi-square statistic and four further byte statistics, and threshold rules, logistic regression and random forest were evaluated with cross-validation grouped by file. Entropy and chi-square ranked fragments almost identically, as expected from their known asymptotic equivalence, so chi-square did not separate the classes better; its advantage was a size-independent threshold. A fixed entropy threshold of 7.9 bits per byte missed every encrypted 512-byte fragment and flagged 73% of unencrypted 64-kilobyte fragments. Deflate-based formats became separable only with large fragments, whereas xz and 7z archives remained close to chance for every method. Base64 encoding removed detection completely, and intermittent encryption was rarely detected in large fragments of uncompressed files. Byte statistics can therefore show that data are not plaintext but cannot confirm that compressed data are encrypted; detectors need size-aware thresholds, decoding of text encodings and format validation.

References

Oz, H., Aris, A., Levi, A., & Uluagac, A. S. (2022). A survey on ransomware: Evolution, taxonomy, and defense solutions. ACM Computing Surveys, 54(11s), Article 238. https://doi.org/10.1145/3514229

McIntosh, T., Susnjak, T., Liu, T., Xu, D., Watters, P., Liu, D., Hao, Y., Ng, A., & Halgamuge, M. (2024). Ransomware reloaded: Re-examining its trend, research and mitigation in the era of data exfiltration. ACM Computing Surveys, 57(1), Article 18. https://doi.org/10.1145/3691340

Begovic, K., Al-Ali, A., & Malluhi, Q. (2023). Cryptographic ransomware encryption detection: Survey. Computers & Security, 132, Article 103349. https://doi.org/10.1016/j.cose.2023.103349

Cen, M., Jiang, F., Qin, X., Jiang, Q., & Doss, R. (2024). Ransomware early detection: A survey. Computer Networks, 239, Article 110138. https://doi.org/10.1016/j.comnet.2023.110138

McIntosh, T., Kayes, A. S. M., Chen, Y.-P. P., Ng, A., & Watters, P. (2021). Ransomware mitigation in the modern era: A comprehensive review, research challenges, and future directions. ACM Computing Surveys, 54(9), Article 197. https://doi.org/10.1145/3479393

Scaife, N., Carter, H., Traynor, P., & Butler, K. R. B. (2016). CryptoLock (and drop it): Stopping ransomware attacks on user data. In 2016 IEEE 36th International Conference on Distributed Computing Systems (ICDCS) (pp. 303-312). IEEE. https://doi.org/10.1109/ICDCS.2016.46

Continella, A., Guagnelli, A., Zingaro, G., De Pasquale, G., Barenghi, A., Zanero, S., & Maggi, F. (2016). ShieldFS: A self-healing, ransomware-aware filesystem. In Proceedings of the 32nd Annual Conference on Computer Security Applications (ACSAC '16) (pp. 336-347). Association for Computing Machinery. https://doi.org/10.1145/2991079.2991110

Kharraz, A., Arshad, S., Mulliner, C., Robertson, W., & Kirda, E. (2016). UNVEIL: A large-scale, automated approach to detecting ransomware. In Proceedings of the 25th USENIX Security Symposium (pp. 757-772). USENIX Association. https://www.usenix.org/conference/usenixsecurity16/technical-sessions/presentation/kharaz

Lee, K., Lee, J., Lee, S.-Y., & Yim, K. (2023). Effective ransomware detection using entropy estimation of files for cloud services. Sensors, 23(6), Article 3023. https://doi.org/10.3390/s23063023

Skračić, K., Petrović, J., & Pale, P. (2023). Classification of low- and high-entropy file fragments using randomness measures and discrete Fourier transform coefficients. Vietnam Journal of Computer Science, 10(4), 433-462. https://doi.org/10.1142/S2196888823500070

Pont, J., Arief, B., & Hernandez-Castro, J. (2020). Why current statistical approaches to ransomware detection fail. In W. Susilo, R. H. Deng, F. Guo, Y. Li, & R. Intan (Eds.), Information security: 23rd International Conference, ISC 2020, proceedings (Lecture Notes in Computer Science, Vol. 12472, pp. 199-216). Springer. https://doi.org/10.1007/978-3-030-62974-8_12

Davies, S. R., Macfarlane, R., & Buchanan, W. J. (2021). Differential area analysis for ransomware attack detection within mixed file datasets. Computers & Security, 108, Article 102377. https://doi.org/10.1016/j.cose.2021.102377

Davies, S. R., Macfarlane, R., & Buchanan, W. J. (2022). Comparison of entropy calculation methods for ransomware encrypted file identification. Entropy, 24(10), Article 1503. https://doi.org/10.3390/e24101503

Davies, S. R., Macfarlane, R., & Buchanan, W. J. (2022). NapierOne: A modern mixed file data set alternative to Govdocs1. Forensic Science International: Digital Investigation, 40, Article 301330. https://doi.org/10.1016/j.fsidi.2021.301330

Casino, F., Choo, K.-K. R., & Patsakis, C. (2019). HEDGE: Efficient traffic classification of encrypted and compressed packets. IEEE Transactions on Information Forensics and Security, 14(11), 2916-2926. https://doi.org/10.1109/TIFS.2019.2911156

Casino, F., Hurley-Smith, D., Hernandez-Castro, J., & Patsakis, C. (2025). Not on my watch: Ransomware detection through classification of high-entropy file segments. Journal of Cybersecurity, 11(1), Article tyaf009. https://doi.org/10.1093/cybsec/tyaf009

De Gaspari, F., Hitaj, D., Pagnotta, G., De Carli, L., & Mancini, L. V. (2022). Reliable detection of compressed and encrypted data. Neural Computing and Applications, 34(22), 20379-20393. https://doi.org/10.1007/s00521-022-07586-7

Kurumathur, S. K., Hooker, A., Huang, W., Pataci, H., Vishwamitra, N., & Choo, K.-K. R. (2026). The classification of encrypted and compressed data containers: A systematic survey. Information and Software Technology, 198, Article 108236. https://doi.org/10.1016/j.infsof.2026.108236

Mittal, G., Korus, P., & Memon, N. (2021). FiFTy: Large-scale file fragment type identification using convolutional neural networks. IEEE Transactions on Information Forensics and Security, 16, 28-41. https://doi.org/10.1109/TIFS.2020.3004266

Skračić, K., Petrović, J., & Pale, P. (2023). ByteRCNN: Enhancing file fragment type identification with recurrent and convolutional neural networks. IEEE Access, 11, 138176-138187. https://doi.org/10.1109/ACCESS.2023.3340441

Haque, M. E., & Tozal, M. E. (2022). Byte embeddings for file fragment classification. Future Generation Computer Systems, 127, 448-461. https://doi.org/10.1016/j.future.2021.09.019

Zou, B., & Liu, H. (2026). Hierarchical deep learning for file fragment classification. Electronics, 15(7), Article 1507. https://doi.org/10.3390/electronics15071507

Loman, M. (2021, August 27). LockFile ransomware's box of tricks: Intermittent encryption and evasion. Sophos. https://www.sophos.com/en-us/blog/lockfile-ransomwares-box-of-tricks-intermittent-encryption-and-evasion

Milenkoski, A., & Walter, J. (2022, September 8). Crimeware trends: Ransomware developers turn to intermittent encryption to evade detection. SentinelLabs. https://www.sentinelone.com/labs/crimeware-trends-ransomware-developers-turn-to-intermittent-encryption-to-evade-detection/

Mahboubi, A., Aboutorab, H., Camtepe, S., Bui, H. T., Luong, K., Ansari, K., Wang, S., & Barry, B. (2025). Ransomware encryption detection: Adaptive file system analysis against evasive encryption tactics. In W. Susilo & J. Pieprzyk (Eds.), Information security and privacy: 30th Australasian Conference, ACISP 2025, proceedings, part III (Lecture Notes in Computer Science, Vol. 15660, pp. 399-414). Springer. https://doi.org/10.1007/978-981-96-9101-2_21

Lee, J., & Lee, K. (2022). A method for neutralizing entropy measurement-based ransomware detection technologies using encoding algorithms. Entropy, 24(2), Article 239. https://doi.org/10.3390/e24020239

Lee, J., Lee, S.-Y., Yim, K., & Lee, K. (2023). Neutralization method of ransomware detection technology using format preserving encryption. Sensors, 23(10), Article 4728. https://doi.org/10.3390/s23104728

Bang, J., Kim, J. N., & Lee, S. (2024). Entropy sharing in ransomware: Bypassing entropy-based detection of cryptographic operations. Sensors, 24(5), Article 1446. https://doi.org/10.3390/s24051446

Lee, J., Yun, J., & Lee, K. (2024). A study on countermeasures against neutralizing technology: Encoding algorithm-based ransomware detection methods using machine learning. Electronics, 13(6), Article 1030. https://doi.org/10.3390/electronics13061030

De Gaspari, F., Hitaj, D., Pagnotta, G., De Carli, L., & Mancini, L. V. (2022). Evading behavioral classifiers: A comprehensive analysis on evading ransomware detection techniques. Neural Computing and Applications, 34(14), 12077-12096. https://doi.org/10.1007/s00521-022-07096-6

Digital Corpora. (n.d.). Govdocs1 [Data set]. Retrieved September 19, 2026, from https://digitalcorpora.org/corpora/file-corpora/files/

Shannon, C. E. (1948). A mathematical theory of communication. Bell System Technical Journal, 27(3), 379-423. https://doi.org/10.1002/j.1538-7305.1948.tb01338.x

Agresti, A. (2018). An introduction to categorical data analysis (3rd ed.). Wiley.

Contreras Rodríguez, L., Madarro-Capó, E. J., Legón-Pérez, C. M., Rojas, O., & Sosa-Gómez, G. (2021). Selecting an effective entropy estimator for short sequences of bits and bytes with Metric Entropy. Entropy, 23(5), Article 561. https://doi.org/10.3390/e23050561

Downloads

Published

2026-09-30

How to Cite

Kiyashko, I. ., Zhumadilla, B., Konyrbaev, N., & Jussupova, G. (2026). LIMITS OF ENTROPY-BASED RANSOMWARE DETECTION: SEPARATING ENCRYPTED FROM COMPRESSED FRAGMENTS. Scientific Journal of Astana IT University, 27(3), 325–340. https://doi.org/10.37943/HOJD6191

Issue

Section

Cybersecurity