













Abstract:File-encrypting ransomware increasingly employs intermittent encryption techniques, encrypting only parts of files to evade classical detection this http URL paper provides a systematic empirical characterization of byte-level statistics under intermittent encryption across common file types, establishing a baseline for how partial encryption reshapes data structure.
Guided by these measurements, we model intermittent encryption as a convex mixture of ciphertext and cleartext and, via a classical KL-divergence bound, derive file-type-specific detectability limits for histogram-based detectors. Leveraging these insights, we evaluate convolutional neural network (CNN) detectors trained on realistic intermittent-encryption configurations from leading ransomware families. Our findings show that localized, chunk-level CNNs consistently outperform whole-file analysis, highlighting a practical, robust baseline for future detection systems.
From: Ynes Ineza [view email]
[v1]
Thu, 16 Oct 2025 20:48:22 UTC (2,262 KB)
[v2]
Sat, 21 Feb 2026 15:31:27 UTC (843 KB)
[v3]
Sat, 15 Aug 2026 18:33:27 UTC (630 KB)
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。