arXiv · 2510.15133
Intermittent File Encryption in Ransomware: Measurement, Modeling, and Detection
Abstract
File-encrypting ransomware increasingly employs intermittent encryption techniques, encrypting only parts of files to evade classical detection methods.This paper provides a systematic empirical characterization of byte-level statistics under intermittent encryption across common file types, establishing a baseline for how partial encryption reshapes data structure. Guided by these measurements, we model intermittent encryption as a convex mixture of ciphertext and cleartext and, via a classical KL-divergence bound, derive file-type-specific detectability limits for histogram-based detectors. Leveraging these insights, we evaluate convolutional neural network (CNN) detectors trained on realistic intermittent-encryption configurations from leading ransomware families. Our findings show that localized, chunk-level CNNs consistently outperform whole-file analysis, highlighting a practical, robust baseline for future detection systems.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Ynes Ineza, Gerald Jackson, Prince Niyonkuru, Jaden Kevil, Abdul Serwadda. 2025-10-16. Intermittent File Encryption in Ransomware: Measurement, Modeling, and Detection. https://arxiv.org/abs/2510.15133
Cite the original work for its findings. Save a collection to share your selection of sources.