paper

Intermittent File Encryption in Ransomware: Measurement, Modeling, and Detection

arXiv:2510.15133

Abstract

File-encrypting ransomware increasingly employs intermittent encryption techniques, encrypting only parts of files to evade classical detection methods.This paper provides a systematic empirical characterization of byte-level statistics under intermittent encryption across common file types, establishing a baseline for how partial encryption reshapes data structure. Guided by these measurements, we model intermittent encryption as a convex mixture of ciphertext and cleartext and, via a classical KL-divergence bound, derive file-type-specific detectability limits for histogram-based detectors. Leveraging these insights, we evaluate convolutional neural network (CNN) detectors trained on realistic intermittent-encryption configurations from leading ransomware families. Our findings show that localized, chunk-level CNNs consistently outperform whole-file analysis, highlighting a practical, robust baseline for future detection systems.

Intermittent File Encryption in Ransomware: Measurement, Modeling, and Detection · wovepaper