AUTHOREA
Log in Sign Up Browse Preprints
LOG IN SIGN UP
Stephen Venne
Stephen Venne

Public Documents 1
Automated Ransomware Detection using Pattern-Entropy Segmentation Analysis: A Novel A...
Stephen Venne

Stephen Venne

and 5 more

October 22, 2024
Ransomware continues to pose a significant and evolving threat to organizations, exploiting vulnerabilities in network security to encrypt sensitive data and demand ransom. A novel approach is introduced in this research through the Pattern-Entropy Segmentation Analysis (PESA) framework, which enhances detection capabilities through real-time entropy analysis of network traffic, offering a more granular and timely identification of ransomware. Unlike traditional signature or behavior-based methods, PESA identifies early-stage anomalies caused by ransomware encryption processes through entropy fluctuations, ensuring rapid detection before critical damage occurs. The framework is evaluated in a controlled network simulation environment, demonstrating its ability to maintain high detection accuracy across multiple ransomware strains, with minimal false positives and rapid response times. Furthermore, the system shows resilience against obfuscation techniques, making it a robust solution for real-world cybersecurity applications. The findings underscore the practical impact of entropy-based detection in strengthening network defenses and mitigating the damage caused by ransomware attacks.

| Powered by Authorea.com

  • Home