Detecting Ransomware via Hybrid Entropic Behavior Monitoring (HEBM)
John Hamill, Alejandro Villareal, Rafael Costanzo, Dominic Van Dermeer, Gregor Ivanovich, Hugo Macpherson · 2024
Ransomware attacks have grown increasingly sophisticated, leveraging advanced encryption techniques and evolving rapidly to bypass traditional detection mechanisms. The need for real-time, autonomous detection systems has never been more critical, and the Hybrid Entropic Behavior Monitoring (HEBM) framework addresses this challenge through a novel combination of entropy deviation monitoring and dynamic behavioral profiling. By detecting significant changes in file entropy and correlating them with behavioral anomalies, HEBM offers a robust solution for identifying both known and novel ransomware variants without reliance on predefined signatures. Experimental results demonstrate that the duallayered approach of HEBM not only enhances detection accuracy but also reduces false positives compared to existing methods. Its machine learning-based behavioral analysis ensures adaptability to new ransomware tactics, while maintaining computational efficiency. The proposed system operates autonomously, providing scalable ransomware protection for a wide range of real-world applications. Additionally, areas for future improvement, such as integrating memory analysis for fileless attacks and optimizing computational overhead, present exciting avenues for extending the framework's capabilities.