CrossSentry: A Cross-Layer Approach to Ransomware Detection in IoT

Farhad Mofidi, Sena G Hounsinou, Gedare Bloom · 2025

The continuous growth of devices of the Internet of Things (IoT) has increased the risk of ransomware attacks. Conventional detection techniques rely on more specific data sources, and isolated layers typically prove insufficient in com-plex, resource-constrained environments like IoT systems. In this work, we present CrossSentry, a cross-layer detection framework that employs metrics from perception, network, and middleware layers to enhance detection accuracy and reduce false positives. CrossSentry integrates a weighted ensemble of anomaly detection algorithms to tie up multiple indicators of file system alterations, network traffic changes, and hardware performance counters into decision-making. The system uses statistical techniques like Z-Score normalization with machine learning approaches (Isolation Forest, One-Class Support Vector Machine, and Local Outlier Factor) to detect even slight ransomware-indicative behaviors. Central to CrossSentry is the adaptive decision mechanism that accords layer-specific importance in real time; thus, ensuring op-timal performance even when computationally challenged. Using knowledge across several layers of the IoT stack, CrossSentry not only addresses the fragmentation inherent in existing detection methods but also lays a scalable foundation for future validation and practical deployment in diverse IoT systems. This paper examines the theoretical basis, architectural innovation, and empirical potential of CrossSentry, thus providing an alternative to ransomware defense in an increasingly distributed dynamic IoT environment.

Read the paper · More papers on PaperTik