Detecting Ransomware via Hybrid Entropic Behavior Monitoring (HEBM)
preprint
OA: closed
CC-BY-NC-ND-4.0
Abstract
Ransomware attacks have grown increasingly sophisticated, leveraging advanced encryption techniques and evolving rapidly to bypass traditional detection mechanisms. The need for real-time, autonomous detection systems has never been more critical, and the Hybrid Entropic Behavior Monitoring (HEBM) framework addresses this challenge through a novel combination of entropy deviation monitoring and dynamic behavioral profiling. By detecting significant changes in file entropy and correlating them with behavioral anomalies, HEBM offers a robust solution for identifying both known and novel ransomware variants without reliance on predefined signatures. Experimental results demonstrate that the duallayered approach of HEBM not only enhances detection accuracy but also reduces false positives compared to existing methods. Its machine learning-based behavioral analysis ensures adaptability to new ransomware tactics, while maintaining computational efficiency. The proposed system operates autonomously, providing scalable ransomware protection for a wide range of real-world applications. Additionally, areas for future improvement, such as integrating memory analysis for fileless attacks and optimizing computational overhead, present exciting avenues for extending the framework's capabilities.
My notes (saved in your browser only)
Citation neighborhood (no data yet)
We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2024) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.
Source provenance
- europepmc
- last seen: 2026-05-20T01:45:00.602351+00:00
- unpaywall
- last seen: 2026-05-22T02:00:06.705733+00:00
License: CC-BY-NC-ND-4.0