Skip to content
Open access

Real-Time Endpoint Ransomware Detection and Prevention via Strategic Deception Directories and Block-Level Entropy Analysis

2026 · International journal of research and innovation in applied science · 0 citations

TL;DR

A lightweight host-based ransomware detection and prevention prototype for Windows endpoints that combines three mechanisms: strategically placed deception directories (1000_Trap), localized Shannon-entropy analysis, and automated process termination using psutil is presented.

Abstract

Ransomware remains a major endpoint-security threat because destructive file operations can progress rapidly and modern attacks may use fileless execution and Living-off-the-Land (LotL) techniques. This paper presents a lightweight host-based ransomware detection and prevention prototype for Windows endpoints that combines three mechanisms: strategically placed deception directories (1000_Trap), localized Shannon-entropy analysis, and automated process termination using psutil. The prototype was evaluated in a controlled Windows 10 virtual-machine testbed using the PSRansom simulator across 50 executions. Under this specific PSRansom configuration, all 50 runs were detected, 5-15 decoy files were encrypted before termination, and no protected user files in Desktop, Documents, Downloads, or Pictures were modified. Mean end-to-end containment latency was approximately 5 s, with observed active-phase values ranging from 4820 to 5150 ms, reflecting user-space event-queue and process-handling overhead. Idle CPU utilization remained below 5%. The benign workload cases evaluated in this study, ZIP compression, document editing, spreadsheet processing, media playback, and PDF generation, produced no mitigation events. These results demonstrate feasibility within the tested PSRansom scenario rather than general robustness against all ransomware families or traversal strategies. Random or selective traversal, multi-process encryption, intermittent encryption, privilege escalation, and user-space evasion were not experimentally validated and are treated as limitations and priorities for future evaluation.

Read PDF

Similar papers

Open access Sep 2026

Implementation of Ransomware Threat Detection Using Behavior-Based Detection Algorithm

It is suggested that the behavioral identification engine be combined into Endpoint Identification and Response (EDR) platforms to promote intelligent threat containment, increase incident response, and reduce the danger of data loss.

Kazeem O. N., Abdul Kareem Olaitan Mummen, Shamsudeen Sani Saleh · 0 citations
Preprint Aug 2026

SSHafe: A Real-Time SSH Brute Force Attack Detection and Novel Credential Rotation Standard

The proposed novel password reset standard performs authentication and password update in a single cryptographically bound flow, eliminating the need for sessions, cookies, OTPs, or email-based verification, and mitigating phishing, session hijacking, CSRF, and replay attacks.

Aditya Mitra, Amar Kumar Mandal, Amaan Rais Shah et al. · 0 citations
Conference Aug 2026

Real-Time DDoS Detection by Integrated eBPF Telemetry and Machine Learning-enhanced SIEM

Distributed Denial-of-Service (DDoS) attacks remain one of the most disruptive threats to modern web services, overwhelming application resources and degrading service availability. This paper presents a lightweight, virtualized system architecture for real-time DDoS detection that combines kernellevel telemetry collec...

Dr Zeeshan Ali, A. Marotta, W. Tiberti et al. · 0 citations
Open access Sep 2026

AI-Augmented Network-Forensics: Leveraging LLMs for Real-Time Threat Detection and Automated Response in Enterprise Environments

In modern enterprise networks, complicated rule-based signatures, fragmented alerts, encrypted traffic, and analyst workloads are delaying the ability to recognize and contain incidents, as the need grows for faster correlation of heterogeneous telemetry. This study evaluates an LLM-augmented network-forensics architec...

Mohammed Imran Choudhary · 0 citations
Conference Open access Sep 2026

DCSYNC ATTACK FROM AN ADVERSARY POINT OF VIEW

This paper examines the DCSync attack from an adversarial perspective, analysing its operational logic, execution variants, and the detection surface each variant presents within monitored Active Directory environments. The study was conducted in a controlled laboratory environment comprising a Windows Server 2019 doma...

Dimitar Nikolov · 0 citations
Open access Sep 2026

Anomaly-Based Intrusion Detection for IoT Microcontrollers Using Power Side-Channel Fingerprinting

This study introduces a unified evaluation framework for device-level intrusion detection using power side-channel fingerprints under an open-set threat model. We target post-enrollment device substitution: an adversary replaces a legitimate Commercial Off-The-Shelf (COTS) node with a counterfeit of the same model and...

S. M. H. Shukry, Frank Kargl, Tallal Elshabrawy et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.