{"id":"https://openalex.org/W4307134482","doi":"https://doi.org/10.3390/e24101503","title":"Comparison of Entropy Calculation Methods for Ransomware Encrypted File Identification","display_name":"Comparison of Entropy Calculation Methods for Ransomware Encrypted File Identification","publication_year":2022,"publication_date":"2022-10-21","ids":{"openalex":"https://openalex.org/W4307134482","doi":"https://doi.org/10.3390/e24101503","pmid":"https://pubmed.ncbi.nlm.nih.gov/37420524"},"language":"en","primary_location":{"id":"doi:10.3390/e24101503","is_oa":true,"landing_page_url":"https://doi.org/10.3390/e24101503","pdf_url":"https://www.mdpi.com/1099-4300/24/10/1503/pdf?version=1666747262","source":{"id":"https://openalex.org/S195231649","display_name":"Entropy","issn_l":"1099-4300","issn":["1099-4300"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Entropy","raw_type":"journal-article"},"type":"article","indexed_in":["arxiv","crossref","doaj","pubmed"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://www.mdpi.com/1099-4300/24/10/1503/pdf?version=1666747262","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101475686","display_name":"Simon Davies","orcid":"https://orcid.org/0000-0001-9377-4539"},"institutions":[{"id":"https://openalex.org/I251738","display_name":"Edinburgh Napier University","ror":"https://ror.org/03zjvnn91","country_code":"GB","type":"education","lineage":["https://openalex.org/I251738"]}],"countries":["GB"],"is_corresponding":true,"raw_author_name":"Simon R. Davies","raw_affiliation_strings":["Blockpass ID Lab, School of Computing, Edinburgh Napier University, Edinburgh EH10 5DT, UK"],"raw_orcid":"https://orcid.org/0000-0001-9377-4539","affiliations":[{"raw_affiliation_string":"Blockpass ID Lab, School of Computing, Edinburgh Napier University, Edinburgh EH10 5DT, UK","institution_ids":["https://openalex.org/I251738"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5055358404","display_name":"Richard Macfarlane","orcid":"https://orcid.org/0000-0002-5325-2872"},"institutions":[{"id":"https://openalex.org/I251738","display_name":"Edinburgh Napier University","ror":"https://ror.org/03zjvnn91","country_code":"GB","type":"education","lineage":["https://openalex.org/I251738"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Richard Macfarlane","raw_affiliation_strings":["Blockpass ID Lab, School of Computing, Edinburgh Napier University, Edinburgh EH10 5DT, UK"],"raw_orcid":"https://orcid.org/0000-0002-5325-2872","affiliations":[{"raw_affiliation_string":"Blockpass ID Lab, School of Computing, Edinburgh Napier University, Edinburgh EH10 5DT, UK","institution_ids":["https://openalex.org/I251738"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5068020099","display_name":"William J. Buchanan","orcid":"https://orcid.org/0000-0003-0809-3523"},"institutions":[{"id":"https://openalex.org/I251738","display_name":"Edinburgh Napier University","ror":"https://ror.org/03zjvnn91","country_code":"GB","type":"education","lineage":["https://openalex.org/I251738"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"William J. Buchanan","raw_affiliation_strings":["Blockpass ID Lab, School of Computing, Edinburgh Napier University, Edinburgh EH10 5DT, UK"],"raw_orcid":"https://orcid.org/0000-0003-0809-3523","affiliations":[{"raw_affiliation_string":"Blockpass ID Lab, School of Computing, Edinburgh Napier University, Edinburgh EH10 5DT, UK","institution_ids":["https://openalex.org/I251738"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5101475686"],"corresponding_institution_ids":["https://openalex.org/I251738"],"apc_list":{"value":2000,"currency":"CHF","value_usd":2165},"apc_paid":{"value":2000,"currency":"CHF","value_usd":2165},"fwci":3.7153,"has_fulltext":true,"cited_by_count":26,"citation_normalized_percentile":{"value":0.9410096,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":95,"max":99},"biblio":{"volume":"24","issue":"10","first_page":"1503","last_page":"1503"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.998199999332428,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11017","display_name":"Chaos-based Image/Signal Encryption","score":0.9972000122070312,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.7946803569793701},{"id":"https://openalex.org/keywords/ransomware","display_name":"Ransomware","score":0.7675029039382935},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7129515409469604},{"id":"https://openalex.org/keywords/entropy","display_name":"Entropy (arrow of time)","score":0.5553181767463684},{"id":"https://openalex.org/keywords/identification","display_name":"Identification (biology)","score":0.41275760531425476},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.41138288378715515},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.3664345145225525},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.3395187556743622},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.23222053050994873},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.1764390766620636},{"id":"https://openalex.org/keywords/physics","display_name":"Physics","score":0.11647841334342957}],"concepts":[{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.7946803569793701},{"id":"https://openalex.org/C2777667771","wikidata":"https://www.wikidata.org/wiki/Q926331","display_name":"Ransomware","level":3,"score":0.7675029039382935},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7129515409469604},{"id":"https://openalex.org/C106301342","wikidata":"https://www.wikidata.org/wiki/Q4117933","display_name":"Entropy (arrow of time)","level":2,"score":0.5553181767463684},{"id":"https://openalex.org/C116834253","wikidata":"https://www.wikidata.org/wiki/Q2039217","display_name":"Identification (biology)","level":2,"score":0.41275760531425476},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.41138288378715515},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.3664345145225525},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.3395187556743622},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.23222053050994873},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.1764390766620636},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.11647841334342957},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0},{"id":"https://openalex.org/C59822182","wikidata":"https://www.wikidata.org/wiki/Q441","display_name":"Botany","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0}],"mesh":[],"locations_count":7,"locations":[{"id":"doi:10.3390/e24101503","is_oa":true,"landing_page_url":"https://doi.org/10.3390/e24101503","pdf_url":"https://www.mdpi.com/1099-4300/24/10/1503/pdf?version=1666747262","source":{"id":"https://openalex.org/S195231649","display_name":"Entropy","issn_l":"1099-4300","issn":["1099-4300"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Entropy","raw_type":"journal-article"},{"id":"pmid:37420524","is_oa":false,"landing_page_url":"https://pubmed.ncbi.nlm.nih.gov/37420524","pdf_url":null,"source":{"id":"https://openalex.org/S4306525036","display_name":"PubMed","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Entropy (Basel, Switzerland)","raw_type":null},{"id":"pmh:oai:arXiv.org:2210.13376","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2210.13376","pdf_url":"https://arxiv.org/pdf/2210.13376","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"pmh:oai:doaj.org/article:729dff7eda204260a733f12815fb2c8a","is_oa":true,"landing_page_url":"https://doaj.org/article/729dff7eda204260a733f12815fb2c8a","pdf_url":null,"source":{"id":"https://openalex.org/S4306401280","display_name":"DOAJ (DOAJ: Directory of Open Access Journals)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Entropy, Vol 24, Iss 10, p 1503 (2022)","raw_type":"article"},{"id":"pmh:oai:mdpi.com:/1099-4300/24/10/1503/","is_oa":true,"landing_page_url":"https://dx.doi.org/10.3390/e24101503","pdf_url":null,"source":{"id":"https://openalex.org/S4306400947","display_name":"MDPI (MDPI AG)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4210097602","host_organization_name":"Multidisciplinary Digital Publishing Institute (Switzerland)","host_organization_lineage":["https://openalex.org/I4210097602"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Entropy; Volume 24; Issue 10; Pages: 1503","raw_type":"Text"},{"id":"pmh:oai:pubmedcentral.nih.gov:9601406","is_oa":true,"landing_page_url":"https://www.ncbi.nlm.nih.gov/pmc/articles/9601406","pdf_url":null,"source":{"id":"https://openalex.org/S2764455111","display_name":"PubMed Central","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Entropy (Basel)","raw_type":"Text"},{"id":"pmh:oai:repository@napier.ac.uk:2937175","is_oa":true,"landing_page_url":"http://researchrepository.napier.ac.uk/Output/2937175","pdf_url":null,"source":{"id":"https://openalex.org/S4306402591","display_name":"Edinburgh Napier Research Repository (Edinburgh Napier University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I251738","host_organization_name":"Edinburgh Napier University","host_organization_lineage":["https://openalex.org/I251738"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"publishedVersion"}],"best_oa_location":{"id":"doi:10.3390/e24101503","is_oa":true,"landing_page_url":"https://doi.org/10.3390/e24101503","pdf_url":"https://www.mdpi.com/1099-4300/24/10/1503/pdf?version=1666747262","source":{"id":"https://openalex.org/S195231649","display_name":"Entropy","issn_l":"1099-4300","issn":["1099-4300"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Entropy","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4307134482.pdf","grobid_xml":"https://content.openalex.org/works/W4307134482.grobid-xml"},"referenced_works_count":48,"referenced_works":["https://openalex.org/W1590929875","https://openalex.org/W1603939896","https://openalex.org/W1952041214","https://openalex.org/W1963898916","https://openalex.org/W1995875735","https://openalex.org/W2083183119","https://openalex.org/W2154965170","https://openalex.org/W2461373307","https://openalex.org/W2513529237","https://openalex.org/W2544488729","https://openalex.org/W2559964890","https://openalex.org/W2601591992","https://openalex.org/W2764249719","https://openalex.org/W2766096867","https://openalex.org/W2786685397","https://openalex.org/W2801973044","https://openalex.org/W2890196927","https://openalex.org/W2899098847","https://openalex.org/W2904558336","https://openalex.org/W2932741247","https://openalex.org/W2946415594","https://openalex.org/W2953225812","https://openalex.org/W2962912862","https://openalex.org/W2971435671","https://openalex.org/W2982782590","https://openalex.org/W2989194228","https://openalex.org/W2993999308","https://openalex.org/W3013049284","https://openalex.org/W3093612846","https://openalex.org/W3098307239","https://openalex.org/W3149815788","https://openalex.org/W3172578675","https://openalex.org/W3175479041","https://openalex.org/W3198679606","https://openalex.org/W3203201880","https://openalex.org/W4206211871","https://openalex.org/W4210603079","https://openalex.org/W4210662571","https://openalex.org/W4220737740","https://openalex.org/W4224312479","https://openalex.org/W4239907196","https://openalex.org/W4242121546","https://openalex.org/W4243494487","https://openalex.org/W6744529318","https://openalex.org/W6753991793","https://openalex.org/W6771628511","https://openalex.org/W6801041139","https://openalex.org/W6807011261"],"related_works":["https://openalex.org/W3201228709","https://openalex.org/W2922354075","https://openalex.org/W4389157351","https://openalex.org/W4232561318","https://openalex.org/W4253977752","https://openalex.org/W3120595989","https://openalex.org/W2964829536","https://openalex.org/W2904586340","https://openalex.org/W4380791770","https://openalex.org/W2942879794"],"abstract_inverted_index":{"Ransomware":[0],"is":[1,23,33,44,82,92,103,114,182,227,236,264,337,343],"a":[2,30,62,87,183,244,370],"malicious":[3],"class":[4],"of":[5,68,75,111,209,270,272,283,295,319,321,376],"software":[6],"that":[7,180,191,255,285],"utilises":[8],"encryption":[9,124],"to":[10,45,52,58,85,99,122,161,173,198,216,238,326,351,367,381],"implement":[11],"an":[12,66,349,384],"attack":[13],"on":[14],"system":[15,48],"availability.":[16],"The":[17,108,177,204,225,316],"target's":[18],"data":[19,133,220],"remains":[20],"encrypted":[21,54,132,202,219,288,330,359],"and":[22,50,154,190,221,243,333,340],"held":[24],"captive":[25],"by":[26,39,289],"the":[27,73,106,115,143,157,163,192,207,233,256,261,273,292,322,353,374],"attacker":[28],"until":[29],"ransom":[31],"demand":[32],"met.":[34],"A":[35],"common":[36],"approach":[37],"used":[38,160,197,237,276],"many":[40],"crypto-ransomware":[41,127,332],"detection":[42,128],"techniques":[43,301],"monitor":[46],"file":[47,123,223,277,335,360],"activity":[49],"attempt":[51,350],"identify":[53,239,352],"files":[55,284,329],"being":[56,179,214],"written":[57],"disk,":[59],"often":[60,71],"using":[61,331,345],"file's":[63],"entropy":[64,89,112,146,188,299,354],"as":[65,84,98,149,279,281],"indicator":[67],"encryption.":[69],"However,":[70],"in":[72,126,213,310,348,386],"description":[74],"these":[76,248],"techniques,":[77],"little":[78],"or":[79,94],"no":[80],"discussion":[81],"made":[83],"why":[86,100],"particular":[88],"calculation":[90,113,300],"technique":[91,102,118],"selected":[93,104],"any":[95],"justification":[96],"given":[97],"one":[101],"over":[105],"alternatives.":[107],"Shannon":[109,152],"method":[110,355],"most":[116,274,356],"commonly-used":[117],"when":[119],"it":[120],"comes":[121],"identification":[125],"techniques.":[129],"Overall,":[130],"correctly":[131],"should":[134],"be":[135,171,196,389],"indistinguishable":[136],"from":[137,142,165],"random":[138],"data,":[139],"so":[140],"apart":[141],"standard":[144],"mathematical":[145],"calculations":[147],"such":[148],"Chi-Square":[150],"(\u03c72),":[151],"Entropy":[153],"Serial":[155],"Correlation,":[156],"test":[158,342],"suites":[159],"validate":[162],"output":[164],"pseudo-random":[166],"number":[167],"generators":[168],"would":[169],"also":[170,365],"suited":[172,357],"perform":[174],"this":[175,346],"analysis.":[176],"hypothesis":[178],"there":[181],"fundamental":[184],"difference":[185],"between":[186,218,328],"different":[187],"methods":[189,194],"best":[193],"may":[195],"better":[199],"detect":[200],"ransomware":[201],"files.":[203],"paper":[205],"compares":[206],"accuracy":[208,318,387],"53":[210],"distinct":[211],"tests":[212,257,378],"able":[215],"differentiate":[217,327],"other":[222,334],"types.":[224],"testing":[226],"broken":[228],"down":[229],"into":[230],"two":[231],"phases,":[232],"first":[234],"phase":[235,246,294],"potential":[240],"candidate":[241,298],"tests,":[242],"second":[245,293],"where":[247,373],"candidates":[249],"are":[250,379],"thoroughly":[251],"evaluated.":[252],"To":[253],"ensure":[254],"were":[258,302],"sufficiently":[259],"robust,":[260],"NapierOne":[262],"dataset":[263,267],"used.":[265],"This":[266],"contains":[268],"thousands":[269],"examples":[271,282],"commonly":[275],"types,":[278],"well":[280],"have":[286],"been":[287],"crypto-ransomware.":[290],"During":[291],"testing,":[296],"11":[297],"tested":[303],"against":[304],"more":[305],"than":[306],"270,000":[307],"individual":[308,323],"files-resulting":[309],"nearly":[311],"three":[312],"million":[313],"separate":[314],"calculations.":[315],"overall":[317],"each":[320,341],"test's":[324],"ability":[325],"types":[336],"then":[338],"evaluated":[339],"compared":[344],"metric":[347],"for":[358],"identification.":[361],"An":[362],"investigation":[363],"was":[364],"undertaken":[366],"determine":[368],"if":[369,383],"hybrid":[371],"approach,":[372],"results":[375],"multiple":[377],"combined,":[380],"discover":[382],"improvement":[385],"could":[388],"achieved.":[390]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":12},{"year":2024,"cited_by_count":5},{"year":2023,"cited_by_count":8}],"updated_date":"2026-05-21T09:19:25.381259","created_date":"2025-10-10T00:00:00"}
