From Entropy to Compression: Surveying Information-theoretic Signals for Early Malware Detection
Kabeya Tshiseba Cedric, Dionga Ndibu Ornella, LUBONGO MUEMBE Georgine, Gloire Alonda Madomba, Simplice Eale Botuli, Joel Mangoma Joel, Kevin MONGOY BONYOLO
Asian Journal of Research in Computer Science · pp. 24–36 · Published 17 Mar 2026
10.9734/ajrcos/2026/v19i3834Abstract
Malware continues to evolve in ways that reduce the effectiveness of signature matching and evade analysis environments, creating demand for early detection methods that can flag suspicious binaries before behavior is observed. This article surveys information-theoretic approaches for early malware detection, focusing on the progression from classical uncertainty measures to algorithmic notions of complexity. We first discuss Shannon entropy as a lightweight indicator of packing, encryption, and obfuscation, and explain how entropy computed over whole files, executable sections, or sliding windows can localize anomalous regions in portable executable binaries. We then examine algorithmic complexity through the lens of Kolmogorov complexity and outline practical approximations using general-purpose compression. Compression-based measures provide a way to estimate structural regularities in binaries that are not captured by frequency statistics alone. Building on this idea, we introduce normalized compression distance as a featureless similarity measure that enables clustering and nearest-neighbor style detection without handcrafted features. The survey highlights how entropy, compressibility, and compression-based similarity can be combined into hybrid pipelines that support triage, prioritization, and explainable inspection, while also noting key limitations. High entropy is not unique to malware and can arise in legitimate packed installers, multimedia resources, or encrypted payloads, leading to false alarms if used in isolation. Compression-based methods can be computationally demanding and sensitive to file size, compressor choice, and adversarial manipulation. By synthesizing these techniques and their practical considerations, this article provides guidance for designing robust early-warning detectors and for integrating information-theoretic signals with complementary static and learning-based components in operational settings.
Cited by 0
No indexed citations yet.
Related research
- Handwritten Arabic Characters Recognition Based on Wavelet Entropy and Neural Network — shares topic coverage
- Cumulative Effects of the Temperature and Damping on the Time Dependent Entropy and Decoherence in the Caldirola-Kanai Harmonic Oscillator — shares topic coverage
- A Comprehensive Study of Malware Detection in Android Operating Systems — shares topic coverage
- A State of Art Survey for Understanding Malware Detection Approaches in Android Operating System — shares topic coverage
- Enhancing Malware Detection Accuracy through Graph Based Model — shares topic coverage
Article metrics
Real usage data collected on this platform.
0
Page views
0
PDF downloads
0
Outbound clicks
0
Citations
Views by country
Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".
No views recorded yet.
Traffic sources
Referring site, by host.
No traffic recorded yet.
Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.