Ransomware can’t encrypt what it can’t reach
Multi-layer ransomware detection analyzes every backup before replicating verified clean copies to a secondary EU data center. If your primary backups are compromised, Shield has a clean copy ready.
Backup completed — 12,847 items
DeltaSync finished for tenant acme-corp
Shannon entropy analysis: avg 4.8
Normal range (text/HTML content)
Compression ratio: 62%
Within expected range for email content
IOC scan: 0 matches
No ransomware extensions or ransom-note filenames
Clean Score: 98/100
No anomalies detected, backup verified clean
Replicating to secondary EU zone...
247 GB queued for cross-region copy
Replica verified (SHA-256 match)
Clean copy stored in secondary data center
Entropy
Normal
Compression
62%
Clean Score
98
Replica
Verified
Detection Engine
How we detect ransomware
Six independent detection signals work together to identify compromised backups before they reach your secondary storage — content analysis, behavioral baselines and a curated ransomware indicator feed, corroborated so no single signal can cause a false alarm.
Shannon Entropy Analysis
Every file is measured for its information density using Shannon entropy (0–8 bits per byte). Normal email content scores 4.0–5.5. Compressed files reach 6.0–7.0. Ransomware-encrypted data hits 7.8–8.0 — virtually indistinguishable from random noise.
This works because encryption algorithms (AES, RSA, ChaCha20) produce pseudo-random output that maximizes entropy — a mathematical fingerprint that can’t be hidden.
Entropy scale (bits per byte)
Compression Ratio Analysis
Random data cannot be compressed — this is a fundamental law of information theory. Normal email content compresses 40–70% with modern algorithms. Ransomware-encrypted content compresses less than 5%.
This detection is algorithm-agnostic. Whether we use Zstandard, gzip, or any other compressor — encrypted data will always fail to compress. A sudden drop in compression ratio across a backup run is a strong indicator of ransomware activity.
Compression ratio by content type
Statistical Anomaly Detection
Every backup run is compared against a 30-day rolling baseline of the mailbox's normal behavior. Mass deletions, mass updates and volume spikes are scored with robust statistics that outliers cannot skew.
- Mass-delete & mass-update detection: flags unusual change volume per mailbox
- Robust per-mailbox baselines: median-based statistics that single outliers can't distort
- Restore-aware: recent restores are recognized so recovery never triggers false alarms
- Proportional severity bands MEDIUM / HIGH / CRITICAL — anomalous runs are excluded from future baselines
Entropy Uniformity Check
A normal mailbox contains diverse content: plain text emails (entropy ~4.0), HTML newsletters (~5.5), PDF attachments (~6.5), and images (~7.0). This creates natural variation in entropy values.
Ransomware eliminates this variation. When all files show uniformly high entropy (average > 7.0, standard deviation < 0.1), it means every file has been encrypted with the same algorithm — a clear sign of ransomware, even if individual entropy values alone wouldn’t trigger an alert.
Normal mailbox
stddev: 1.2 — varied
Ransomware
stddev: 0.02 — uniform
Ransomware IOC Matching
Attachment and file names are matched against a curated feed of known ransomware indicators: 100+ file extensions used by families like LockBit, Akira or BlackCat, plus ransom-note filename patterns.
An IOC hit is the highest-precision signal there is — a ransom note inside a backup is virtually never legitimate. Matches escalate the run immediately and corroborate the statistical findings.
Sample indicators
Multi-Signal Corroboration
Drastic action requires agreement. Snapshots are frozen only on a critical finding, or when at least two independent signal families point the same way. A single noisy metric never locks up your data.
Detection also correlates across mailboxes: if several mailboxes of a tenant turn anomalous within the same hour, Backup Shield raises a tenant-wide critical alert — the signature of a real ransomware event or a compromised account.
Independent signal families
Freeze only on CRITICAL — or when ≥ 2 families agree
Health Metric
Clean Score
Every backup run receives a Clean Score from 0 to 100. The score starts at 100 and receives deductions based on detected anomalies. Only backups scoring 70 or above are considered clean and eligible for replication.
Backup verified clean
Eligible for replication
Defense in Depth
Three lines of defense
Only verified clean backups reach the secondary storage zone. Every backup passes through three independent checkpoints before replication.
During backup
Shannon entropy and compression ratio are calculated for every item as it is backed up. These metrics are stored alongside the backup data for later analysis.
- Per-item entropy calculation
- Compression ratio measurement
- Metrics stored in database
After backup
The anomaly detection engine compares the run against a 30-day baseline. Z-score analysis, entropy uniformity, and compression drop checks produce a Clean Score.
- 30-day rolling baseline
- Z-score deviation analysis
- Clean Score 0–100
Before replication
A final re-check verifies the backup run is still clean (status may have changed). Individual items undergo a spot-check for suspicious entropy/compression combinations.
- Run status re-verification
- Individual item spot-check
- Blocked if suspicious
Disaster Recovery
Cross-region replication
Verified clean backups are automatically replicated to a secondary EU data center. Every copy is verified with SHA-256 hash comparison to ensure bit-perfect integrity.
- EU-only infrastructure — data never leaves the European Union
- SHA-256 hash verification after every copy operation
- Only the latest version per item is replicated — no storage bloat
- Replicated items appear as additional restore points in search
- Automatic 24-hour schedule, configurable per tenant
acme-corp/exchange
124 GB
acme-corp/onedrive
89 GB
startup-inc/exchange
34 GB
Pay only for replicated storage
No per-mailbox fees. No minimum commitment. Just €0.03 per GB per month for cross-region replication with full ransomware detection included.

