Cookie Settings

We use cookies to ensure the basic functionality of our website. Essential cookies (theme preference, session, consent status) are required and cannot be disabled. Optional cookies for analytics and payment processing are only set with your explicit consent. Privacy Policy

Ransomware can’t encrypt what it can’t reach

Multi-layer ransomware detection analyzes every backup before replicating verified clean copies to a secondary EU data center. If your primary backups are compromised, Shield has a clean copy ready.

Backup Shield — Detection Pipeline
Detection pipeline active
Region: EU-DE

Backup completed — 12,847 items

DeltaSync finished for tenant acme-corp

Shannon entropy analysis: avg 4.8

Normal range (text/HTML content)

Compression ratio: 62%

Within expected range for email content

IOC scan: 0 matches

No ransomware extensions or ransom-note filenames

Clean Score: 98/100

No anomalies detected, backup verified clean

Replicating to secondary EU zone...

247 GB queued for cross-region copy

Replica verified (SHA-256 match)

Clean copy stored in secondary data center

Entropy

Normal

Compression

62%

Clean Score

98

Replica

Verified

Detection Engine

How we detect ransomware

Six independent detection signals work together to identify compromised backups before they reach your secondary storage — content analysis, behavioral baselines and a curated ransomware indicator feed, corroborated so no single signal can cause a false alarm.

Shannon Entropy Analysis

Every file is measured for its information density using Shannon entropy (0–8 bits per byte). Normal email content scores 4.0–5.5. Compressed files reach 6.0–7.0. Ransomware-encrypted data hits 7.8–8.0 — virtually indistinguishable from random noise.

This works because encryption algorithms (AES, RSA, ChaCha20) produce pseudo-random output that maximizes entropy — a mathematical fingerprint that can’t be hidden.

Entropy scale (bits per byte)

0 — Normal text6 — Compressed8 — Encrypted

Compression Ratio Analysis

Random data cannot be compressed — this is a fundamental law of information theory. Normal email content compresses 40–70% with modern algorithms. Ransomware-encrypted content compresses less than 5%.

This detection is algorithm-agnostic. Whether we use Zstandard, gzip, or any other compressor — encrypted data will always fail to compress. A sudden drop in compression ratio across a backup run is a strong indicator of ransomware activity.

Compression ratio by content type

Email (text/HTML)65%
Office documents45%
PDF files30%
Ransomware-encrypted3%

Statistical Anomaly Detection

Every backup run is compared against a 30-day rolling baseline of the mailbox's normal behavior. Mass deletions, mass updates and volume spikes are scored with robust statistics that outliers cannot skew.

  • Mass-delete & mass-update detection: flags unusual change volume per mailbox
  • Robust per-mailbox baselines: median-based statistics that single outliers can't distort
  • Restore-aware: recent restores are recognized so recovery never triggers false alarms
  • Proportional severity bands MEDIUM / HIGH / CRITICAL — anomalous runs are excluded from future baselines

Entropy Uniformity Check

A normal mailbox contains diverse content: plain text emails (entropy ~4.0), HTML newsletters (~5.5), PDF attachments (~6.5), and images (~7.0). This creates natural variation in entropy values.

Ransomware eliminates this variation. When all files show uniformly high entropy (average > 7.0, standard deviation < 0.1), it means every file has been encrypted with the same algorithm — a clear sign of ransomware, even if individual entropy values alone wouldn’t trigger an alert.

Normal mailbox

stddev: 1.2 — varied

Ransomware

stddev: 0.02 — uniform

Ransomware IOC Matching

Attachment and file names are matched against a curated feed of known ransomware indicators: 100+ file extensions used by families like LockBit, Akira or BlackCat, plus ransom-note filename patterns.

An IOC hit is the highest-precision signal there is — a ransom note inside a backup is virtually never legitimate. Matches escalate the run immediately and corroborate the statistical findings.

Sample indicators

.lockbit.akira.blackcat.medusaDECRYPT_INSTRUCTIONS.txtHOW_TO_RESTORE_FILES.txt

Multi-Signal Corroboration

Drastic action requires agreement. Snapshots are frozen only on a critical finding, or when at least two independent signal families point the same way. A single noisy metric never locks up your data.

Detection also correlates across mailboxes: if several mailboxes of a tenant turn anomalous within the same hour, Backup Shield raises a tenant-wide critical alert — the signature of a real ransomware event or a compromised account.

Independent signal families

Change behavior
Content analysis
IOC matches

Freeze only on CRITICAL — or when ≥ 2 families agree

Health Metric

Clean Score

Every backup run receives a Clean Score from 0 to 100. The score starts at 100 and receives deductions based on detected anomalies. Only backups scoring 70 or above are considered clean and eligible for replication.

Entropy anomaly (CRITICAL)-25
Entropy anomaly (HIGH)-20
Size deviation (CRITICAL)-20
Size deviation (HIGH)-15
Compression drop-15
Entropy uniformity-15
Entropy anomaly (MEDIUM)-10
Size deviation (MEDIUM)-10
98Score

Backup verified clean

Eligible for replication

Entropy
4.8 avg
Compression
62%
Size deviation
+0.3σ
Entropy Uniformity Check
stddev 1.2

Defense in Depth

Three lines of defense

Only verified clean backups reach the secondary storage zone. Every backup passes through three independent checkpoints before replication.

01

During backup

Shannon entropy and compression ratio are calculated for every item as it is backed up. These metrics are stored alongside the backup data for later analysis.

  • Per-item entropy calculation
  • Compression ratio measurement
  • Metrics stored in database
02

After backup

The anomaly detection engine compares the run against a 30-day baseline. Z-score analysis, entropy uniformity, and compression drop checks produce a Clean Score.

  • 30-day rolling baseline
  • Z-score deviation analysis
  • Clean Score 0–100
03

Before replication

A final re-check verifies the backup run is still clean (status may have changed). Individual items undergo a spot-check for suspicious entropy/compression combinations.

  • Run status re-verification
  • Individual item spot-check
  • Blocked if suspicious

Disaster Recovery

Cross-region replication

Verified clean backups are automatically replicated to a secondary EU data center. Every copy is verified with SHA-256 hash comparison to ensure bit-perfect integrity.

  • EU-only infrastructure — data never leaves the European Union
  • SHA-256 hash verification after every copy operation
  • Only the latest version per item is replicated — no storage bloat
  • Replicated items appear as additional restore points in search
  • Automatic 24-hour schedule, configurable per tenant
Primary (EU-DE)
Replica (EU-DE)

acme-corp/exchange

124 GB

Verified

acme-corp/onedrive

89 GB

Verified

startup-inc/exchange

34 GB

Replicating...

Pay only for replicated storage

No per-mailbox fees. No minimum commitment. Just €0.03 per GB per month for cross-region replication with full ransomware detection included.

€0.03/GB/month