Copy & Return: Evidence-Preserving Damage Suppression with Lightweight AI-Based Ransomware Screening

Dynamic ransomware analysis presents a dilemma: terminating a sample prevents later behavior from being observed, whereas allowing destructive functions to complete can corrupt the analysis environment and its evidence. Copy & Return addresses this problem by suppressing selected destructive effects at function boundaries while allowing the original process to continue. An ABI-compatible substitute is introduced via dynamic-library interposition or binary injection to redirect a dangerous destination, preserve a mutable buffer, or bypass a destructive transformation before returning control to the unchanged caller. To identify potential intervention targets, we implement a static-analysis pipeline that ranks candidate functions and presents the underlying evidence for target confirmation. We evaluate candidate rankings on 10 selected ELF ransomware binaries and conduct detailed runtime case studies of MBRLocker, Conti, and Cylance. For MBRLocker, the 512-byte disk payload is redirected to a dummy file without modifying the actual boot sector. For Conti and Cylance, the original contents of eight target files per sample are preserved while file renaming, metadata appending, and ransom-note creation remain observable, demonstrating evidence-preserving damage suppression. Separately, we use numerical features obtained through static analysis to train and evaluate a lightweight ransomware screening model based on histogram-based gradient boosting. On 1156 binaries comprising 126 ransomware and 1030 benign samples, the model achieves a mean F1-score of 0.9124 and a mean false-positive rate of 1.62% under nested grouped cross-validation; the serialized model occupies approximately 39.3 KiB. These results demonstrate complementary roles for function-level damage suppression, static target-identification support, and lightweight AI-based ransomware screening.

Authors

Institutions

Publication Details

Journal
Applied Sciences
Published
2026-10-05
DOI
https://doi.org/10.3390/app16199876
Primary Topic
Advanced Malware Detection Techniques
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

Copy & Return: Evidence-Preserving Damage Suppression with Lightweight AI-Based Ransomware Screening

Seungkwang Lee, Jiseok Bang, Yong-je Choi, Yohan Lee et al.
Applied Sciences
Advanced Malware Detection Techniques
article

Copy & Return: Evidence-Preserving Damage Suppression with Lightweight AI-Based Ransomware Screening

Seungkwang Lee, Jiseok Bang, Yong-je Choi, Yohan Lee, Sang-su Lee
article en

Abstract

Dynamic ransomware analysis presents a dilemma: terminating a sample prevents later behavior from being observed, whereas allowing destructive functions to complete can corrupt the analysis environment and its evidence. Copy & Return addresses this problem by suppressing selected destructive effects at function boundaries while allowing the original process to continue. An ABI-compatible substitute is introduced via dynamic-library interposition or binary injection to redirect a dangerous destination, preserve a mutable buffer, or bypass a destructive transformation before returning control to the unchanged caller. To identify potential intervention targets, we implement a static-analysis pipeline that ranks candidate functions and presents the underlying evidence for target confirmation. We evaluate candidate rankings on 10 selected ELF ransomware binaries and conduct detailed runtime case studies of MBRLocker, Conti, and Cylance. For MBRLocker, the 512-byte disk payload is redirected to a dummy file without modifying the actual boot sector. For Conti and Cylance, the original contents of eight target files per sample are preserved while file renaming, metadata appending, and ransom-note creation remain observable, demonstrating evidence-preserving damage suppression. Separately, we use numerical features obtained through static analysis to train and evaluate a lightweight ransomware screening model based on histogram-based gradient boosting. On 1156 binaries comprising 126 ransomware and 1030 benign samples, the model achieves a mean F1-score of 0.9124 and a mean false-positive rate of 1.62% under nested grouped cross-validation; the serialized model occupies approximately 39.3 KiB. These results demonstrate complementary roles for function-level damage suppression, static target-identification support, and lightweight AI-based ransomware screening.

Applied SciencesVol. 16(19)
Electronics and Telecommunications Research Institute (KR), Dankook University (KR)
Openalex Percentile: Top 11%
Advanced Malware Detection Techniques
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.