Copy & Return: Evidence-Preserving Damage Suppression with Lightweight AI-Based Ransomware Screening
Dynamic ransomware analysis presents a dilemma: terminating a sample prevents later behavior from being observed, whereas allowing destructive functions to complete can corrupt the analysis environment and its evidence. Copy & Return addresses this problem by suppressing selected destructive effects at function boundaries while allowing the original process to continue. An ABI-compatible substitute is introduced via dynamic-library interposition or binary injection to redirect a dangerous destination, preserve a mutable buffer, or bypass a destructive transformation before returning control to the unchanged caller. To identify potential intervention targets, we implement a static-analysis pipeline that ranks candidate functions and presents the underlying evidence for target confirmation. We evaluate candidate rankings on 10 selected ELF ransomware binaries and conduct detailed runtime case studies of MBRLocker, Conti, and Cylance. For MBRLocker, the 512-byte disk payload is redirected to a dummy file without modifying the actual boot sector. For Conti and Cylance, the original contents of eight target files per sample are preserved while file renaming, metadata appending, and ransom-note creation remain observable, demonstrating evidence-preserving damage suppression. Separately, we use numerical features obtained through static analysis to train and evaluate a lightweight ransomware screening model based on histogram-based gradient boosting. On 1156 binaries comprising 126 ransomware and 1030 benign samples, the model achieves a mean F1-score of 0.9124 and a mean false-positive rate of 1.62% under nested grouped cross-validation; the serialized model occupies approximately 39.3 KiB. These results demonstrate complementary roles for function-level damage suppression, static target-identification support, and lightweight AI-based ransomware screening.
Authors
- Seungkwang Lee (ORCID: https://orcid.org/0000-0001-9534-9624)
- Jiseok Bang (ORCID: https://orcid.org/0009-0008-5285-9403)
- Yong-je Choi
- Yohan Lee
- Sang-su Lee
Institutions
- Electronics and Telecommunications Research Institute (KR)
- Dankook University (KR)
Publication Details
- Journal
- Applied Sciences
- Published
- 2026-10-05
- DOI
- https://doi.org/10.3390/app16199876
- Primary Topic
- Advanced Malware Detection Techniques
- Type
- article
- Field-Weighted Citation Impact
- 0.00