Research Article

Mal-Netminer: Malware Classification Approach Based on Social Network Analysis of System Call Graph

Table 10

System call dictionary of adware.

FunctionalitySystem call list

Local procedure callNtAlpcAcceptConnectPort, NtAlpcConnectPort, NtAlpcCreatePort, and NtAlpcSendWaitReceivePort

File & general I/ONtCreateIoCompletion

ObjectNtClose

AtomsNtFindAtom

Processes & threadNtResumeThread, NtCreateUserProcess, and NtCreateWorkerFactory

SynchronizationNtCreateKeyedEvent and NtReleaseMutant

Timers & system timeNtSetTimer and NtCreateTimer