Research Article

Mal-Netminer: Malware Classification Approach Based on Social Network Analysis of System Call Graph

Table 11

System call dictionary of Trojans.

FunctionalitySystem call list

Processor & busNtFlushInstructionCache

Local procedure callNtConnectPort, NtRequestWaitReplyPort, NtAlpcConnectPort, and NtAlpcSendWaitReceivePort

MemoryNtMapViewOfSection

File & general I/ONtCreateFile, NtQueryInformationFile, and NtCreateIoCompletion

ObjectNtClose

AtomsNtAddAtom

Processes & threadNtCreateThread, NtResumeThread, NtCreateProcessEx, NtQuerySystemInformation, NtCreateWorkerFactory, and NtQueryInformationProcess

SynchronizationNtCreateKeyedEvent and NtCreateMutant

Timers & system timeNtCreateTimer