Research Article

Mal-Netminer: Malware Classification Approach Based on Social Network Analysis of System Call Graph

Table 12

System call dictionary of worms.

FunctionalitySystem call list

Processor & busNtFlushInstructionCache

Local procedure callNtAlpcCreateSecurityContext and NtAlpcSetInformation

MemoryNtMapViewOfSection

RegistryNtEnumerateKey and NtEnumerateValueKey

MiscellaneousNtQuerySystemInformation

File & general I/ONtCreateFile and NtDeviceIoControlFile

ObjectNtClose

AtomsNtAddAtom

Processes & threadNtCreateThread, NtResumeThread, NtCreateProcessEx, and NtQueryInformationProcess

SynchronizationNtReleaseMutant

Timers & system timeNtSetTimer and NtQueryPerformanceCounter