Research Article

Mal-Netminer: Malware Classification Approach Based on Social Network Analysis of System Call Graph

Table 9

Distribution of in-degree centrality in adware (Win32.ScreenSaver_001 case).

System callIn-degree centrality

NtClose46

NtAlpcSendWaitReceivePort23

NtAlpcConnectPort7

NtReleaseMutant5

NtAllocateVirtualMemory4

NtDuplicateObject, NtAlertThread, NtOpenThreadToken, NtQueryValueKey, NtUnmapViewOfSection, NtOpenKeyEx, NtCreateTimer, and NtQueryInformationProcess3

NtQueryKey, NtSetEvent, NtOpenProcessToken, NtCreateEvent, NtQueryVirtualMemory, NtTestAlert, NtCreateThreadEx, NtDeviceIoControlFile, NtOpenProcessTokenEx, NtAlpcDeleteSecurityContext, NtResumeThread, NtCreateFile, NtWaitForSingleObject, NtAlpcSetInformation, NtCreateMutant, NtWaitForMultipleObjects, and NtOpenKey2

NtCreateWorkerFactory, NtCreateKeyedEvent, NtOpenProcess, NtAccessCheckByType, NtSetValueKey, NtOpenEvent, NtSetInformationFile, NtCreateKey, NtOpenSection, NtAccessCheck, NtSetInformationThread, NtMapViewOfSection, NtCreateIoCompletion, NtDelayExecution, NtWaitForKeyedEvent, NtGetMUIRegistryInfo, NtFreeVirtualMemory, NtWaitForWorkViaWorkerFactory, NtQuerySystemInformation, NtEnumerateKey, NtEnumerateValueKey, NtOpenFile, NtMapCMFModule, NtQuerySystemInformationEx, NtQueryDefaultLocale, NtRequestPort, NtRequestWaitReplyPort, NtQueryAttributesFile, NtConnectPort, NtProtectVirtualMemory, NtWorkerFactoryWorkerReady, NtNotifyChangeKey, NtCreateSection, NtQueryInformationFile, NtAlpcCreatePort, NtSetInformationProcess, NtSetTimer, and NtTraceControl 1