A Comprehensive API Call Analysis for Detecting Windows-Based Ransomware
P. Mohan Anand, P. V. Sai Charan, Sandeep K. Shukla
Abstract
P. Mohan Anand, P. V. Sai Charan, Sandeep K. Shukla
Abstract
Ransomware has been one of the prevalent malware for the past decade, and it is continuing to be one of the significant threats today. The API call-based analysis is a widely adopted method to identify malware threats and helps analyze suspicious activities of a program during its execution. However, the importance of identifying the key API calls is not considered in many detection methods. The feature importance in API call analysis needs more prominence as key features are the building blocks for implementing a robust machine learning model. Our work identifies the key API calls invoked by multiple ransomware strains using four state-of-the-art feature selection algorithms. We consider 46 ransomware families to perform dynamic and static analysis and extract API call features. Overall, we present 135 key API features to build a robust classification model with 0.9615 detection accuracy.
OpenAlex reports 10 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Ransomware has been one of the prevalent malware for the past decade, and it is continuing to be one of the significant threats today. The API call-based analysis is a widely adopted method to identify malware threats and helps analyze suspicious activities of a program during its execution. However, the importance of identifying the key API calls is not considered in many detection methods. The feature importance in API call analysis needs more prominence as key features are the building blocks for implementing a robust machine learning model. Our work identifies the key API calls invoked by multiple ransomware strains using four state-of-the-art feature selection algorithms. We consider 46 ransomware families to perform dynamic and static analysis and extract API call features. Overall, we present 135 key API features to build a robust classification model with 0.9615 detection accuracy.
Key concepts: Ransomware, Malware analysis, Malware, Computer science, Key (lock), Static analysis, Feature selection, Feature (linguistics)