Detection of malicious software on based on multiple equations of API-calls sequences
Olga Hachinyan · 2017
Development and dissemination of malicious software requires the creation of new methods for their detection. Therefore we began to use proactive technologies that use the test program to detect the presence of certain symptoms, often occurring in malware. Dynamic analysis of the studied program launched for execution. There is a study of how the program interacts with the software environment that is read/write at certain registry keys, files, network activity the use of certain API calls. Due to the fact that studied the program is potentially harmful, to make its execution must be in an isolated environment. This paper discusses proactive methods based on API call analysis and propose a new method using a multiple sequence alignment to identify common traits in malware. The paper considers the scheme to detect malicious software, based on API calls, each of which is implemented in software. Also presented a completely new malware detection scheme based on multiple sequence API calls alignment. This scheme is described in detail and implemented in software. A test on a set of software and the legitimacy of the viral nature. Testing has shown that the established scheme of competitive shows and identifies malicious software with high accuracy.