A Comprehensive API Call Analysis for Detecting Windows-Based Ransomware

P. Mohan Anand, Venkata Sai Charan Putrevu, Sandeep K. Shukla · 2022

Ransomware has been one of the prevalent malware for the past decade, and it is continuing to be one of the significant threats today. The API call-based analysis is a widely adopted method to identify malware threats and helps analyze suspicious activities of a program during its execution. However, the importance of identifying the key API calls is not considered in many detection methods. The feature importance in API call analysis needs more prominence as key features are the building blocks for implementing a robust machine learning model. Our work identifies the key API calls invoked by multiple ransomware strains using four state-of-the-art feature selection algorithms. We consider 46 ransomware families to perform dynamic and static analysis and extract API call features. Overall, we present 135 key API features to build a robust classification model with 0.9615 detection accuracy.

Read the paper · More papers on PaperTik