管理機能

タイトル(英語) Analysis of API calls with 'A'and 'W' suffixes used in parent and child processes for ransomware detection
著者
  1. Yoshiki Matsuda(松田 祥希)
  2. Kenichi Takahashi(高橋 健一)
  3. Masayuki Higashino(東野 正幸)
  4. Takao Kawamura(川村 尚生)
論文誌 2024 Twelfth International Symposium on Computing and Networking (CANDAR)
ページ pp. 176-182
発行日 2024年12月31日
DOI 10.1109/CANDAR64496.2024.00029
概要(英語) In recent years, the impact of ransomware attacks has been increasing. Consequently, numerous studies on ran-somware detection have been conducted. These studies often focus on the API calls used by ransomware. Ransomware frequently generates multiple child processes to conceal malicious behaviors such as file encryption. However, existing research does not focus on the characteristics of child and parent processes. In this paper, we analyze the number of processes generated by ransomware and benign software as well as the Windows API calls of each processes. As the result of our analysis, we found that ransomware exhibits specific characteristics in API calls with ’A’ and ’W’ suffixes used in parent and child processes, which differ from those in benign software. Thus, we attempt to detect ransomware by using these characteristics of parent and child processes. Our results confirm that the characteristics of parent and child processes are effective for ransomware detection.
BibTeX BibTeX