|
概要(英語)
|
In recent years, the impact of ransomware attacks has been increasing. Ransomware often generates multiple child processes to hide malicious behaviors such as file encryption. Additionally, some windows APIs have ANSI and Unicode versions, and provide processing according to the environment. However, existing research does not focus on parent-child processes relationship and the API character code. In this paper, we focus on APIs with ANSI and Unicode version and parent-child relationship. As the result of the analysis, we found the characteristics of ransomware in API calls with ANSI and Unicode versions used in parent and child processes are difference from benign softwares. Thus, we try to detect ransomware by using their characteristics of parent and child processes with API pairs of ANSI and Unicode versions. As the result, we confirmed their characteristics have been effective for ransomware detection.
|