Research Article

Toward Detecting Malware Based on Process-Aware Behaviors

Figure 2

API score for eight representative APIs. Note that some APIs are provided by the sandbox, e.g., SetFileHiddenOrReadOnly, and are composed of many NT APIs.