Behavior-Based Detection of Cryptojacking Malware

Behavior-Based Detection of Cryptojacking Malware
复制标题

基于行为的加密劫持恶意软件检测

DOI:
10.1109/usbereit48449.2020.9117732
复制
发表时间:
2020
期刊:
2020 Ural Symposium on Biomedical Engineering, Radioelectronics and Information Technology (USBEREIT)
影响因子:
--
通讯作者:
D. Tanana
D. Tanana
中科院分区:
--
文献类型:
--
作者:
D. Tanana

文献摘要

被引文献

相似文献

随着加密货币的普及和价值的上升,越来越多的网络犯罪分子寻求利用这种新技术获利。使用加密货币获取非法利润的最常见方法是勒索软件和加密劫持,也称为恶意挖掘。虽然勒索软件是众所周知的、经过充分研究的威胁,而且从设计上看是显而易见的,但加密劫持往往被忽视,因为它的危害较小,而且更难检测。本文研究了加密劫持检测问题。简要介绍了加密劫持的历史和定义,以及设计自定义检测技术的原因。我们还提出了基于应用程序CPU负载的复杂检测技术,该技术可以应用于基于浏览器和可执行类型的加密劫持示例。采用决策树算法设计了基于该技术的原型检测程序。该程序在受控的虚拟机环境中进行了测试,针对选定数量的加密劫持样本实现了82%的成功率。最后,我们将讨论所提出的技术在未来工作中的推广。
With rise of cryptocurrency popularity and value, more and more cybercriminals seek to profit using that new technology. Most common ways to obtain illegitimate profit using cryptocurrencies are ransomware and cryptojacking also known as malicious mining. And while ransomware is well-known and well-studied threat which is obvious by design, cryptojacking is often neglected because it’s less harmful and much harder to detect. This article considers question of cryptojacking detection. Brief history and definition of cryptojacking are described as well as reasons for designing custom detection technique. We also propose complex detection technique based on CPU load by an application, which can be applied to both browser-based and executable-type cryptojacking samples. Prototype detection program based on our technique was designed using decision tree algorithm. The program was tested in a controlled virtual machine environment and achieved 82% success rate against selected number of cryptojacking samples. Finally, we’ll discuss generalization of proposed technique for future work.