Behavior-Based Detection of Cryptojacking Malware
Behavior-Based Detection of Cryptojacking Malware
复制标题
基于行为的加密劫持恶意软件检测
DOI:
10.1109/usbereit48449.2020.9117732
复制
发表时间:
2020
期刊:
影响因子:
--
通讯作者:
D. Tanana
中科院分区:
文献类型:
--
作者:
D. Tanana
With rise of cryptocurrency popularity and value, more and more cybercriminals seek to profit using that new technology. Most common ways to obtain illegitimate profit using cryptocurrencies are ransomware and cryptojacking also known as malicious mining. And while ransomware is well-known and well-studied threat which is obvious by design, cryptojacking is often neglected because it’s less harmful and much harder to detect. This article considers question of cryptojacking detection. Brief history and definition of cryptojacking are described as well as reasons for designing custom detection technique. We also propose complex detection technique based on CPU load by an application, which can be applied to both browser-based and executable-type cryptojacking samples. Prototype detection program based on our technique was designed using decision tree algorithm. The program was tested in a controlled virtual machine environment and achieved 82% success rate against selected number of cryptojacking samples. Finally, we’ll discuss generalization of proposed technique for future work.