arrow
Return

CryptojackingTrap: An Evasion Resilient Nature-Inspired Algorithm to Detect Cryptojacking Malware

delete2024-01-01
delete0
PRE
AI
A
Atefeh Zareh Chahoki *
H
Hamid Reza Shahriari
M
Marco Roveri
DOI:10.1109/TIFS.2024.3353072delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The high profitability of mining cryptocurrencies mining, a computationally intensive activity, forms a fertile ecosystem that is enticing not only legitimate investors but also cyber attackers who invest their illicit computational resources in this area. Cryptojacking refers to the surreptitious exploitation of a victim's computing resources to mine cryptocurrencies on behalf of the cyber-criminal. This malicious behavior is observed in executable files and browser executable codes, including JavaScript and Assembly modules, downloaded from websites to victims' machines and executed. Although there are numerous botnet detection techniques to stop this malicious activity, attackers can circumvent these protections using a variety of techniques. In this paper, CryptojackingTrap is presented as a novel cryptojacking detection solution designed to resist most malware defense methods. The CryptojackingTrap is armed with a debugger and extensible cryptocurrency listeners and its algorithm is based on the execution of cryptocurrency hash functions: an indispensable behavior of all cryptojacking executors. This algorithm becomes aware of this specific hash execution by correlating the memory access traces of suspicious executables with publicly available cryptocurrency P2P network data. With the advantage of this assembly-level investigation and a nature-inspired approach to triggering the detection alarm, CryptojackingTrap provides an accurate, evasion-proof technique for detecting cryptojacking. After experimental evaluation, the false negative and false positive rates are zero, and in addition, the false positive rate is mathematically calculated as 10(-20). CryptojackingTrap has an open, extensible architecture and is available to the open-source community.
Keywords:
Malware
Botnet
Codes
Feature extraction
Behavioral sciences
Blockchains
Bitcoin
Blockchain
cryptocurrency
Ethereum
Monero
mining
malware detection
botnet
Botcoin
Crypto jacking
blockchain security
dynamic analysis
dynamic binary instrumentation

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

U
University of Trento
Scholars:
8.8K
Papers: 9.0K
Citations: 1.2W
A
Amirkabir University of Technology
Scholars:
1.1W
Papers: 1.1W
Citations: 1.0W