Detection of Encrypted Cryptomining Malware Connections With Machine and Deep Learning

被引:35
|
作者
Pastor, Antonio [1 ]
Mozo, Alberto [2 ]
Vakaruk, Stanislav [2 ]
Canavese, Daniele [3 ]
Lopez, Diego R. [1 ]
Regano, Leonardo [3 ]
Gomez-Canaval, Sandra [2 ]
Lioy, Antonio [3 ]
机构
[1] Telefon I D, Madrid 28010, Spain
[2] Univ Politecn Madrid, Dept Sistemas Informat, Madrid 28031, Spain
[3] Politecn Torino, Dipartimento Automat & Informat, I-10129 Turin, Italy
来源
IEEE ACCESS | 2020年 / 8卷
基金
欧盟地平线“2020”;
关键词
Machine learning; Cryptocurrency; Servers; Data mining; Malware; Protocols; Cryptomining detection; malware detection; cryptojacking detection; cryptocurrency mining; netflow measurements; encrypted traffic classification; machine learning; deep learning;
D O I
10.1109/ACCESS.2020.3019658
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Nowadays, malware has become an epidemic problem. Among the attacks exploiting the computer resources of victims, one that has become usual is related to the massive amounts of computational resources needed for digital currency cryptomining. Cybercriminals steal computer resources from victims, associating these resources to the crypto-currency mining pools they benefit from. This research work focuses on offering a solution for detecting such abusive cryptomining activity, just by means of passive network monitoring. To this end, we identify a new set of highly relevant network flow features to be used jointly with a rich set of machine and deep-learning models for real-time cryptomining flow detection. We deployed a complex and realistic cryptomining scenario for training and testing machine and deep learning models, in which clients interact with real servers across the Internet and use encrypted connections. A complete set of experiments were carried out to demonstrate that, using a combination of these highly informative features with complex machine learning models, cryptomining attacks can be detected on the wire with telco-grade precision and accuracy, even if the traffic is encrypted.
引用
收藏
页码:158036 / 158055
页数:20
相关论文
共 50 条
  • [1] DeCrypto Pro: Deep Learning Based Cryptomining Malware Detection Using Performance Counters
    Mani, Ganapathy
    Pasumarti, Vikram
    Bhargava, Bharat
    Vora, Faisal Tariq
    MacDonald, James
    King, Justin
    Kobes, Jason
    2020 IEEE INTERNATIONAL CONFERENCE ON AUTONOMIC COMPUTING AND SELF-ORGANIZING SYSTEMS (ACSOS 2020), 2020, : 109 - 118
  • [2] Comparison of Deep Learning and the Classical Machine Learning Algorithm for the Malware Detection
    Sewak, Mohit
    Sahay, Sanjay K.
    Rathore, Hemant
    2018 19TH IEEE/ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, ARTIFICIAL INTELLIGENCE, NETWORKING AND PARALLEL/DISTRIBUTED COMPUTING (SNPD), 2018, : 293 - 296
  • [3] Cryptomining Detection in Container Clouds Using System Calls and Explainable Machine Learning
    Karn, Rupesh Raj
    Kudva, Prabhakar
    Huang, Hai
    Suneja, Sahil
    Elfadel, Ibrahim M.
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2021, 32 (03) : 674 - 691
  • [4] When a RF beats a CNN and GRU, together-A comparison of deep learning and classical machine learning approaches for encrypted malware traffic classification
    Lichy, Adi
    Bader, Ofek
    Dubin, Ran
    Dvir, Amit
    Hajaj, Chen
    COMPUTERS & SECURITY, 2023, 124
  • [5] Static Analysis of Android Malware Detection using Deep Learning
    Sandeep, H. R.
    PROCEEDINGS OF THE 2019 INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTING AND CONTROL SYSTEMS (ICCS), 2019, : 841 - 845
  • [6] A novel deep learning-based approach for malware detection
    Shaukat, Kamran
    Luo, Suhuai
    Varadharajan, Vijay
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2023, 122
  • [7] Automated machine learning for deep learning based malware detection
    Brown, Austin
    Gupta, Maanak
    Abdelsalam, Mahmoud
    COMPUTERS & SECURITY, 2024, 137
  • [8] Static Malware Analysis Using Machine and Deep Learning
    Singh, Himanshu Kumar
    Singh, Jyoti Prakash
    Tewari, Anand Shanker
    PROCEEDINGS OF INTERNATIONAL CONFERENCE ON COMPUTING AND COMMUNICATION NETWORKS (ICCCN 2021), 2022, 394 : 437 - 446
  • [9] LONGCGDROID: ANDROID MALWARE DETECTION THROUGH LONGITUDINAL STUDY FOR MACHINE LEARNING AND DEEP LEARNING
    Mesbah, Abdelhak
    Baddari, Ibtihel
    Riahla, Mohamed Amine
    JORDANIAN JOURNAL OF COMPUTERS AND INFORMATION TECHNOLOGY, 2023, 9 (04): : 328 - 346
  • [10] Android malware detection and identification frameworks by leveraging the machine and deep learning techniques: A comprehensive review
    Smmarwar, Santosh K.
    Gupta, Govind P.
    Kumar, Sanjay
    TELEMATICS AND INFORMATICS REPORTS, 2024, 14