Detection of Encrypted Cryptomining Malware Connections With Machine and Deep Learning

被引:35
|
作者
Pastor, Antonio [1 ]
Mozo, Alberto [2 ]
Vakaruk, Stanislav [2 ]
Canavese, Daniele [3 ]
Lopez, Diego R. [1 ]
Regano, Leonardo [3 ]
Gomez-Canaval, Sandra [2 ]
Lioy, Antonio [3 ]
机构
[1] Telefon I D, Madrid 28010, Spain
[2] Univ Politecn Madrid, Dept Sistemas Informat, Madrid 28031, Spain
[3] Politecn Torino, Dipartimento Automat & Informat, I-10129 Turin, Italy
来源
IEEE ACCESS | 2020年 / 8卷
基金
欧盟地平线“2020”;
关键词
Machine learning; Cryptocurrency; Servers; Data mining; Malware; Protocols; Cryptomining detection; malware detection; cryptojacking detection; cryptocurrency mining; netflow measurements; encrypted traffic classification; machine learning; deep learning;
D O I
10.1109/ACCESS.2020.3019658
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Nowadays, malware has become an epidemic problem. Among the attacks exploiting the computer resources of victims, one that has become usual is related to the massive amounts of computational resources needed for digital currency cryptomining. Cybercriminals steal computer resources from victims, associating these resources to the crypto-currency mining pools they benefit from. This research work focuses on offering a solution for detecting such abusive cryptomining activity, just by means of passive network monitoring. To this end, we identify a new set of highly relevant network flow features to be used jointly with a rich set of machine and deep-learning models for real-time cryptomining flow detection. We deployed a complex and realistic cryptomining scenario for training and testing machine and deep learning models, in which clients interact with real servers across the Internet and use encrypted connections. A complete set of experiments were carried out to demonstrate that, using a combination of these highly informative features with complex machine learning models, cryptomining attacks can be detected on the wire with telco-grade precision and accuracy, even if the traffic is encrypted.
引用
收藏
页码:158036 / 158055
页数:20
相关论文
共 50 条
  • [21] Feature mining for encrypted malicious traffic detection with deep learning and other machine learning algorithms
    Wang, Zihao
    Thing, Vrizlynn L. L.
    COMPUTERS & SECURITY, 2023, 128
  • [22] Android Malware Detection Using Parallel Machine Learning Classifiers
    Yerima, Suleiman Y.
    Sezer, Sakir
    Muttik, Igor
    2014 EIGHTH INTERNATIONAL CONFERENCE ON NEXT GENERATION MOBILE APPS, SERVICES AND TECHNOLOGIES (NGMAST), 2014, : 37 - 42
  • [23] A Closer Look at Machine Learning Effectiveness in Android Malware Detection
    Giannakas, Filippos
    Kouliaridis, Vasileios
    Kambourakis, Georgios
    INFORMATION, 2023, 14 (01)
  • [24] Detecting Cryptomining Malware: a Deep Learning Approach for Static and Dynamic Analysis
    Darabian, Hamid
    Homayounoot, Sajad
    Dehghantanha, Ali
    Hashemi, Sattar
    Karimipour, Hadis
    Parizi, Reza M.
    Choo, Kim-Kwang Raymond
    JOURNAL OF GRID COMPUTING, 2020, 18 (02) : 293 - 303
  • [25] Comprehensive review on machine learning and deep learning techniques for malware detection in android and IoT devicesComprehensive review on machine learning and deep learning techniques...W. Almobaideen et al.
    Wesam Almobaideen
    Orieb Abu Alghanam
    Muhammad Abdullah
    Syed Basit Hussain
    Umar Alam
    International Journal of Information Security, 2025, 24 (3)
  • [26] The Curious Case of Machine Learning in Malware Detection
    Saad, Sherif
    Briguglio, William
    Elmiligi, Haytham
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY (ICISSP), 2019, : 528 - 535
  • [27] A brief survey of deep learning methods for android Malware detection
    Joomye, Abdurraheem
    Ling, Mee Hong
    Yau, Kok-Lim Alvin
    INTERNATIONAL JOURNAL OF SYSTEM ASSURANCE ENGINEERING AND MANAGEMENT, 2025, 16 (02) : 711 - 733
  • [28] Deep learning for image-based mobile malware detection
    Mercaldo, Francesco
    Santone, Antonella
    JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2020, 16 (02) : 157 - 171
  • [29] Android Malware Detection Using Machine Learning
    Droos, Ayat
    Al-Mahadeen, Awss
    Al-Harasis, Tasnim
    Al-Attar, Rama
    Ababneh, Mohammad
    2022 13TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION SYSTEMS (ICICS), 2022, : 36 - 41
  • [30] Deep learning for image-based mobile malware detection
    Francesco Mercaldo
    Antonella Santone
    Journal of Computer Virology and Hacking Techniques, 2020, 16 : 157 - 171