Detection of Encrypted Cryptomining Malware Connections With Machine and Deep Learning

被引:35
|
作者
Pastor, Antonio [1 ]
Mozo, Alberto [2 ]
Vakaruk, Stanislav [2 ]
Canavese, Daniele [3 ]
Lopez, Diego R. [1 ]
Regano, Leonardo [3 ]
Gomez-Canaval, Sandra [2 ]
Lioy, Antonio [3 ]
机构
[1] Telefon I D, Madrid 28010, Spain
[2] Univ Politecn Madrid, Dept Sistemas Informat, Madrid 28031, Spain
[3] Politecn Torino, Dipartimento Automat & Informat, I-10129 Turin, Italy
来源
IEEE ACCESS | 2020年 / 8卷
基金
欧盟地平线“2020”;
关键词
Machine learning; Cryptocurrency; Servers; Data mining; Malware; Protocols; Cryptomining detection; malware detection; cryptojacking detection; cryptocurrency mining; netflow measurements; encrypted traffic classification; machine learning; deep learning;
D O I
10.1109/ACCESS.2020.3019658
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Nowadays, malware has become an epidemic problem. Among the attacks exploiting the computer resources of victims, one that has become usual is related to the massive amounts of computational resources needed for digital currency cryptomining. Cybercriminals steal computer resources from victims, associating these resources to the crypto-currency mining pools they benefit from. This research work focuses on offering a solution for detecting such abusive cryptomining activity, just by means of passive network monitoring. To this end, we identify a new set of highly relevant network flow features to be used jointly with a rich set of machine and deep-learning models for real-time cryptomining flow detection. We deployed a complex and realistic cryptomining scenario for training and testing machine and deep learning models, in which clients interact with real servers across the Internet and use encrypted connections. A complete set of experiments were carried out to demonstrate that, using a combination of these highly informative features with complex machine learning models, cryptomining attacks can be detected on the wire with telco-grade precision and accuracy, even if the traffic is encrypted.
引用
收藏
页码:158036 / 158055
页数:20
相关论文
共 50 条
  • [31] Automatic malware classification and new malware detection using machine learning
    Liu Liu
    Bao-sheng Wang
    Bo Yu
    Qiu-xi Zhong
    Frontiers of Information Technology & Electronic Engineering, 2017, 18 : 1336 - 1347
  • [32] Automatic malware classification and new malware detection using machine learning
    Liu, Liu
    Wang, Bao-sheng
    Yu, Bo
    Zhong, Qiu-xi
    FRONTIERS OF INFORMATION TECHNOLOGY & ELECTRONIC ENGINEERING, 2017, 18 (09) : 1336 - 1347
  • [33] Application of deep learning in malware detection: a review
    Yafei Song
    Dandan Zhang
    Jian Wang
    Yanan Wang
    Yang Wang
    Peng Ding
    Journal of Big Data, 12 (1)
  • [34] Trend of Malware Detection Using Deep Learning
    Lee, Yoon-seon
    Lee, Jae-ung
    Soh, Woo-young
    ICEMT 2018: PROCEEDINGS OF THE 2018 2ND INTERNATIONAL CONFERENCE ON EDUCATION AND MULTIMEDIA TECHNOLOGY, 2018, : 102 - 106
  • [35] Zero-Day Malware Classification and Detection Using Machine Learning
    Kumar J.
    Rajendran B.
    Sudarsan S.D.
    SN Computer Science, 5 (1)
  • [36] Malware Detection using Malware Image and Deep Learning
    Choi, Sunoh
    Jang, Sungwook
    Kim, Youngsoo
    Kim, Jonghyun
    2017 INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC), 2017, : 1193 - 1195
  • [37] Applications of deep learning for mobile malware detection: A systematic literature review
    Cagatay Catal
    Görkem Giray
    Bedir Tekinerdogan
    Neural Computing and Applications, 2022, 34 : 1007 - 1032
  • [38] Detection of Android Malware Using Machine Learning and Siamese Shot Learning Technique for Security
    Almarshad, Fahdah A.
    Zakariah, Mohammed
    Gashgari, Ghada Abdalaziz
    Aldakheel, Eman Abdullah
    Alzahrani, Abdullah I. A.
    IEEE ACCESS, 2023, 11 : 127697 - 127714
  • [39] Towards Light-weight Deep Learning based Malware Detection
    Kan, Zeliang
    Wang, Haoyu
    Xu, Guoai
    Guo, Yao
    Chen, Xiangqun
    2018 IEEE 42ND ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), VOL 1, 2018, : 600 - 609
  • [40] Applications of deep learning for mobile malware detection: A systematic literature review
    Catal, Cagatay
    Giray, Gorkem
    Tekinerdogan, Bedir
    NEURAL COMPUTING & APPLICATIONS, 2022, 34 (02) : 1007 - 1032