Detection of Encrypted Cryptomining Malware Connections With Machine and Deep Learning

被引:35
|
作者
Pastor, Antonio [1 ]
Mozo, Alberto [2 ]
Vakaruk, Stanislav [2 ]
Canavese, Daniele [3 ]
Lopez, Diego R. [1 ]
Regano, Leonardo [3 ]
Gomez-Canaval, Sandra [2 ]
Lioy, Antonio [3 ]
机构
[1] Telefon I D, Madrid 28010, Spain
[2] Univ Politecn Madrid, Dept Sistemas Informat, Madrid 28031, Spain
[3] Politecn Torino, Dipartimento Automat & Informat, I-10129 Turin, Italy
来源
IEEE ACCESS | 2020年 / 8卷
基金
欧盟地平线“2020”;
关键词
Machine learning; Cryptocurrency; Servers; Data mining; Malware; Protocols; Cryptomining detection; malware detection; cryptojacking detection; cryptocurrency mining; netflow measurements; encrypted traffic classification; machine learning; deep learning;
D O I
10.1109/ACCESS.2020.3019658
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Nowadays, malware has become an epidemic problem. Among the attacks exploiting the computer resources of victims, one that has become usual is related to the massive amounts of computational resources needed for digital currency cryptomining. Cybercriminals steal computer resources from victims, associating these resources to the crypto-currency mining pools they benefit from. This research work focuses on offering a solution for detecting such abusive cryptomining activity, just by means of passive network monitoring. To this end, we identify a new set of highly relevant network flow features to be used jointly with a rich set of machine and deep-learning models for real-time cryptomining flow detection. We deployed a complex and realistic cryptomining scenario for training and testing machine and deep learning models, in which clients interact with real servers across the Internet and use encrypted connections. A complete set of experiments were carried out to demonstrate that, using a combination of these highly informative features with complex machine learning models, cryptomining attacks can be detected on the wire with telco-grade precision and accuracy, even if the traffic is encrypted.
引用
收藏
页码:158036 / 158055
页数:20
相关论文
共 50 条
  • [41] A review of artificial intelligence based malware detection using deep learning
    Mustafa Majid A.-A.
    Alshaibi A.J.
    Kostyuchenko E.
    Shelupanov A.
    Materials Today: Proceedings, 2023, 80 : 2678 - 2683
  • [42] An Automated Vision-Based Deep Learning Model for Efficient Detection of Android Malware Attacks
    Almomani, Iman
    Alkhayer, Aala
    El-Shafai, Walid
    IEEE ACCESS, 2022, 10 : 2700 - 2720
  • [43] Explainable Machine Learning for Malware Detection on Android Applications
    Palma, Catarina
    Ferreira, Artur
    Figueiredo, Mario
    INFORMATION, 2024, 15 (01)
  • [44] Advanced Machine Learning Based Malware Detection Systems
    Kim, Song-Kyoo
    Feng, Xiaomei
    Al Hamadi, Hussam
    Damiani, Ernesto
    Yeun, Chan Yeob
    Nandyala, Sivaprasad
    IEEE ACCESS, 2024, 12 : 115296 - 115305
  • [45] Enhancing Obfuscated Malware Detection with Machine Learning Techniques
    Dang, Quang-Vinh
    FUTURE DATA AND SECURITY ENGINEERING. BIG DATA, SECURITY AND PRIVACY, SMART CITY AND INDUSTRY 4.0 APPLICATIONS, FDSE 2022, 2022, 1688 : 731 - 738
  • [46] A Survey of Malware Detection Techniques based on Machine Learning
    El Merabet, Hoda
    Hajraoui, Abderrahmane
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2019, 10 (01) : 366 - 373
  • [47] FEATURE SELECTION AND MACHINE LEARNING CLASSIFICATION FOR MALWARE DETECTION
    Khammas, Ban Mohammed
    Monemi, Alireza
    Bassi, Joseph Stephen
    Ismail, Ismahani
    Nor, Sulaiman Mohd
    Marsono, Muhammad Nadzir
    JURNAL TEKNOLOGI, 2015, 77 (01):
  • [48] Machine Learning and Recognition of User Tasks for Malware Detection
    Alagrash, Yasamin
    Mohan, Nithasha
    Gollapalli, Sandhya Rani
    Rrushi, Julian
    2019 FIRST IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2019), 2019, : 73 - 81
  • [49] Study on Machine Learning Techniques for Malware Classification and Detection
    Moon, Jaewoong
    Kim, Subin
    Song, Jaeseung
    Kim, Kyungshin
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2021, 15 (12): : 4308 - 4325
  • [50] PDF Malware Detection Using Visualization and Machine Learning
    Liu, Ching-Yuan
    Chiu, Min-Yi
    Huang, Qi-Xian
    Sun, Hung-Min
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXXV, 2021, 12840 : 209 - 220