MINOS: A Lightweight Real-Time Cryptojacking Detection System
Faraz Naseem Naseem, Ahmet Aris, Leonardo Babun, Ege Tekiner, A. Selcuk Uluagac
Abstract
Emerging WebAssembly(Wasm)-based cryptojacking malware covertly uses the computational resources of users without their consent or knowledge. Indeed, most victims of this malware are unaware of such unauthorized use of their computing power due to techniques employed by cryptojacking malware authors such as CPU throttling and obfuscation. A number of dynamic analysis-based detection mechanisms exist that aim to circumvent such techniques. However, since these mechanisms use dynamic features, the collection of such features, as well as the actual detection of the malware, require that the cryptojacking malware run for a certain amount of time, effectively mining for that period, and therefore causing significant overhead. To solve these limitations, in this paper, we propose MINOS, a novel, extremely lightweight cryptojacking detection system that uses deep learning techniques to accurately detect the presence of unwarranted Wasm-based mining activity in real-time. MINOS uses an image-based classification technique to distinguish between benign webpages and those using Wasm to implement unauthorized mining. Specifically, the classifier implements a convolutional neural network (CNN) model trained with a comprehensive dataset of current malicious and benign Wasm binaries. MINOS achieves exceptional accuracy with a low TNR and FPR. Moreover, our extensive performance analysis of MINOS shows that the proposed detection technique can detect mining activity instantaneously from the most current in-the-wild cryptojacking malware with an accuracy of 98.97%, in an average of 25.9 milliseconds while using a maximum of 4% of the CPU and 6.5% of RAM, proving that MINOS is highly effective while lightweight, fast, and computationally inexpensive.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 14672d4f-06a3-4e4c-83fc-58e51a77813dCited by top-tier papers6
- MagTracer: Detecting GPU Cryptojacking Attacks via Magnetic Leakage SignalsRui Xiao, Tianyu Li, Soundarya Ramesh, Jun Han et al.MobiCom 2023 · 20 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- An Extensive Study of Residential Proxies in ChinaMingshuo Yang, Yunnan Yu, Xianghang Mi, Shujun Tang et al.CCS 2022 · 9 citations
- Ready Raider One: Exploring the Misuse of Cloud Gaming ServicesGuannan Liu, Daiping Liu, Shuai Hao, Xing Gao et al.CCS 2022 · 2 citations
- A Lightweight IoT Cryptojacking Detection Mechanism in Heterogeneous Smart Home NetworksEge Tekiner, Abbas Acar, A. Selcuk UluagacNDSS 2022
Builds on5
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Sensitive Information Tracking in Commodity IoTZ. Berkay Celik, Leonardo Babun, Amit Kumar Sikder, Hidayet Aksu et al.USENIX Security 2018 · 236 citations
- MineSweeper: An In-depth Look into Drive-by Cryptocurrency Mining and Its DefenseRadhesh Krishnan Konoth, Emanuele Vineti, Veelasha Moonsamy, Martina Lindorfer et al.CCS 2018 · 162 citations
- How You Get Shot in the Back: A Systematical Study about Cryptojacking in the Real WorldGeng Hong, Zhemin Yang, Sen Yang, Lei Zhang et al.CCS 2018 · 120 citations
- Just the Tip of the Iceberg: Internet-Scale Exploitation of Routers for CryptojackingHugo L. J. Bijmans, Tim M. Booij, Christian DoerrCCS 2019 · 32 citations
Related papers
- When Does Wasm Malware Detection Fail? A Systematic Analysis of Their Robustness to EvasionTaeyoung Kim, Sanghak Oh, Kiho Lee, Weihang Wang et al.ASE 2025
- WasmGuard: Enhancing Web Security through Robust Raw-Binary Detection of WebAssembly MalwareYuxia Sun, Huihong Chen, Zhixiao Fu, Wenjian Lv et al.WWW 2025 · 2 citations
- MinerRay: Semantics-Aware Analysis for Ever-Evolving Cryptojacking DetectionAlan Romano, Yunhui Zheng, Weihang WangASE 2020 · 30 citations
- Dynamic Malware Analysis with Feature Engineering and Feature LearningZhaoqi Zhang, Panpan Qi, Wei WangAAAI 2020 · 153 citations
- MineShark: Cryptomining Traffic Detection at ScaleShaoke Xi, Tianyi Fu, Kai Bu, Chunling Yang et al.NDSS 2025
