MineSweeper: An In-depth Look into Drive-by Cryptocurrency Mining and Its Defense
Radhesh Krishnan Konoth, Emanuele Vineti, Veelasha Moonsamy, Martina Lindorfer, Christopher Kruegel, Herbert Bos, Giovanni Vigna
Abstract
A wave of alternative coins that can be effectively mined without specialized hardware, and a surge in cryptocurrencies' market value has led to the development of cryptocurrency mining ( cryptomining ) services, such as Coinhive, which can be easily integrated into websites to monetize the computational power of their visitors. While legitimate website operators are exploring these services as an alternative to advertisements, they have also drawn the attention of cybercriminals: drive-by mining (also known as cryptojacking ) is a new web-based attack, in which an infected website secretly executes JavaScript code and/or a WebAssembly module in the user's browser to mine cryptocurrencies without her consent. In this paper, we perform a comprehensive analysis on Alexa's Top 1 Million websites to shed light on the prevalence and profitability of this attack. We study the websites affected by drive-by mining to understand the techniques being used to evade detection, and the latest web technologies being exploited to efficiently mine cryptocurrency. As a result of our study, which covers 28 Coinhive-like services that are widely being used by drive-by mining websites, we identified 20 active cryptomining campaigns. Motivated by our findings, we investigate possible countermeasures against this type of attack. We discuss how current blacklisting approaches and heuristics based on CPU usage are insufficient, and present MineSweeper, a novel detection technique that is based on the intrinsic characteristics of cryptomining code, and, thus, is resilient to obfuscation. Our approach could be integrated into browsers to warn users about silent cryptomining when visiting websites that do not ask for their consent.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 740b7b27-cf5f-4e65-818d-a2c62a8316dbCited by top-tier papers31
- Investigating System Operators' Perspective on Security MisconfigurationsConstanze Dietrich, Katharina Krombholz, Kevin Borgolte, Tobias FiebigCCS 2018 · 116 citations
- An Empirical Study of Real-World WebAssembly Binaries: Security, Languages, Use CasesAaron Hilbig, Daniel Lehmann, Michael PradelWWW 2021 · 114 citations
- Less is More: Quantifying the Security Benefits of Debloating Web ApplicationsBabak Amin Azad, Pierre Laperdrix, Nick NikiforakisUSENIX Security 2019 · 100 citations
- ICLab: A Global, Longitudinal Internet Censorship Measurement PlatformArian Akhavan Niaki, Shinyoung Cho, Zachary Weinberg, Nguyen Phong Hoang et al.S&P 2020 · 94 citations
- HideNoSeek: Camouflaging Malicious JavaScript in Benign ASTsAurore Fass, Michael Backes, Ben StockCCS 2019 · 78 citations
Related papers
- How You Get Shot in the Back: A Systematical Study about Cryptojacking in the Real WorldGeng Hong, Zhemin Yang, Sen Yang, Lei Zhang et al.CCS 2018 · 120 citations
- MinerRay: Semantics-Aware Analysis for Ever-Evolving Cryptojacking DetectionAlan Romano, Yunhui Zheng, Weihang WangASE 2020 · 30 citations
- Inadvertently Making Cyber Criminals Rich: A Comprehensive Study of Cryptojacking Campaigns at Internet ScaleHugo L. J. Bijmans, Tim M. Booij, Christian DoerrUSENIX Security 2019 · 46 citations
- Just the Tip of the Iceberg: Internet-Scale Exploitation of Routers for CryptojackingHugo L. J. Bijmans, Tim M. Booij, Christian DoerrCCS 2019 · 32 citations
- MINOS: A Lightweight Real-Time Cryptojacking Detection SystemFaraz Naseem Naseem, Ahmet Aris, Leonardo Babun, Ege Tekiner et al.NDSS 2021
