Title
MANiC: Multi-step Assessment for Crypto-miners
Abstract
Modern Browsers have become sophisticated applications, providing a portal to the web. Browsers host a complex mix of interpreters such as HTML and JavaScript, allowing not only useful functionality but also malicious activities, known as browser-hijacking. These attacks can be particularly difficult to detect, as they usually operate within the scope of normal browser behaviour. CryptoJacking is a form of browser-hijacking that has emerged as a result of the increased popularity and profitability of cryptocurrencies, and the introduction of new cryptocurrencies that promote CPU-based mining. This paper proposes MANiC (Multi-step AssessmeNt for Crypto-miners), a system to detect CryptoJacking websites. It uses regular expressions that are compiled in accordance with the API structure of different miner families. This allows the detection of crypto-mining scripts and the extraction of parameters that could be used to detect suspicious behaviour associated with CryptoJacking. When MANiC was used to analyse the Alexa top 1m websites, it detected 887 malicious URLs containing miners from 11 different families and demonstrated favourable results when compared to related CryptoJacking research. We demonstrate that MANiC can be used to provide insights into this new threat, to identify new potential features of interest and to establish a ground-truth dataset, assisting future research.
Year
DOI
Venue
2019
10.1109/CyberSecPODS.2019.8885003
2019 International Conference on Cyber Security and Protection of Digital Services (Cyber Security)
Keywords
DocType
ISBN
CryptoJacking,Drive-by Mining,Crypto-mining,Malware,Browser Security,Web-based Threats
Conference
978-1-7281-0230-6
Citations 
PageRank 
References 
1
0.35
5
Authors
4
Name
Order
Citations
PageRank
Jonah Burgess131.74
Domhnall Carlin211.37
Philip O'Kane350.75
Sakir Sezer4101084.22