A Mining Traffic Identification Method under Encrypted Proxy Based on K-S Test
The K-S test-based method efficiently identifies encrypted mining traffic by analyzing packet size and time intervals, achieving high accuracy and rapid detection of mining activities with minimal user intervention and low configuration costs.
Patent Information
- Application Number
- CN202310006129.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-04
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2043-01-04
AI Technical Summary
The existing traffic analysis methods are difficult to effectively identify mining traffic in the encryption proxy scenario, and the existing methods require software installation or data set balancing, and the detection time is long.
By building an encrypted proxy forwarding and obfuscating data packets, collecting mining traffic, extracting packet size and time interval characteristics, and using K-S test to compare and identify mining traffic.
It realizes accurate identification of mining traffic under the encryption agent, shortens the detection time to zero false alarms within six minutes, and the recall rate reaches 98.84%, effectively supervising mining behavior.
Smart Images

Figure CN115955357B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of cyberspace security and relates to a method for identifying mining traffic under an encrypted proxy based on the K-S test. Background Art
[0002] As the underlying technology of Bitcoin, blockchain is essentially a decentralized database that can achieve functions such as consistent storage of data in the ledger, difficulty in tampering, and prevention of repudiation. Mining is an essential process for blockchain. It not only verifies and adds transactions to the blockchain but also establishes consensus in a decentralized organization. The benefits of mining have also attracted the attention of hackers. Crypto-jacking refers to the act of manipulating a device to mine cryptocurrencies for the attacker's benefit against the user's will or without the user's knowledge. Since 2018, crypto-jacking has become a widespread attack similar to ransomware. Hackers develop malware to attack personal computers, servers, and even Internet of Things devices, making them mine cryptocurrencies for the hackers.
[0003] The mining behavior itself consumes a large amount of computing resources, causing the system, software, and application services to run slowly and even potentially crashing the system and causing data loss; virtual currency mining causes a large amount of energy consumption and carbon emissions. Crypto-jacking occupies the resources of the victim device, affects the normal use of the victim user, and brings illegal benefits to the attacker. Therefore, detecting mining behavior can not only prevent crypto-jacking attacks but also help control the proliferation of virtual currency mining.
[0004] There have been some host-based methods to defend against crypto-jacking. They identify whether a device has been hijacked for mining by monitoring software operations, website access, and hardware status data. However, these methods require installing software on the terminal device, involve the user's private data, and need to be updated in a timely manner, which is rejected by many users. In addition, host-based methods only protect a single terminal device, and protecting a managed network requires installing and maintaining monitoring software on each device. Therefore, in recent years, researchers have more often detected crypto-jacking through network traffic analysis. The original mining traffic follows the Stratum protocol and is transmitted in plaintext, so it can be defended against through IP blocking and deep packet inspection. However, attackers can still encrypt, obfuscate, and forward mining traffic by configuring an encrypted proxy to evade supervision. The existing traffic analysis methods do not perform well in the scenario of using an encrypted proxy for mining, either requiring a relatively balanced dataset or a long detection time.
[0005] Therefore, the present invention collects mining traffic by building an encrypted proxy for forwarding, encrypting and obfuscating data packets, and joining a mining pool for mining; then preprocesses the traffic to extract the characteristic distributions of the mining traffic and the traffic to be tested; and finally uses the K-S test to compare the characteristic distributions, and completes the identification of the mining traffic according to the results of the K-S test. Summary of the Invention
[0006] In order to effectively supervise mining behaviors and realize the identification of mining traffic using encrypted proxies, the present invention proposes a method for identifying mining traffic under an encrypted proxy based on the K-S test. Aiming at the problem that it is difficult to detect mining traffic using encrypted proxies, an efficient method for identifying mining traffic is proposed by using the K-S test to compare the characteristic distribution functions. The method first groups and filters the initial traffic according to the protocol characteristics of the mining traffic. Then, through the characteristic analysis of the mining traffic, the characteristics of the data packet size and the time interval are extracted as the detection basis; subsequently, the incoming traffic is taken as a detection unit for every 60 data packets, and the outgoing traffic is taken as a detection unit for every 40 data packets, and the characteristic distribution functions of the data packet size and the data packet time interval are respectively generated; finally, the K-S test is used to compare the characteristic distributions of the traffic to be detected and the mining traffic, and the identification of the mining traffic is completed according to the results of the K-S test. To achieve the above object, the present invention provides the following technical solutions:
[0007] A method for identifying mining traffic under an encrypted proxy based on the K-S (Kolmogorov-Smirnov test) test, comprising the following steps:
[0008] (1) Collect mining traffic by joining a mining pool for mining, using an encrypted proxy to forward and obfuscate data;
[0009] (2) Group the initial traffic according to the five-tuple <source IP, destination IP, source port, destination port, protocol type>, and then filter out irrelevant data packets, only retaining TCP packets with the PSH flag;
[0010] (3) Extract the characteristics of the remaining packets, and generate a characteristic distribution according to the number of data packets in each set detection unit;
[0011] (4) Compare the characteristic distribution of the traffic to be detected with the marked mining traffic through the K-S test, and realize the identification of the mining traffic according to the test results.
[0012] Further, the step (1) specifically includes the following sub-steps:
[0013] (1.1) Use the V2Ray tool to build an encrypted proxy to achieve data forwarding, encryption and obfuscation;
[0014] (1.2) Join the Poolin mining pool to mine two cryptocurrencies, Ether and Ethereum Classic;
[0015] (1.3) Collect mining traffic that uses an encrypted proxy;
[0016] (1.4) Generate the feature distribution of the mining traffic under the encrypted proxy;
[0017] (1.5) Obtain the public dataset ISCX VPN as the traffic to be tested in the experiment.
[0018] Further, the step (2) specifically includes the following sub-steps:
[0019] (2.1) Group the initial traffic according to the five-tuple <source IP, destination IP, source port, destination port, protocol type>. This step is to distinguish different applications that use the same proxy.
[0020] (2.2) According to the protocol characteristics of the mining traffic, filter out irrelevant packets and only leave TCP packets with the PSH flag. The function of the PSH flag bit is to let the receiving end deliver the packets to the application layer as soon as possible, and the mining revenue is closely related to time.
[0021] Further, the step (3) specifically includes the following sub-steps:
[0022] (3.1) Extract the features of the remaining traffic after data preprocessing, including the packet size and packet time interval features;
[0023] (3.2) For the incoming traffic, take every 60 packets as a detection unit, and for the outgoing traffic, take every 40 packets as a detection unit, and generate the feature distribution functions of the packet size and packet time interval respectively.
[0024] Further, the step (4) specifically includes the following sub-steps:
[0025] (4.1) Input the feature distribution function of the unrecognized traffic into the detection model, and use the two-sample K-S test to compare it with the feature distribution of the labeled mining traffic, and output the test result;
[0026] (4.2) According to the K-S test result, if the packet size and time interval features of the unrecognized traffic both come from the same distribution as the features of the mining traffic, then determine this traffic as mining traffic, otherwise determine it as normal traffic.
[0027] (4.3) Output the recognition result.
[0028] Compared with the prior art, the present invention has the following advantages:
[0029] (1) The present invention can effectively identify the mining traffic existing in the current network, with the precision rate of the monitoring effect reaching 100% and the recall rate reaching 98.84%. It is convenient for network administrators to supervise mining behaviors and defend against cryptocurrency hijacking behaviors.
[0030] (2) The present invention analyzes the characteristics of mining traffic after using an encryption proxy. The cost of configuring an encryption proxy is very low, and using it can well avoid supervision, so this scenario is more relevant and meaningful to the actual detection situation.
[0031] (3) In the present invention, by analyzing the mining traffic before and after using an encryption proxy, it is found that the packet size and time interval distribution are significantly different from other traffic. Combining with the K-S test method, it only takes six minutes of observation of mining traffic to complete the detection and achieve zero false alarms, effectively improving the detection speed and accuracy.
[0032] (4) Through adversarial evaluation, the method for identifying mining traffic under an encryption proxy based on the K-S test proposed by the present invention can, to a certain extent, prevent attackers from escaping detection by changing packet characteristics. The specific manifestations of the adversarial evaluation are shown in the following two tables
[0033] Description of the Drawings
[0034] Figure 1 Schematic diagram of the detector architecture;
[0035] Figure 2 Schematic diagram for comparing the time interval distributions of mining and other traffic;
[0036] Figure 3 Schematic diagram for comparing the packet size distributions of mining and other traffic, where (a) is the comparison diagram of the packet sizes of in-degree direction traffic, and (b) is the comparison diagram of the packet sizes of out-degree direction traffic;
[0037] Figure 4 Model detection performance under different detection window sizes. Detailed Embodiments
[0038] The following will detail the technical solutions provided by the present invention in combination with specific embodiments. It should be understood that the following specific embodiments are only used to illustrate the present invention and not to limit the scope of the present invention.
[0039] Embodiment 1: The present invention proposes a method for identifying mining traffic under an encryption proxy based on the K-S test, and the identification framework is as Figure 1As shown in the figure, it is divided into four parts. The first part is the collection of mining traffic under the encryption proxy. The specific content is to build an encryption proxy using the V2Ray tool to achieve data forwarding and obfuscation, join the Poolin mining pool, mine two cryptocurrencies, Ether and Ethereum Classic, and then collect the mining traffic using the encryption proxy, and obtain the public dataset ISCX VPN as the experimental traffic to be measured; the second part is the preprocessing of traffic data. The specific content is to analyze the protocol characteristics of mining traffic as the basis for the preprocessing stage, group the initial traffic by five-tuple, and then filter out irrelevant packets, leaving only TCP packets with the PSH flag; the third part is the extraction of features. The specific content is to extract the features of the remaining traffic after data preprocessing, including the packet size and the packet time interval features. Then, the incoming traffic is taken as a detection unit for every 60 packets, and the outgoing traffic is taken as a detection unit for every 40 packets, and the feature distribution functions of the packet size and the packet time interval are generated respectively; the fourth part is the identification of mining traffic. The specific content is to input the feature distribution function of the unrecognized traffic into the detection model, use the two-sample K-S test to compare with the feature distribution of the labeled mining traffic, and then output the identification result according to the test result.
[0040] Specifically, a method for identifying mining traffic under an encryption proxy based on the K-S test includes the following steps:
[0041] (1) Mine by joining a mining pool, use an encryption proxy to forward and obfuscate data, and collect mining traffic.
[0042] The specific process of this step is as follows:
[0043] (1.1) Build an encryption proxy using the V2Ray tool to achieve data forwarding, encryption and obfuscation;
[0044] (1.2) Join the Poolin mining pool and mine two cryptocurrencies, Ether and Ethereum Classic;
[0045] (1.3) Collect the mining traffic using the encryption proxy;
[0046] (1.4) Generate the feature distribution of mining traffic;
[0047] (1.5) Obtain the public dataset ISCX VPN as the experimental traffic to be measured.
[0048] (2) Group the initial traffic according to the five-tuple <source IP, destination IP, source port, destination port, protocol type>, and then filter out irrelevant data packets, only retaining TCP packets with the PSH flag. This step can filter out 80% of the initial traffic, reducing the subsequent processing time of the model.
[0049] The specific process in this step is as follows:
[0050] (2.1) Observe the communication behavior between miners and mining pools during the mining process, analyze the overall characteristics of mining traffic, and find that there is less interaction during the mining process, and it mainly consists of three actions: task distribution, result submission, and result feedback; therefore, the mining traffic is relatively sparse, the time interval between data packets is long, and the traffic characteristics show regularity within a certain time window;
[0051] (2.2) Analyze the data packet structure of mining traffic, obtain the protocol type and TCP flag bit characteristics of mining traffic, and find that mining traffic packets all use the TCP protocol, and data packets with payloads all carry the PSH flag, the port numbers are fixed within a certain period of time, and the data packet sizes are evenly distributed within a fixed range;
[0052] (2.3) According to the relevant characteristics obtained in steps (2.1) and (2.2), as the basis for the preprocessing stage, group the initial traffic according to the five-tuple, and then filter out irrelevant packets, only leaving TCP packets with the PSH flag.
[0053] (3) After completing the traffic preprocessing, extract the characteristics of the remaining packets and generate a feature distribution according to the number of data packets in each detection unit set.
[0054] The specific process in this step is as follows:
[0055] (3.1) Use the data set remaining after filtering in step (2) to extract the data packet size and data packet time interval characteristics. From Figure 2 、 Figure 3 It can be seen that the distribution of the data packet size and time interval of mining traffic using an encrypted proxy has particularity.
[0056] (3.2) Evaluate the performance of models with different numbers of detection unit sizes. According to the results, select to use 60 data packets as one detection unit for the incoming traffic and 40 data packets as one detection unit for the outgoing traffic, and generate the feature distribution functions of the data packet size and data packet time interval respectively. The specific performance results of different numbers of detection units are as Figure 4 .
[0057] (4) Compare the feature distribution of the traffic to be detected with the labeled mining traffic through the K-S test, and identify the mining traffic according to the test results.
[0058] The specific process in this step is as follows:
[0059] (4.1) Input the characteristic distribution function of the unrecognized traffic into the detection model, and use the two-sample K-S test to compare it with the characteristic distribution of the labeled mining traffic, and output the test result.
[0060] (4.2) According to the K-S test result, if the packet size and time interval characteristics of the unrecognized traffic both come from the same distribution as the characteristics of the mining traffic, then determine this traffic as mining traffic; otherwise, determine it as normal traffic.
[0061] (4.3) Output the recognition result. The experiment achieved a precision of 100% and a recall rate of 98.84%. The confusion matrix result is shown in the following table
[0062]
[0063] The technical means disclosed in the solution of the present invention are not limited to the technical means disclosed in the above embodiments, and also include technical solutions composed of any combination of the above technical features. It should be noted that for those of ordinary skill in the art of this technology, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements are also regarded as the protection scope of the present invention.
Claims
1. A method for identifying mining traffic under an encrypted proxy based on the K-S test, characterized in that It includes the following steps: (1) Join a mining pool for mining, set up an encryption proxy to forward and obfuscate data, collect mining traffic, and generate the characteristic distribution of mining traffic; (2) Group the initial traffic according to the five-tuple <source IP, destination IP, source port, destination port, protocol type>, and then filter out irrelevant data packets, only retaining TCP packets with the PSH flag; (3) Extract the characteristics of the preprocessed packets and generate the characteristic distribution according to the number of data packets in each detection unit set; (4) Compare the characteristic distribution of the traffic to be detected with the mining traffic through the K-S test, and identify the mining traffic according to the test results; The specific steps of step (4) include the following sub-steps: (4.1) Input the characteristic distribution function of the unrecognized traffic into the detection model, use the two-sample K-S test to compare it with the characteristic distribution of the labeled mining traffic, and output the K-S test result; (4.2) According to the K-S test result, if the packet size and time interval characteristics of the unrecognized traffic both come from the same distribution as the characteristics of the mining traffic, then determine this traffic as mining traffic, otherwise determine it as normal traffic; (4.3) Output the model recognition result.
2. The method for identifying mining traffic under an encrypted proxy based on the K-S test according to claim 1, wherein Step (1) collects mining traffic using an encryption proxy; specifically includes the following sub-steps: (1.1) Use the V2Ray tool to set up an encryption proxy to achieve data forwarding, encryption, and obfuscation; (1.2) Join the Poolin mining pool to mine two cryptocurrencies, Ethereum and Ethereum Classic; (1.3) Collect mining traffic using the encryption proxy; (1.4) Generate the characteristic distribution of mining traffic under the encryption proxy; (1.5) Obtain the publicly available dataset ISCX VPN as the traffic to be tested in the experiment.
3. The method for identifying mining traffic under an encrypted proxy based on the K-S test according to claim 1, wherein The specific steps of step (2) include the following sub-steps: (2.1) Group the initial traffic according to the five-tuple <source IP, destination IP, source port, destination port, protocol type>, which is to distinguish different applications using the same proxy; (2.2) According to the protocol characteristics of the mining traffic, filter out irrelevant packets, only leaving TCP packets with the PSH flag. The function of the PSH flag bit is to let the receiving end deliver the packet to the application layer as soon as possible, and the mining revenue is closely related to time.
4. The mining traffic identification method under an encrypted proxy based on the K-S test according to claim 1, wherein The specific steps of step (3) include the following sub-steps: (3.1) Extract the packet header information of the remaining traffic after data preprocessing, including the packet size and packet time interval characteristics; (3.2) For the incoming traffic, take every 60 packets as a detection unit, and for the outgoing traffic, take every 40 packets as a detection unit to generate the characteristic distribution function of the packet size and packet time interval.
Citation Information
Patent Citations
Machine-learning-based flow identification technology
CN108833360A
Mining Trojan horse detection system based on flow analysis
CN110933060A