Virtual currency mining machine number identification method and device, electronic equipment and storage medium
By acquiring the data packet traffic characteristics of communication between miners and mining pools in an encrypted traffic environment, filtering notification and submission data packets, and using timestamps to determine the active time of the source port, the error problem of miner number identification under shared IP and dynamic port switching is solved, and high-precision miner number identification is achieved.
Patent Information
- Application Number
- CN202511046903.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-29
- Publication Date
- 2025-11-11
AI Technical Summary
Existing technologies struggle to accurately identify the number of cryptocurrency mining machines in encrypted traffic environments, especially with shared IPs and dynamic port switching. This leads to significant errors in traditional methods, making it difficult to effectively monitor mining activities.
By acquiring the encrypted communication traffic between the mining rig set and the mining pool, extracting the traffic characteristics of the data packets, filtering out notification data packets and submission data packets, and using the timestamps of the data packets to determine the active time of the source port, the number of mining rigs can be accurately identified.
Without decrypting the traffic, it improves the accuracy of identifying the number of mining machines, breaks through the analysis bottleneck in encrypted environments, effectively distinguishes different mining machines, and supports the supervision of illegal mining activities.
Smart Images

Figure CN120934798A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of traffic monitoring technology, and in particular to methods, devices, electronic devices and storage media for identifying the number of virtual currency mining machines. Background Technology
[0002] Cryptocurrency mining involves using computer hardware to perform complex mathematical calculations to solve cryptographic problems and verify transactions, thereby earning cryptocurrency rewards. Mining activities consume significant amounts of electricity and network bandwidth, especially as computing power increases, leading to a continuous growth in the number and scale of mining rigs. This not only results in enormous resource consumption but also causes energy waste and excessive network bandwidth usage. Therefore, related technologies require the regulation and identification of cryptocurrency mining activities. However, to evade regulation, mining organizations often conceal their activities through encrypted traffic, posing a significant challenge to traditional traffic analysis methods. Summary of the Invention
[0003] The main objective of this application is to provide a method, apparatus, electronic device, and storage medium for identifying the number of cryptocurrency mining machines, aiming to improve the accuracy of mining machine identification under encrypted mining traffic conditions. The technical solution is as follows: In a first aspect, embodiments of this application provide a method for identifying the number of virtual currency mining machines, including: Acquire encrypted communication traffic between the mining rig cluster and the mining pool; Obtain the traffic characteristics of data packets in the encrypted communication traffic; the traffic characteristics include at least the source port of the data packet, the size of the data packet, and the timestamp of the data packet; Based on the traffic characteristics, notification data packets and submission data packets are determined from the encrypted communication traffic; Based on the timestamp of the notification data packet and the timestamp of the submission data packet, the active time of each source port within a set time range is determined; The number of mining machines performing mining in the mining machine set is determined based on the active time.
[0004] Secondly, embodiments of this application provide a virtual currency mining machine quantity identification device, comprising: The traffic acquisition unit is used to acquire the encrypted communication traffic between the mining machine cluster and the mining pool; The feature acquisition unit is used to acquire the traffic features of data packets in the encrypted communication traffic; the traffic features include at least the source port of the data packet, the size of the data packet, and the timestamp of the data packet; A data packet filtering unit is used to determine notification data packets and submission data packets from the encrypted communication traffic based on the traffic characteristics; An activity detection unit is used to determine the active time of each source port within a set time range based on the timestamp of the notification data packet and the timestamp of the submission data packet; A quantity determination unit is used to determine the number of mining machines performing mining in the mining machine set based on the active time.
[0005] Thirdly, embodiments of this application provide an electronic device, the electronic device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the steps of the method described above.
[0006] Fourthly, embodiments of this application provide a storage medium storing a computer program, which, when executed by a processor, implements the steps of the method described above.
[0007] In this embodiment, the encrypted communication traffic between the mining rig set and the mining pool is acquired, and the traffic characteristics of the data packets in the encrypted communication traffic are obtained. Then, notification data packets and submission data packets are filtered out from the encrypted communication traffic based on the traffic characteristics. The notification data packets and submission data packets reflect the interaction between the mining rig set and the mining pool. Therefore, the active time of interaction between each source port corresponding to the mining rig set and the mining pool within a set time range can be determined by the timestamps of the notification data packets and submission data packets. Each mining rig typically communicates with the mining pool through different ports, and the number of mining rigs is determined based on the active duration of each source port. Using this method, without relying on decrypted traffic, the metadata characteristics (traffic characteristics) of the traffic can be used to effectively distinguish different mining rigs in the mining rig set and accurately identify the number of mining rigs. Attached Figure Description
[0008] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0009] Figure 1 This is a schematic diagram of a scenario for a method for identifying the number of virtual currency mining machines provided in an embodiment of this application; Figure 2 This is a schematic diagram of a scenario for a method for identifying the number of virtual currency mining machines provided in an embodiment of this application; Figure 3 This is a flowchart illustrating a method for identifying the number of virtual currency mining machines provided in an embodiment of this application; Figure 4This is a schematic diagram of the communication process of a virtual currency mining machine quantity identification method provided in an embodiment of this application; Figure 5 This is a flowchart illustrating a method for identifying the number of virtual currency mining machines provided in an embodiment of this application; Figure 6 This is a flowchart illustrating a method for identifying the number of virtual currency mining machines provided in an embodiment of this application; Figure 7 This is a flowchart illustrating a method for identifying the number of virtual currency mining machines provided in an embodiment of this application; Figure 8 This is a flowchart illustrating a method for identifying the number of virtual currency mining machines provided in an embodiment of this application; Figure 9 This is a schematic diagram of the structure of a virtual currency mining machine quantity identification device provided in an embodiment of this application; Figure 10 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0010] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this specification.
[0011] In the description of this specification, it should be understood that the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. In the description of this specification, it should be noted that, unless otherwise expressly specified and limited, "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or devices. Those skilled in the art can understand the specific meaning of the above terms in this specification based on the specific circumstances. Furthermore, in the description of this specification, unless otherwise stated, "multiple" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship.
[0012] Accurate estimation of the number of cryptocurrency mining rigs is crucial for cracking down on illegal mining, helping regulators identify illicit activities and allocate public resources appropriately. One related technology relies on Deep Packet Inspection (DPI) to directly extract keywords (such as miner names and task IDs) from network traffic packets to estimate the number of miners. However, with the widespread adoption of traffic encryption, traditional methods face significant challenges because this crucial information cannot be directly extracted from encrypted traffic. Furthermore, they struggle to handle complex network environments such as shared IPs and dynamic port switching.
[0013] A mining farm refers to a location comprised of a large number of computer devices (usually specialized mining rigs) specifically used for mining cryptocurrencies. In mining farms, due to the relative scarcity of public IP addresses, especially in large-scale environments, multiple mining rigs typically share one or a few public IP addresses for mining. Although these mining rigs communicate with the mining pool through the same public IP address, each rig's connection is still distinguished by a different source port number. For example... Figure 1 As shown, miner 1 corresponds to Port1 (source port 1), miner 2 corresponds to Port2 (source port 2), and miner n corresponds to Port3 (source port 3). The operating system dynamically assigns a unique port number to each connection, ensuring that the mining pool can distinguish connection requests from different miners at the protocol level. However, determining the number of miners solely based on the number of port numbers is still inaccurate. For example, if a miner disconnects from the mining pool and then reconnects to continue mining, the reconnection will assign a new port number, causing errors in identifying the number of miners based on the number of port numbers.
[0014] To address the aforementioned issues, this application provides a method for identifying the number of cryptocurrency mining machines. The method involves acquiring the encrypted communication traffic between a mining machine set (such as all mining machines in a mining farm) and a mining pool. Then, it extracts the traffic characteristics of the data packets, primarily including the source port, packet size, and timestamp. These traffic characteristics distinguish between "notification packets" and "submission packets." Notification packets refer to data packets used by the mining pool to issue mining tasks, while submission packets refer to data packets submitted by mining machines in response to mining tasks, reflecting the interaction process between the mining machine set and the mining pool. Based on the timestamps of the "notification packets" and "submission packets," the active time of the source port within a set time range is calculated. Then, the number of mining machines actually performing mining in the mining machine set is determined based on the active time of each source port. Combining the active time of the source ports improves the accuracy of identifying the number of mining machines. Furthermore, this method avoids the complexity of decrypting traffic, directly utilizing traffic metadata for analysis, thus overcoming the traditional analysis bottlenecks in encrypted mining environments.
[0015] Please see Figure 2This document provides a scenario illustration of a method for identifying the number of cryptocurrency mining machines in an embodiment of this application. The mining machine number identification device provided in this embodiment can be a terminal device such as a mobile phone, computer, or tablet computer, or it can be a module in the terminal device used to implement the mining machine number identification generation method. For example, the mining machine number identification device can be a traffic monitoring platform, which monitors network traffic. For instance, the traffic monitoring platform can obtain encrypted traffic between the mining machine set (mining farm) and the mining pool through network packet capture, automated scripts or systems directly obtaining data from the public interface of the mining pool, web crawlers, manual import, etc. The traffic monitoring platform performs feature analysis on the encrypted communication traffic between the mining machines and the mining pool to obtain traffic features. Based on these features, it filters out notification data packets and submission data packets from the encrypted communication traffic, and determines the active time of each source port corresponding to the data packet based on the timestamp of the notification data packet and the timestamp of the submission data packet, thereby identifying the number of mining machines contained in the encrypted mining traffic.
[0016] The method for identifying the number of virtual currency mining machines provided in this specification will be described in detail below with reference to specific embodiments.
[0017] Please see Figure 3 This is a flowchart illustrating a method for identifying the number of cryptocurrency mining machines, as provided in this application embodiment. Figure 3 As shown, the method described in this application embodiment may include the following steps S101-S105.
[0018] S101, obtain the encrypted communication traffic between the mining machine set and the mining pool; In one embodiment, a mining machine typically refers to the equipment or software used in cryptocurrency mining to generate and send mining data packets to a mining pool. A mining machine pool can be a collection of all mining machines within a designated institution, company, or server; these machines may share one or more IP addresses. The mining pool server breaks down the transaction blocks to be verified on the blockchain network into smaller computational tasks (such as hash calculation fragments) and distributes them to connected mining machines. Miners and the mining pool server communicate via a specific communication protocol; common mining communication protocols include the GetWorks protocol and the Stratum protocol.
[0019] In one feasible implementation, network traffic between mining rigs and mining pools can be captured in real time using network packet capture tools (such as Wireshark, tcpdump, etc.). You can specify the IP address or domain name of the target mining rig and mining pool to filter and capture relevant data packets. Optionally, many mining pools provide open API interfaces, allowing you to query basic information about the pool, hash rate, online miners, and other data. These APIs can be used to monitor the status of the mining pool periodically. If the traffic uses TLS encryption, the mining pool can be identified by checking the IP address and port. In addition, traffic logging can be configured on network devices or firewalls, and the log files can be analyzed periodically. Traffic logs typically record information such as the source IP, destination IP, communication protocol, and port of the connection. Optionally, deep packet inspection technology can be used to perform deep parsing on every data packet passing through the network to identify specific application layer protocols (such as mining pool protocols) and other specific traffic characteristics, thereby obtaining the encrypted communication traffic.
[0020] S102, Obtain the traffic characteristics of data packets in the encrypted communication traffic; In one embodiment, statistical characteristics of data packets in encrypted communication traffic are obtained. Without decryption, the source port, destination port, source IP, destination IP, protocol, and protocol version number of each data packet can be obtained; the packet duration and arrival time of each data packet; and one or more of the following: the number of forward / reverse packets, the number of forward / reverse bytes, and the length of forward / reverse packets. Here, "forward / reverse packet" is a relative concept; for example, if a packet sent from the server to the client is considered positive, then a packet sent from the client to the server is considered negative.
[0021] The traffic characteristics obtained in the embodiments of this specification include at least the source port of the data packet, the size of the data packet, and the timestamp of the data packet. The timestamp of the data packet includes the sending timestamp and the receiving timestamp.
[0022] S103, determine the notification data packet and the submission data packet from the encrypted communication traffic based on the traffic characteristics; In one embodiment, the notification data packet refers to the data packet used for mining tasks issued by the mining pool, and the submission data packet refers to the data packet in which the miner submits the result for the mining task, reflecting the interaction process between the mining machine set and the mining pool.
[0023] Please see Figure 4This diagram illustrates the communication process of a mining machine quantity identification method provided in this embodiment. The Stratum protocol is currently the most commonly used mining communication protocol, especially widely used between mining pools and miners of mainstream cryptocurrencies such as Bitcoin, Ethereum, and Monero. Taking the Stratum protocol as an example, the communication process between miners (mining machines) and mining pools generally includes the following steps: First, the miner establishes a connection with the mining pool and obtains subscription information through a `mining.subscribe` request. Next, the miner uses the `mining.authorize` directive to provide authentication information (such as username and password) to confirm their identity. Subsequently, the mining pool sets the mining difficulty through `mining.set_difficulty` and issues specific mining tasks through `mining.notify`. The miner begins calculating the hash value of the block header based on these tasks. When the miner finds a valid hash that meets the conditions, they submit the calculation result to the mining pool through `mining.submit`. Finally, the mining pool verifies the submitted result. If valid, it broadcasts the new block to the Bitcoin network and distributes the corresponding reward to the miner. This process ensures efficient and secure allocation of mining tasks and verification of results between mining pools and miners. `mining.set_difficulty` is typically used initially after connection establishment (immediately after authorization): the mining pool sets a base difficulty to inform miners of the subsequent task criteria. Once the connection is established and the difficulty is set, the main interactions between miners and the mining pool are primarily `mining.submit` (submitting data packets) and `mining.notify` (notifying data packets). Therefore, it's difficult to verify other data packets (such as `mining.set_difficulty`) using periodic characteristics. However, within the same mining pool, the period and size of `mining.notify` data packets are relatively constant. Therefore, the size and period of these data packets can be used to identify notification data packets.
[0024] In one feasible implementation, the size of the data packet determines whether it is a notification packet (or a submission packet). Notification packets typically have a larger and relatively stable size (usually between 900 and 1200 bytes). Furthermore, the sizes of notification and submission packets are significantly different. Submission packets contain data such as the allocation task number, block hash, transaction ID list, block version number, current time, and notification method. Therefore, the size of the resulting data packet is also relatively stable. By statistically identifying the sizes of submission and notification packets, filtering between them can be achieved.
[0025] Optionally, before determining the size of the data packets, data packets sent from the mining pool to the mining rig set can be filtered by transmission direction, and then notification data packets can be filtered by packet size. Similarly, data packets received from the mining rig set to the mining pool can be filtered by transmission direction, and then submission data packets can be filtered by packet size, reducing the number of data packets to be compared and improving filtering efficiency.
[0026] In another feasible implementation, the regularity of the packet transmission and reception frequency determines whether a packet is a notification packet or a submission packet. The packet transmission and reception frequency can include the submission frequency of submission packets and the reception frequency of receiving packets. The submission frequency refers to how frequently a miner sends submission packets, which is usually related to the miner's computing power. Therefore, the submission frequency (submission interval) of each miner is typically consistent. If the submission frequency of some packets is consistent based on the packet timestamps, then these packets can be identified as submission packets. Although the frequency of mining pool task releases is affected by network fluctuations, block generation difficulty, and mining pool strategies, notification packets usually exhibit a relatively stable periodicity within a certain range. Therefore, if the reception frequency of some packets is consistent (periodic) based on the packet timestamps, then these packets can be identified as notification packets.
[0027] S104, Based on the timestamp of the notification data packet and the timestamp of the submission data packet, determine the active time of each source port within a set time range; In one embodiment, for each source port, it is checked whether it continuously receives notification data packets and continuously submits submission data packets within a reasonable time range to determine the active time of the source port. The active time refers to the period from the start of activity to the end of activity. It can be understood that the "active" source port defined in the embodiments of this specification means that the source port is performing mining tasks normally, which inevitably involves interaction with the mining pool, that is, receiving notification data packets and returning the corresponding submission data packets.
[0028] Specifically, each notification data packet and submission data packet corresponds to a source port. First, the notification data packets and submission data packets corresponding to each source port are obtained. Then, based on the timestamps of the notification data packets and submission data packets, the active time of the source port within a set time range is determined. The set time range is a preset detection period that can be set according to actual needs and is not specifically limited. For example, a one-day period or a ten-hour period can be used as the set time range.
[0029] S105, determine the number of mining machines performing mining in the mining machine set based on the active time.
[0030] In one embodiment, since this specification primarily focuses on the mining behavior of large-scale mining farms, which typically operate for extended periods (e.g., every 24 hours), mining machines generally continuously submit and notify data packets. Therefore, the active time of a normally functioning source port should be close to or the same as the set time range. If a source port is determined to be functioning normally based on its active time, then each normally functioning source port corresponds to one mining machine. If the active time is significantly less than the set time range, it may be due to a disconnection between the mining machine and the mining pool. When the mining machine reconnects to the pool, it will be assigned a new source port, resulting in multiple source ports corresponding to the same mining machine. Therefore, the active time can be used to filter out suspected duplicate source ports, and then the number of mining machines corresponding to these source ports can be further determined, thereby improving the accuracy of mining machine identification.
[0031] For example, if the time range is set to 0:00-24:00 every day, the active time of source port 1 is 0:00-24:00, the active time of source port 2 is 0:00-4:00, the active time of source port 3 is 4:10-24:00, and the active time of source port 4 is 0:00-24:00. Then source port 1 and source port 2 must correspond to two different mining machines. Source port 2 and source port 3 may correspond to the same mining machine or different mining machines. This can be identified by the time interval (preset value) between the active times of the source ports. Since the time interval between the active times of source port 2 and source port 3 is very small, it may be caused by the same mining machine briefly restarting. When calculating the number of mining machines, source port 2 and source port 3 correspond to one mining machine.
[0032] In this embodiment, by acquiring the encrypted communication traffic between the mining rig set and the mining pool, and obtaining the traffic characteristics of the data packets in the encrypted communication traffic, notification data packets and submission data packets are filtered out from the encrypted communication traffic based on the traffic characteristics. The notification data packets and submission data packets reflect the interaction between the mining rig set and the mining pool. Therefore, by using the timestamps of the notification data packets and submission data packets, the active time of interaction between each source port corresponding to the mining rig set and the mining pool can be determined within a set time range. Each mining rig typically communicates with the mining pool through different ports, and monitoring the active duration of each port helps to estimate the number of mining rigs. Using this method, without relying on decrypted traffic, the metadata characteristics (traffic characteristics) of the traffic can effectively distinguish different mining rigs in the mining rig set, improving the accuracy of mining rig number identification.
[0033] Please see Figure 5 This is a flowchart illustrating a method for identifying the number of cryptocurrency mining machines provided in an embodiment of this application. Figure 5 As shown, the method described in this application embodiment may include the following steps S201-S204.
[0034] S201, the source port whose active time is greater than the active time threshold is determined as the first port, and the source port whose active time is less than or equal to the active time threshold is determined as the second port; In one embodiment, source ports are classified according to their active time. Specifically, when the active time of a source port exceeds a preset active time threshold, the source port is classified as a first port; and when the active time of a source port does not exceed the active time threshold, the source port is classified as a second port. The active time threshold is determined based on a set time range, for example, if the set time range is 0:00-24:00, the active time threshold can be 23 hours, which can be adjusted according to the communication characteristics between different mining pools and miners. It is understood that when the active time is less than or equal to the active time threshold, the source port is an abnormal port, which may have stopped after running for a period of time, or stopped and reconnected after running for a period of time. These second ports are filtered out for further analysis.
[0035] S202, Based on the timestamp of the submitted data packet corresponding to each second port, determine the average submission time interval of each second port; In one embodiment, based on the timestamp of the submitted data packets for each second port, the interval between the submission times of the submitted data packets corresponding to each second port is calculated and determined, and the average value is calculated. This step aims to evaluate the communication patterns of each port by statistically analyzing the submission time intervals.
[0036] It should be noted that after identifying the second port, the active time interval can be calculated for the second ports with non-overlapping active times. For example, in the embodiment described above, the active time interval between source port 2 (0:00-4:00) and source port 3 (4:10-24:00) is 2 minutes, which may indicate that they belong to the same miner. However, judging whether they belong to the same miner based on the active time interval may be inaccurate. For example, some miners may be shut down for a long time before reconnecting, which could lead to misjudgment. To improve accuracy, the average submission time interval of data packets submitted in the second port is used to determine whether they belong to the same miner. Since this method judges based on the inherent computing power characteristics of each miner, it has higher accuracy, especially when multiple miners share an IP address, it can still accurately estimate the number of miners.
[0037] S203, determine the set of duplicate ports in the second port based on the average submission time interval; In one embodiment, based on the average submission time interval of the second port, a set of duplicate ports meeting specific conditions is further identified. This set includes ports whose submission time intervals tend to be consistent or fluctuate within a certain threshold range; these ports are considered duplicate ports belonging to the same miner. It is understood that since the computing power of the same miner typically does not change, and the computing power of different miners may differ, the average time interval can be used to determine whether the submission cycles of different source ports are similar, thus identifying a set of ports that may belong to the same miner in the second port set; this set is called a duplicate port set. The number of duplicate port sets may be one or more. It is understood that duplicate port sets may also not exist. For example, if all the submission time intervals of the second ports are different, then each second port corresponds to one miner. However, this solution primarily focuses on situations where the same miner disconnects and reconnects, thereby improving the accuracy of miner number identification in such cases.
[0038] S204, the sum of the number of the first ports, the number of the duplicate port set, and the number of the third ports is determined as the number of mining machines performing mining in the mining machine set; the third port is the port other than the duplicate port set in the second ports.
[0039] In one embodiment, the number of mining machines is determined as follows: first, the number of first ports is calculated; second, the number of duplicate port sets is calculated; and finally, the number of third ports is added. The third port refers to all ports in the second port set except those categorized as duplicate ports. Ultimately, the sum of all these quantities represents the number of mining machines performing mining operations in the mining machine set. It is possible that the third port does not exist, meaning that all second ports are categorized into duplicate port sets.
[0040] For example, setting the time range to 0:00-24:00 daily, the active time for source port 1 is 0:00-24:00, the active time for source port 2 is 0:00-4:00, the active time for source port 3 is 4:10-24:00, the active time for source port 4 is 0:00-24:00, and the active time for port 5 is 0:00-8:00. With an active time threshold of 24 hours, the first ports are source port 1 and source port 4, and the second ports are source port 2, source port 3, and source port 5. Further analysis of the average submission time intervals for source ports 2, 3, and 5 reveals that only source ports 2 and 3 have the same average submission time interval. Therefore, source ports 2 and 3 are grouped into a duplicate port set, resulting in a final number of miners: 2 + 1 + 1 = 4.
[0041] This specification provides a method for determining the number of mining machines based on port activity time and data packet submission time interval. First, source ports are classified according to an activity time threshold. Ports with activity times greater than the threshold are identified as first ports, while ports with activity times less than or equal to the threshold are identified as second ports. Then, based on the timestamps of data packets submitted by the second ports, the average submission time interval for each port is calculated. Further, a set of duplicate ports meeting specific conditions is identified; this set contains ports with similar submission time intervals. Finally, the number of mining machines is determined by adding the numbers of the first ports, the set of duplicate ports, and the number of third ports, where the third ports refer to other ports not belonging to the second ports in the set of duplicate ports. This method can accurately determine the number of mining machines performing mining operations, improving system efficiency and reliability.
[0042] Please see Figure 6 This is a flowchart illustrating a method for identifying the number of cryptocurrency mining machines provided in an embodiment of this application. Figure 6 As shown, the method described in this application embodiment may include the following steps S301-S302.
[0043] S301, Obtain the fifth port among the second ports whose active time does not overlap with that of the fourth port; the fourth port is any one of the second ports; In one embodiment, after determining the average submission time interval of each second port based on the timestamp of the submitted data packets corresponding to each second port, any one of the second ports is identified as the fourth port. Next, all ports whose active times do not overlap with the fourth port are selected from the second ports and designated as the fifth port. The purpose of this operation is to find ports that may be affected by restarts or other actions; the active times of these ports definitely do not overlap with the active time of the fourth port, while those whose active times overlap with the fourth port are definitely executed by another miner. This ensures that the active times of the compared ports do not overlap, improving the accuracy of the analysis.
[0044] S302, the fifth port whose difference from the average submission time interval of the fourth port is less than the difference threshold is determined as the repeating port of the fourth port, and the fourth port and the repeating ports are clustered to obtain the repeating port set.
[0045] In one embodiment, after obtaining fifth ports whose active times do not overlap with those of the fourth port, the average submission time interval of each fifth port is calculated and compared with the average submission time interval of the fourth port. If the difference between the average submission time interval of the fifth port and that of the fourth port is less than a preset difference threshold, the two ports can be considered to have a high degree of similarity in mining behavior, and thus the fifth port is classified as a duplicate port of the fourth port. By performing the same judgment and screening on all fifth ports that meet the conditions, the fourth port and its identified duplicate ports are clustered to obtain a set of duplicate ports. This set includes all ports whose average submission time interval is similar to that of the fourth port and whose active times do not overlap. This set represents ports that may belong to the same mining machine. The difference threshold can be determined according to the actual situation and is not specifically limited.
[0046] It is understood that the above description illustrates the clustering operation for any one of the second ports. Therefore, each port in the second port group can be detected in the same manner. Specifically, when determining the fourth port, the second port with the earliest active time can be prioritized, and it can be determined whether a later active port belongs to the same mining machine as the earlier active port. In a feasible implementation, to reduce the complexity of the determination, after clustering the fifth port with the fourth port, when obtaining the fifth port for the next fourth port, those duplicate ports that have already been clustered can be omitted.
[0047] For example, the second port includes source port 1 (active time 0:00-8:00), source port 2 (active time 0:00-8:00), source port 3 (active time 10:00-24:00), and source port 4 (active time 12:00-24:00). Assuming source port 1 is selected as the fourth port, and the active times of source port 2 and source port 1 overlap, they are not compared. The corresponding fifth ports are source port 3 and source port 4. The submission time intervals of source port 1, source port 3, and source port 4 are compared respectively. If the difference between the submission time of source port 3 and the submission time interval of source port 1 is less than a difference threshold, then source port 3 is a duplicate port, forming a duplicate port set together with source port 1. Then, source port 2 is determined as the fourth port, and the obtained fifth port is source port 4. If the difference between the submission time of source port 4 and the submission time interval of source port 2 is greater than or equal to a difference threshold, then they do not correspond to the same miner.
[0048] In this embodiment, by obtaining a fifth port from the second port whose active time does not overlap with that of the fourth port, and identifying the fifth port whose difference from the average submission time interval of the fourth port is less than a difference threshold, the fourth port and the duplicate ports are clustered to obtain a set of duplicate ports. Considering that the active times of the same miner's ports may not overlap during restarts or other special circumstances, it is necessary to filter out ports with non-overlapping active times to ensure more accurate comparison of submission time intervals.
[0049] Please see Figure 7 This is a flowchart illustrating a method for identifying the number of cryptocurrency mining machines provided in an embodiment of this application. Figure 7 As shown, the method described in this application embodiment may include the following steps S401-S403.
[0050] S401, based on the timestamp of the notification data packet and the timestamp of the submission data packet, determine the first detected submission data packet within a preset time range, and determine the timestamp of the notification data packet corresponding to the first detected submission data packet as the active start time of the source port; In one embodiment, for each source port, based on the timestamps of its corresponding notification data packet and submission data packet, the first detected submission data packet is identified within a preset time range. It is understood that a submission data packet must be sent to the mining pool based on a notification data packet; therefore, when the first submission data packet is detected, there must exist a corresponding notification data packet. The timestamp of this notification data packet is determined as the active start time of the source port. This time point marks the beginning of the source port's interaction with the mining pool, and thus is the starting point of the source port's active cycle.
[0051] S402, based on the timestamp of the notification data packet and the timestamp of the submission data packet, it is determined that the last interaction data packet was detected within a preset time range, and the timestamp corresponding to the interaction data packet is determined as the active end time of the source port; the interaction data packet is the notification data packet or the submission data packet; In one embodiment, within a preset time range, the last interaction data packet, i.e., the last notification data packet or submission data packet, is identified and determined. If the source port does not submit a corresponding submission data packet after receiving the notification data packet, it indicates that the interaction with the mining pool has ended. Similarly, if the source port does not receive any notification data packets from the miner after sending the submission data packet, it also indicates that the interaction with the mining pool has ended. The timestamp of this interaction data packet is regarded as the active end time of the source port. The active end time indicates the moment of the last interaction between the source port and the mining pool, marking the end of the source port's active period.
[0052] S403, determine the active time of the source port based on the active start time and the active end time.
[0053] In one embodiment, once the active start time and active end time of the source port are determined, the active time of the source port can be obtained by calculating the time difference between the two. Specifically, the active time of the source port is the active end time minus the active start time, reflecting the duration of continuous activity of the port within a set time range.
[0054] In this embodiment of the application, the timestamps of the notification data packet and the submission data packet are used in combination with a set time range to accurately calculate the active time of each source port, providing accurate time data for subsequent analysis and processing.
[0055] Please see Figure 8 This is a flowchart illustrating a method for identifying the number of cryptocurrency mining machines provided in an embodiment of this application. Figure 8 As shown, the method described in this application embodiment may include the following steps S501-S502.
[0056] S501, based on the size of the data packet, filter out the notification data packets that match the first byte count feature; In one embodiment, the first byte count feature characterizes the typical size of the notification data packet, such as 900 to 1200 bytes. By comparing the size of each data packet in the encrypted communication traffic with the first byte count feature, notification data packets matching the first byte count feature can be determined. Matching the first byte count feature means that the difference between the data packet size (evaluated in bytes) and the first byte count feature is less than a set threshold.
[0057] S502, based on the size of the data packet, select the submitted data packets that match the second byte count feature.
[0058] Similarly, the second byte count feature characterizes the typical size of submitted data packets. By calculating the size of each data packet (in bytes) and comparing it with the second byte count feature, submitted data packets that meet this feature are selected. The first and second byte count features are usually derived through statistical analysis of historical data packets.
[0059] Optionally, as actual traffic changes, the size range of notification and submission data packets needs to be adjusted in real time; that is, the first and second byte count characteristics can be dynamically adjusted. Based on real-time feedback from traffic analysis, the data packet size range is dynamically adjusted to adapt to different mining pool task deployment strategies and network environments. For example, an initial first byte count characteristic, such as 900 to 1200 bytes, can be preset to filter encrypted communication traffic. If data packets within this range cannot be filtered out, the initial first byte count characteristic can be adjusted, for example, to 600 to 900 bytes or 1200 to 1500 bytes, to try and obtain data packets. If data packets can be obtained after the modified range, the periodicity of these data packets is further verified. The timestamp is used to determine whether the reception of these data packets is periodic and whether they appear in pairs with submission data packets. If so, this new range (first byte count characteristic) is used as a benchmark to identify the number of mining machines in the current mining pool and mining machine set. Optionally, if so, determine the average size of these submitted data packets, and adjust the range based on this average. For example, if the range is adjusted to 1200-1500, and a batch of submitted data packets has been identified with an average byte count of 1400 bytes, the first byte count characteristic can be adjusted to 1300-1500 bytes. Similarly, the second byte count characteristic of the submitted data packets can also be adjusted in this way to improve the versatility and adaptability of the filtering method.
[0060] Further, in one embodiment, the traffic characteristics include the transmission direction of the data packets, and filtering out notification data packets that match the first byte count characteristic based on the size of the data packets includes the following steps S5011-S5012: S5011, filter data packets whose transmission direction is from the mining pool to the mining machine set; In one embodiment, initial filtering is performed based on the transmission direction of data packets. Since different transmission directions represent different communication roles and functions, filtering out data packets with a transmission direction of "from the mining pool to the mining rig set" can significantly reduce the number of irrelevant data packets, thereby improving subsequent filtering efficiency. The transmission direction is determined by the source and destination addresses specified in the network protocol (mining protocol), where the source address is the mining pool and the destination address is the mining rig set.
[0061] S5011, filter out notification data packets whose size matches the first byte count feature from the sent data packets; In one embodiment, notification data packets that meet the first byte size characteristic are further filtered from the data packets transmitted in the direction of "mining pool to mining machine set". By filtering the size of the data packets, the number of mismatched candidate data packets is further reduced, thereby improving the accuracy and efficiency of the filtering.
[0062] The step of filtering submitted data packets that match the second byte count feature based on the size of the data packet includes: S5021, filter the received data packets whose transmission direction is from the mining machine set to the mining pool; In one embodiment, the mining rig ensemble typically sends a submission data packet to the mining pool, similar to step S5011, in which the receiving data packet "sent by the mining rig ensemble to the mining pool" is selected based on the transmission direction of the data packet.
[0063] S5022, Select the submitted data packets whose size matches the second byte count feature from the received data packets.
[0064] In one embodiment, packets that meet the second byte count characteristic are selected from the received data packets of “miner set sent to mining pool” as submission data packets.
[0065] By first filtering communication data packets between the mining pool and the mining rig ensemble based on the transmission direction, and then further filtering notification and submission data packets based on byte count characteristics, the number of data packets requiring comparison can be significantly reduced, improving matching efficiency. This method helps to more efficiently filter notification and submission data packets matching specific byte count characteristics from a large amount of encrypted communication traffic, thereby improving system performance and data processing efficiency.
[0066] Furthermore, in one embodiment, filtering notification data packets that match the first byte count feature based on the size of the data packet includes the following steps: S601, based on the size of the data packet, select the first data packet that matches the first byte count feature; In one embodiment, a first data packet whose size matches a first byte count feature is selected from the data packet stream. This helps to locate candidate data packets that may be related to the notification data packet based on the data packet size feature.
[0067] S602, based on the timestamp of the first data packet, determine the first time interval between adjacent first data packets; In one embodiment, the timestamps of adjacent first data packets are analyzed to determine the time interval between them. This time interval helps verify the periodicity of the data packets. Specifically, each data packet has a timestamp recording its transmission time (e.g., a reception timestamp indicating the time the miner received it). At this stage, timestamps are extracted from the selected first data packets, and the time difference between adjacent first data packets, i.e., the first time interval, is calculated. By analyzing the time intervals of multiple data packets, it can be identified whether the data packet is sent within a relatively stable time interval. If the time intervals between some data packets are relatively uniform, this indicates that they may belong to the same type of periodic data packets.
[0068] S603, the first data packet whose difference in the first time interval is less than the first difference threshold is determined as a notification data packet.
[0069] In one embodiment, the time interval difference between any two adjacent first data packets is calculated. If the difference between these time intervals is less than a preset threshold (first difference threshold), then these data packets can be considered to have a stable periodicity, conforming to the characteristics of notification data packets.
[0070] For example, data packet 1: timestamp 10:00:00, data packet 2: timestamp 10:00:05, data packet 3: timestamp 10:00:10, data packet 4: timestamp 10:00:15, data packet 5: timestamp 10:00:30. The time interval between data packets 1 and 2 is 10:00:05 - 10:00:00 = 5 seconds; the time interval between data packets 2 and 3 is 10:00:10 - 10:00:05 = 5 seconds; the time interval between data packets 3 and 4 is 10:00:15 - 10:00:10 = 5 seconds; the time interval between data packets 4 and 5 is 10:00:35 - 10:00:15 = 20 seconds. First data packet 1 to first data packet 2 and first data packet 2 to first data packet 3: 5 seconds - 5 seconds = 0 seconds (difference less than 1 second); First data packet 2 to first data packet 3 and first data packet 3 to data packet 4: 5 seconds - 5 seconds = 0 seconds (difference less than 1 second); Data packet 3 to 4 and data packet 4 to 5: 5 seconds - 20 seconds = -15 seconds (absolute value of difference greater than 1 second). The time intervals between adjacent data packets in the first data packets 1 through 4 are all less than 1 second, and the time intervals are stable (all 5 seconds), conforming to periodic characteristics. Therefore, these data packets are considered to meet the characteristics of notification data packets. First data packet 5 is not a notification data packet.
[0071] After initial screening based on packet size, further analysis of the time intervals between adjacent packets can identify notification packets exhibiting periodic characteristics. Although the frequency of mining pool task releases is affected by various factors (such as network fluctuations and mining pool strategies), notification packets typically display a stable periodicity. Therefore, comparing time intervals can improve the accuracy of notification packet filtering.
[0072] Further, in one embodiment, filtering submitted data packets that match the second byte count feature based on the size of the data packet includes the following steps S701-S703: S701, based on the size of the data packet, select a second data packet that matches the second byte count feature; In one embodiment, it is necessary to filter out second data packets that meet the size range (e.g., the second byte count characteristic is between 200 and 500 bytes). This filtering condition is a preliminary screening to ensure that the data packets meet the expected size requirements and to avoid processing irrelevant packets.
[0073] S702, based on the timestamp of the second data packet, determine the second time interval between adjacent second data packets; In one embodiment, the time interval between adjacent second data packets is analyzed based on timestamps.
[0074] S703, the second data packet whose second time interval difference is less than the second difference threshold is determined as the submission data packet.
[0075] In one embodiment, the time interval between data packets submitted by the miner should be stable. Therefore, a threshold is set to determine whether the time interval difference between adjacent data packets conforms to normal periodicity. By setting a second difference threshold, data packets with excessively large time interval differences can be filtered out, avoiding misjudgment of packets that do not meet the periodic submission requirements. If the time interval difference between adjacent data packets is less than the second difference threshold, the periodicity characteristic of the data packet is considered to be consistent with expectations, and it may be a submission data packet. The specific analysis method is similar to that of notification data packets, and will not be elaborated here.
[0076] In this embodiment, notification and submission data packets are filtered using traffic characteristics. Whether a data packet is a notification or submission packet is determined based on one or more traffic characteristics (data packet size and / or transmission direction). This dual verification of data packet size and periodicity improves the efficiency and accuracy of the determination process.
[0077] The following will be combined with the appendix Figure 9 This application provides a detailed description of the mining machine quantity identification device provided in its embodiments. It should be noted that the appendix... Figure 9The mining machine quantity identification device in this manual is used to execute the functions described in this manual. Figures 2-8 The methods shown in the embodiments are illustrated for ease of explanation, showing only the parts relevant to the embodiments of this application. For specific technical details not disclosed, please refer to this specification. Figures 2-8 The example shown.
[0078] Please see Figure 9 This illustration shows a schematic diagram of a mining machine quantity identification device provided in an exemplary embodiment of this application. The mining machine quantity identification device can be implemented as all or part of a device through software, hardware, or a combination of both. The device 1 includes a traffic acquisition unit 11, a feature acquisition unit 12, a data packet filtering unit 13, an activity detection unit 14, and a quantity determination unit 15.
[0079] Traffic acquisition unit 11 is used to acquire encrypted communication traffic between the mining machine cluster and the mining pool; The feature acquisition unit 12 is used to acquire the traffic features of data packets in the encrypted communication traffic; the traffic features include at least the source port of the data packet, the size of the data packet, and the timestamp of the data packet; The data packet filtering unit 13 is used to determine notification data packets and submission data packets from the encrypted communication traffic based on the traffic characteristics; The activity detection unit 14 is used to determine the active time of each source port within a set time range based on the timestamp of the notification data packet and the timestamp of the submission data packet; The quantity determination unit 15 is used to determine the number of mining machines performing mining in the mining machine set based on the active time.
[0080] Optionally, the quantity determination unit 15 is specifically used to determine the source port whose active time is greater than the active time threshold as the first port, and to determine the source port whose active time is less than or equal to the active time threshold as the second port; Based on the timestamp of the submitted data packet corresponding to each second port, the average submission time interval of each second port is determined; The set of duplicate ports in the second port is determined based on the average submission time interval; The sum of the number of the first port, the number of the duplicate port set, and the number of the third port is determined as the number of mining machines performing mining in the mining machine set; the third port is the port other than the duplicate port set in the second port set.
[0081] Optionally, the quantity determination unit 15 is specifically used to obtain a fifth port among the second ports whose active time does not overlap with that of the fourth port; the fourth port is any one of the second ports; The fifth port whose difference from the average submission time interval of the fourth port is less than the difference threshold is identified as the repeating port of the fourth port, and the fourth port and the repeating ports are clustered to obtain the repeating port set.
[0082] Optionally, the active detection unit 14 is specifically used to determine the first detected submission data packet within a preset time range based on the timestamp of the notification data packet and the timestamp of the submission data packet, and to determine the timestamp of the notification data packet corresponding to the first detected submission data packet as the active start time of the source port. Based on the timestamp of the notification data packet and the timestamp of the submission data packet, it is determined that the last interaction data packet was detected within a preset time range, and the timestamp corresponding to the interaction data packet is determined as the active end time of the source port; the interaction data packet is either the notification data packet or the submission data packet. The active time of the source port is determined based on the active start time and the active end time.
[0083] Optionally, the data packet filtering unit 13 is specifically used to filter out notification data packets that match the first byte count feature based on the size of the data packet; Submitted data packets that match the second byte count feature are selected based on the size of the data packet.
[0084] Optionally, the data packet filtering unit 13 is specifically used to filter out a first data packet that matches the first byte count feature based on the size of the data packet; Based on the timestamp of the first data packet, a first time interval between adjacent first data packets is determined; The first data packet whose difference in the first time interval is less than the first difference threshold is identified as a notification data packet.
[0085] Optionally, the traffic characteristics include the transmission direction of the data packets, and the data packet filtering unit 13 is specifically used to filter data packets whose transmission direction is from the mining pool to the mining machine set; Filter out notification data packets whose size matches the first byte count feature from the sent data packets; The data packets being filtered are those sent from the mining machine cluster to the mining pool. Submitted data packets whose size matches the second byte count feature are selected from the received data packets.
[0086] Optionally, the data packet filtering unit 13 is specifically used to filter out a second data packet that matches the second byte count feature based on the size of the data packet; Based on the timestamp of the second data packet, a second time interval between adjacent second data packets is determined; The second data packet whose second time interval difference is less than the second difference threshold is identified as the submitted data packet.
[0087] It should be noted that the virtual currency mining machine quantity identification device provided in the above embodiments is only illustrated by the division of the above functional modules when executing the virtual currency mining machine quantity identification method. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the virtual currency mining machine quantity identification device and the virtual currency mining machine quantity identification method embodiments provided in the above embodiments belong to the same concept, and the implementation process is detailed in the method embodiments, which will not be repeated here.
[0088] The sequence numbers of the embodiments described above are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments. In some cases, the actions or steps described in the claims can be performed in a different order than that shown in the embodiments and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0089] This application embodiment also provides a storage medium storing a computer program, which, when executed by a processor, implements the above-described functionality. Figures 2-8 The method described in the illustrated embodiment can be found in the following document for a detailed execution process. Figures 2-8 The specific details of the illustrated embodiments will not be elaborated here.
[0090] Please refer to Figure 10 This diagram illustrates the structure of an electronic device provided in an exemplary embodiment of this specification. The electronic device in this specification may include one or more components such as a processor 110, a memory 120, an input device 130, an output device 140, and a bus 150. The processor 110, memory 120, input device 130, and output device 140 may be connected via the bus 150.
[0091] Processor 110 may include one or more processing cores. Processor 110 connects to various parts of the electronic device using various interfaces and lines, and performs various functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in memory 120, and by calling data stored in memory 120. Optionally, processor 110 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). Processor 110 may integrate one or more of a Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem. The CPU primarily handles the operating system, user page, and applications; the GPU is responsible for rendering and drawing the displayed content; and the modem handles wireless communication. It is understood that the modem may also not be integrated into processor 110 and may be implemented separately using a communication chip.
[0092] The memory 120 may include random access memory (RAM) or read-only memory (ROM). Optionally, the memory 120 may include non-transitory computer-readable storage medium. The memory 120 may be used to store instructions, programs, code, code sets, or instruction sets. The memory 120 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the various method embodiments described above, etc. The operating system may be the Android system, including systems deeply developed based on the Android system, the iOS system developed by Apple Inc., including systems deeply developed based on the iOS system, or other systems.
[0093] The memory 120 can be divided into operating system space and user space. The operating system runs in the operating system space, while native and third-party applications run in user space. To ensure that different third-party applications can achieve good running performance, the operating system allocates corresponding system resources for each application. However, different application scenarios within the same third-party application have different requirements for system resources. For example, in local resource loading scenarios, third-party applications have high requirements for disk read speed; in animation rendering scenarios, third-party applications have high requirements for GPU performance. Since the operating system and third-party applications are independent of each other, the operating system often cannot promptly perceive the current application scenario of a third-party application, resulting in the operating system's inability to adapt system resources accordingly.
[0094] In order for the operating system to distinguish the specific application scenarios of third-party applications, it is necessary to establish data communication between the third-party applications and the operating system. This would allow the operating system to obtain the current scenario information of the third-party applications at any time, and then perform targeted system resource adaptation based on the current scenario.
[0095] The input device 130 is used to receive input instructions or data, and includes, but is not limited to, a keyboard, mouse, camera, microphone, or touch device. The output device 140 is used to output instructions or data, and includes, but is not limited to, a display device and a speaker. In one example, the input device 130 and the output device 140 can be combined, and the input device 130 and the output device 140 can be a touch display screen.
[0096] The touch display screen can be designed as a full-screen, curved screen, or irregularly shaped screen. It can also be designed as a combination of a full-screen and a curved screen, or a combination of an irregularly shaped screen and a curved screen; however, this application does not limit the specific design in this regard.
[0097] In addition, those skilled in the art will understand that the structure of the electronic device shown in the above figures does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown, or combine certain components, or have different component arrangements. For example, the electronic device may also include radio frequency circuits, input units, sensors, audio circuits, WiFi modules, power supplies, Bluetooth modules, etc., which will not be described in detail here.
[0098] exist Figure 10 In the illustrated electronic device, the processor 110 can be used to call a computer program stored in the memory 120 and specifically perform the following operations: Acquire encrypted communication traffic between the mining rig cluster and the mining pool; Obtain the traffic characteristics of data packets in the encrypted communication traffic; the traffic characteristics include at least the source port of the data packet, the size of the data packet, and the timestamp of the data packet; Based on the traffic characteristics, notification data packets and submission data packets are determined from the encrypted communication traffic; Based on the timestamp of the notification data packet and the timestamp of the submission data packet, the active time of each source port within a set time range is determined; The number of mining machines performing mining in the mining machine set is determined based on the active time.
[0099] In one embodiment, when the processor 110 determines the number of mining machines performing mining in the mining machine set based on the active time, it specifically performs the following operations: The source port whose active time is greater than the active time threshold is determined as the first port, and the source port whose active time is less than or equal to the active time threshold is determined as the second port; Based on the timestamp of the submitted data packet corresponding to each second port, the average submission time interval of each second port is determined; The set of duplicate ports in the second port is determined based on the average submission time interval; The sum of the number of the first port, the number of the duplicate port set, and the number of the third port is determined as the number of mining machines performing mining in the mining machine set; the third port is the port other than the duplicate port set in the second port set.
[0100] In one embodiment, when the processor 110 performs the operation of determining the set of duplicate ports in the second port based on the average submission time interval, it specifically performs the following operations: Obtain the fifth port from the second ports whose active time does not overlap with that of the fourth port; the fourth port is any one of the second ports. The fifth port whose difference from the average submission time interval of the fourth port is less than the difference threshold is identified as the repeating port of the fourth port, and the fourth port and the repeating ports are clustered to obtain the repeating port set.
[0101] In one embodiment, when the processor 110 determines the active time of each source port within a set time range based on the timestamp of the notification data packet and the timestamp of the submission data packet, it specifically performs the following operations: Based on the timestamp of the notification data packet and the timestamp of the submission data packet, the first detected submission data packet within a preset time range is determined, and the timestamp of the notification data packet corresponding to the first detected submission data packet is determined as the active start time of the source port. Based on the timestamp of the notification data packet and the timestamp of the submission data packet, it is determined that the last interaction data packet was detected within a preset time range, and the timestamp corresponding to the interaction data packet is determined as the active end time of the source port; the interaction data packet is either the notification data packet or the submission data packet. The active time of the source port is determined based on the active start time and the active end time.
[0102] In one embodiment, when the processor 110 determines the notification data packet and the submission data packet from the encrypted communication traffic based on the traffic characteristics, it specifically performs the following operations: Based on the size of the data packet, notification data packets matching the first byte count feature are selected; Submitted data packets that match the second byte count feature are selected based on the size of the data packet.
[0103] In one embodiment, when the processor 110 executes the operation of filtering out notification data packets that match the first byte count feature based on the size of the data packet, it specifically performs the following operations: Based on the size of the data packet, a first data packet matching the first byte count feature is selected; Based on the timestamp of the first data packet, a first time interval between adjacent first data packets is determined; The first data packet whose difference in the first time interval is less than the first difference threshold is identified as a notification data packet.
[0104] In one embodiment, the traffic characteristics include the transmission direction of the data packets; when the processor 110 executes the operation of filtering out notification data packets that match the first byte count characteristic based on the size of the data packets, it specifically performs the following operations: Filter data packets whose transmission direction is from the mining pool to the mining machine set; Filter out notification data packets whose size matches the first byte count feature from the sent data packets; When the processor 110 executes the operation of filtering submitted data packets that match the second byte count feature based on the size of the data packet, it specifically performs the following operations: The data packets being filtered are those sent from the mining machine cluster to the mining pool. Submitted data packets whose size matches the second byte count feature are selected from the received data packets.
[0105] In one embodiment, when the processor 110 executes the operation of filtering submitted data packets that match the second byte count feature based on the size of the data packet, it specifically performs the following operations: Based on the size of the data packet, a second data packet matching the second byte count feature is selected; Based on the timestamp of the second data packet, a second time interval between adjacent second data packets is determined; The second data packet whose second time interval difference is less than the second difference threshold is identified as the submitted data packet.
[0106] In this embodiment, by acquiring the encrypted communication traffic between the mining rig set and the mining pool, and obtaining the traffic characteristics of the data packets in the encrypted communication traffic, notification data packets and submission data packets are filtered out from the encrypted communication traffic based on the traffic characteristics. The notification data packets and submission data packets reflect the interaction between the mining rig set and the mining pool. Therefore, by using the timestamps of the notification data packets and submission data packets, the active time of interaction between each source port corresponding to the mining rig set and the mining pool can be determined within a set time range. Each mining rig typically communicates with the mining pool through different ports, and monitoring the active duration of each port helps to estimate the number of mining rigs. Using this method, without relying on decrypted traffic, the metadata characteristics (traffic characteristics) of the traffic can effectively distinguish different mining rigs in the mining rig set, improving the accuracy of mining rig number identification.
[0107] Furthermore, a method for determining the number of mining rigs based on port activity time and packet submission time interval is provided. First, source ports are classified according to an activity time threshold, with ports having an activity time greater than the threshold identified as first ports, and ports having an activity time less than or equal to the threshold identified as second ports. Then, based on the timestamps of packets submitted by the second ports, the average submission time interval for each port is calculated. Further, a set of duplicate ports meeting specific conditions is identified, containing ports with similar submission time intervals. Finally, the number of mining rigs is determined by adding the numbers of the first ports, the set of duplicate ports, and the third port, where the third port refers to any other port not belonging to the second port set within the set of duplicate ports. This method can accurately determine the number of mining rigs performing mining operations, improving system efficiency and reliability.
[0108] Furthermore, by identifying the fifth port from the second port whose active time does not overlap with that of the fourth port, and determining that the fifth port whose difference from the average submission time interval of the fourth port is less than a threshold, the fourth port and the duplicate ports are clustered to obtain a set of duplicate ports. Considering that the active times of the same miner's ports may not overlap during restarts or other special circumstances, it is necessary to filter out ports with non-overlapping active times to ensure more accurate comparison of submission time intervals.
[0109] Furthermore, by utilizing the timestamps of notification and submission data packets, combined with a set time range, the active time of each source port can be accurately calculated, providing precise time data for subsequent analysis and processing.
[0110] Furthermore, filtering of notification and submission data packets is achieved through traffic characteristics. Whether a data packet is a notification or submission packet is determined based on one (packet size) or multiple traffic characteristics (packet timestamp and / or transmission direction). This dual verification of packet size and periodicity improves the efficiency and accuracy of the determination process.
[0111] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc.
[0112] The above-disclosed embodiments are merely preferred embodiments of this specification and should not be construed as limiting the scope of this specification. Therefore, any equivalent variations made in accordance with the claims of this specification shall still fall within the scope of this specification.
Claims
1. A method for identifying the number of cryptocurrency mining machines, characterized in that, The method includes: Acquire encrypted communication traffic between the mining rig cluster and the mining pool; Obtain the traffic characteristics of data packets in the encrypted communication traffic; the traffic characteristics include at least the source port of the data packet, the size of the data packet, and the timestamp of the data packet; Based on the traffic characteristics, notification data packets and submission data packets are determined from the encrypted communication traffic; Based on the timestamp of the notification data packet and the timestamp of the submission data packet, the active time of each source port within a set time range is determined; The number of mining machines performing mining in the mining machine set is determined based on the active time.
2. The method as described in claim 1, characterized in that, Determining the number of mining machines performing mining in the mining machine set based on the active time includes: The source port whose active time is greater than the active time threshold is determined as the first port, and the source port whose active time is less than or equal to the active time threshold is determined as the second port; Based on the timestamp of the submitted data packet corresponding to each second port, the average submission time interval of each second port is determined; The set of duplicate ports in the second port is determined based on the average submission time interval; The sum of the number of the first port, the number of the duplicate port set, and the number of the third port is determined as the number of mining machines performing mining in the mining machine set; the third port is the port other than the duplicate port set in the second port set.
3. The method as described in claim 2, characterized in that, The step of determining the set of duplicate ports in the second port based on the average submission time interval includes: Obtain the fifth port from the second ports whose active time does not overlap with that of the fourth port; the fourth port is any one of the second ports. The fifth port whose difference from the average submission time interval of the fourth port is less than the difference threshold is identified as the repeating port of the fourth port, and the fourth port and the repeating ports are clustered to obtain the repeating port set.
4. The method as described in claim 1, characterized in that, The determination of the active time of each source port within a set time range based on the timestamp of the notification data packet and the timestamp of the submission data packet includes: Based on the timestamp of the notification data packet and the timestamp of the submission data packet, the first detected submission data packet within a preset time range is determined, and the timestamp of the notification data packet corresponding to the first detected submission data packet is determined as the active start time of the source port. Based on the timestamp of the notification data packet and the timestamp of the submission data packet, it is determined that the last interaction data packet was detected within a preset time range, and the timestamp corresponding to the interaction data packet is determined as the active end time of the source port; the interaction data packet is either the notification data packet or the submission data packet. The active time of the source port is determined based on the active start time and the active end time.
5. The method as described in claim 1, characterized in that, Determining the notification data packet and the submission data packet from the encrypted communication traffic based on the traffic characteristics includes: Based on the size of the data packet, notification data packets matching the first byte count feature are selected; Submitted data packets that match the second byte count feature are selected based on the size of the data packet.
6. The method as described in claim 5, characterized in that, The step of filtering out notification data packets that match the first byte count feature based on the size of the data packet includes: Based on the size of the data packet, a first data packet matching the first byte count feature is selected; Based on the timestamp of the first data packet, a first time interval between adjacent first data packets is determined; The first data packet whose difference in the first time interval is less than the first difference threshold is identified as a notification data packet.
7. The method as described in claim 5, characterized in that, The traffic characteristics include the transmission direction of the data packets; The step of filtering out notification data packets that match the first byte count feature based on the size of the data packet includes: Filter data packets whose transmission direction is from the mining pool to the mining machine set; Filter out notification data packets whose size matches the first byte count feature from the sent data packets; The step of filtering submitted data packets that match the second byte count feature based on the size of the data packet includes: The data packets being filtered are those sent from the mining machine cluster to the mining pool. Submitted data packets whose size matches the second byte count feature are selected from the received data packets.
8. The method as described in claim 5, characterized in that, The step of filtering submitted data packets that match the second byte count feature based on the size of the data packet includes: Based on the size of the data packet, a second data packet matching the second byte count feature is selected; Based on the timestamp of the second data packet, a second time interval between adjacent second data packets is determined; The second data packet whose second time interval difference is less than the second difference threshold is identified as the submitted data packet.
9. A device for identifying the number of virtual currency mining machines, characterized in that, The device includes: The traffic acquisition unit is used to acquire the encrypted communication traffic between the mining machine cluster and the mining pool; The feature acquisition unit is used to acquire the traffic features of data packets in the encrypted communication traffic; the traffic features include at least the source port of the data packet, the size of the data packet, and the timestamp of the data packet; A data packet filtering unit is used to determine notification data packets and submission data packets from the encrypted communication traffic based on the traffic characteristics; An activity detection unit is used to determine the active time of each source port within a set time range based on the timestamp of the notification data packet and the timestamp of the submission data packet; A quantity determination unit is used to determine the number of mining machines performing mining in the mining machine set based on the active time.
10. An electronic device, characterized in that, include: Processor and memory; The memory stores a computer program adapted to be loaded by the processor and to execute the steps of the method as described in any one of claims 1 to 8.
11. A storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 8.