Cryptocurrency Mining Detection via Network Traffic Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems fail to effectively detect and mitigate cryptocurrency mining malware infections on electronic devices, particularly in identifying malicious web-servers and Command and Control (C&C) servers that control distributed bot-nets, and do not perform adequate remedial actions.

Innovation Solution

A system that monitors network activity over a cellular communication network to detect cryptocurrency mining operations, identifies malicious servers, and performs corrective actions by analyzing packets and network traffic, utilizing network probes and big data analytics to detect and isolate infected devices and control servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional systems monitor network activity to detect malware, then detection capability is improved, but detection precision for cryptocurrency mining malware remains insufficient

Engineering Contradiction:
Improvedetection precisionVSAvoiddetection reliability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system segments the detection process into three distinct phases: (1) detecting infection communications between web-servers and end-user devices, (2) detecting activation communications between C&C servers and devices, and (3) detecting mining task communications between C&C servers and activated bots. This segmentation allows each phase to be analyzed with specialized indicators, improving overall detection precision while maintaining reliability through comprehensive coverage of the malware lifecycle.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary analysis of network traffic patterns to establish baseline behavior before malware infection occurs. By pre-configuring detection rules for known cryptocurrency mining protocols, C&C communication patterns, and malware distribution behaviors, the system prepares detection mechanisms in advance, enabling immediate and precise identification of suspicious activities without compromising reliability.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If the system analyzes all network packets to detect malicious activity, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system applies local quality by implementing different analysis depths for different types of network traffic. Critical traffic such as C&C communications and mining task submissions undergo deep packet inspection with high analysis intensity, while routine traffic receives lighter inspection. This differentiated approach maintains high detection accuracy for malicious activities while reducing overall system complexity and computational overhead.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system introduces intermediary components including protocol parsers, signature matchers, and behavior analyzers that act as mediators between raw network packets and the detection engine. These intermediaries pre-process and filter traffic, transforming complex packet data into structured information that is easier to analyze, thereby improving detection accuracy without proportionally increasing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the system performs comprehensive remedial actions against detected threats, then security effectiveness is improved, but network disruption increases

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidnetwork disruption
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The system implements partial remedial actions tailored to the specific threat level and type. For confirmed cryptocurrency mining malware, the system applies targeted blocking of malicious servers and rate-limiting of infected devices rather than complete network isolation. This partial action approach maintains security effectiveness by neutralizing threats while minimizing unnecessary network disruption to legitimate traffic.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system incorporates feedback mechanisms that continuously monitor the impact of remedial actions. When blocking or rate-limiting is applied, the system observes network traffic patterns to ensure malicious activity is suppressed while legitimate communications remain unaffected. This feedback loop allows dynamic adjustment of remedial measures, maintaining security effectiveness while minimizing harmful network disruption.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11089049B2System, device, and method of detecting cryptocurrency mining activity
Publication Date: 2021.08.10 ALLOT COMM LTD
  • US11089049B2 patent drawing
  • US11089049B2 patent drawing

AI summary

A system monitors network activity of an end-user device that communicates with servers over a communications network. The performs analysis of packets of data that are transported via the network. The system detects a first set of communications in which a first server infects the end-user device with a cryptocurrency mining malware; a second set of communications, in which a second server activates the end-user device as an activated cryptocurrency mining bot; and a third set of communications, in which the second server allocates a cryptocurrency mining task to the end-user device and later receives a cryptocurrency mining output from the end-user device. The system determines that the first server is a malicious infecting web-server; that the second server is a malicious Command and Control server of a distributed bot-net of cryptocurrency mining bots; and that the end-user device is an infected and activated and operational cryptocurrency mining bot.