Behavioral Rule-Based Cryptominer Detection System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing detection methods for unauthorized cryptomining are ineffective due to the rapid evolution of cryptominer malware and the difficulty in distinguishing between authorized and unauthorized cryptocurrency mining activities, as standard antivirus software relies on signature verification and blacklists, which are easily bypassed by the numerous variants of cryptominers.

Innovation Solution

A method and system that monitor processes on a computer system for suspicious behavior by comparing collected data against behavioral rules, generating alerts for non-compliant activity, and updating these rules based on telemetry data to improve detection accuracy, including the ability to identify and tag cryptominer intrusions and adjust parameters to capture common characteristics of cryptominer activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If standard antivirus software based on signature verification and blacklists is used, then detection of known malware is possible, but detection of rapidly evolving cryptominer variants becomes ineffective

Engineering Contradiction:
Improvedetection reliabilityVSAvoidadaptability to new cryptominer variants
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adjusts detection parameters and behavioral rules based on real-time telemetry data and machine learning models, allowing the detection mechanism to adapt to rapidly evolving cryptominer variants without relying on static signatures or blacklists

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system collects telemetry data from detected processes and uses this feedback to continuously improve the machine learning model and update behavioral rules, enabling progressive adaptation to new cryptominer techniques and variants

Inventive Principle:
Principle #23Feedback

2Measurement precision

If behavioral monitoring and machine learning are implemented, then detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the detection process into distinct modules: process monitoring, behavioral rule evaluation, anomaly detection, and machine learning model updates, making the complex system more manageable and maintainable while improving detection accuracy through specialized functionality

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If continuous monitoring and rule updates are performed, then detection accuracy improves, but computational resources are consumed

Engineering Contradiction:
Improvedetection accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system applies partial monitoring by focusing computational resources on specific behavioral parameters and processes that are most indicative of cryptominer activity, rather than continuously analyzing all system operations, thereby reducing overall computational consumption while maintaining detection accuracy

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11403389B2System and method of detecting unauthorized access to computing resources for cryptomining
Publication Date: 2022.08.02 ACRONIS INT
  • US11403389B2 patent drawing
  • US11403389B2 patent drawing
  • US11403389B2 patent drawing

AI summary

Disclosed herein are systems and method for detecting unauthorized access to computing resources for cryptomining. In one exemplary aspect, a method may detect that at least one process has been launched on a computer system. In response to the detecting, the method may collect data related to the launch of the at least one process. The method may compare the collected data with behavioral rules specifying compliant behavior on the computer system. The method may identify suspicious behavior associated with the at least one process in response to determining that the collected data does not meet the behavioral rules. The method may generate an alert indicative of the suspicious behavior. In response to identifying the suspicious behavior, the method may obtain telemetry data of the computer system, and may update the behavioral rules based on the telemetry data to improve accuracy of identifying further suspicious behavior.