Cryptomining Malware Detection via Script and Resource Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems face challenges in effectively identifying and mitigating cryptomining malware, which can covertly utilize computer resources for cryptocurrency mining without user permission, leading to performance degradation and malicious activity.

Innovation Solution

A system and method utilizing a security engine that monitors network elements for suspicious website and script activity, employing regular expression analysis and CPU/resource usage monitoring to identify and block malicious scripts and websites, and reporting spikes in resource usage to a network security engine for further analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional security systems are used to monitor network traffic, then basic malware detection is possible, but cryptomining malware cannot be effectively identified due to its covert resource usage patterns

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidcryptomining malware identification reliability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system dynamically monitors resource usage patterns of network elements in real-time, adapting detection thresholds based on baseline behavior. The security engine continuously adjusts monitoring parameters to identify anomalous resource consumption indicative of cryptomining activities, rather than relying on static detection rules.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the detection parameters from traditional signature-based methods to resource usage pattern analysis. By monitoring CPU utilization, memory consumption, and network traffic characteristics, the system transforms the detection approach to identify cryptomining malware through its distinctive resource consumption profile rather than known malware signatures.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If comprehensive resource monitoring is implemented to detect cryptomining malware, then detection accuracy improves, but system complexity and processing overhead increase

Engineering Contradiction:
Improvecryptomining malware detection accuracyVSAvoidsecurity system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the critical resource usage parameters necessary for cryptomining detection (CPU utilization, memory consumption, network traffic patterns) from the full system state. By focusing monitoring on these specific extracted parameters rather than comprehensive system analysis, the solution achieves high detection accuracy while minimizing system complexity and processing overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The security engine performs multiple functions using the same monitoring infrastructure: it simultaneously detects cryptomining malware, analyzes resource usage patterns, and provides baseline behavior establishment. This multi-functionality reduces overall system complexity by consolidating detection capabilities rather than implementing separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If real-time analysis of all scripts and websites is performed, then malware identification accuracy improves, but processing time and system performance degradation increase

Engineering Contradiction:
Improvemalware identification accuracyVSAvoidscript analysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs partial analysis by focusing monitoring efforts on network elements exhibiting suspicious resource usage patterns rather than analyzing all scripts and websites uniformly. When anomalous resource consumption is detected, the security engine then performs comprehensive script analysis only on those specific targets, reducing overall processing time while maintaining high identification accuracy through targeted investigation.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements preliminary baseline establishment of normal resource usage patterns for network elements before malware detection begins. This preliminary action creates reference profiles that enable faster subsequent detection, as the system can quickly compare current resource usage against established baselines to identify deviations indicative of malware, avoiding time-consuming analysis from scratch.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If traditional blacklisting methods are used to block malicious websites, then known malware is prevented, but new or obfuscated cryptomining malware can bypass detection

Engineering Contradiction:
Improveknown malware blocking effectivenessVSAvoiddetection of new malware variants
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system transitions from static blacklisting to dynamic behavior-based detection. Instead of relying on fixed lists of known malicious websites, the security engine continuously monitors resource usage patterns and adapts detection criteria based on observed behavior. This dynamic approach enables the system to identify new and obfuscated cryptomining malware variants that have not been previously blacklisted, as detection is based on behavioral patterns rather than known signatures.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11182480B2Identification of malware
Publication Date: 2021.11.23 MCAFEE LLC
  • US11182480B2 patent drawing
  • US11182480B2 patent drawing
  • US11182480B2 patent drawing

AI summary

Particular embodiments described herein provide for a system that can be configured to identify cryptomining malware. The electronic device can be configured to identify a website, determine one or more uniform resource locators associated with the website, determine scripts associated with the website, obtain a string format of each of the determined scripts associated with the website, analyze each of the of the string formats to determine if a specific script is related to malware, and block the website if the specific script is related to malware. In an example, the system can also be configured to determine if usage of the computer processing unit and/or system resources increase more than a threshold amount during access to the website and send the one or more uniform resource locators associated with the website to a network security engine for further analysis.