Cryptomining Malware Detection via Script and Resource Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems face challenges in effectively identifying and mitigating cryptomining malware, which can covertly utilize computer resources for cryptocurrency mining without user permission, leading to performance degradation and malicious activity.
Innovation Solution
A system and method utilizing a security engine that monitors network elements for suspicious website and script activity, employing regular expression analysis and CPU/resource usage monitoring to identify and block malicious scripts and websites, and reporting spikes in resource usage to a network security engine for further analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional security systems are used to monitor network traffic, then basic malware detection is possible, but cryptomining malware cannot be effectively identified due to its covert resource usage patterns
Solution Approach 1:
The system dynamically monitors resource usage patterns of network elements in real-time, adapting detection thresholds based on baseline behavior. The security engine continuously adjusts monitoring parameters to identify anomalous resource consumption indicative of cryptomining activities, rather than relying on static detection rules.
Solution Approach 2:
The patent changes the detection parameters from traditional signature-based methods to resource usage pattern analysis. By monitoring CPU utilization, memory consumption, and network traffic characteristics, the system transforms the detection approach to identify cryptomining malware through its distinctive resource consumption profile rather than known malware signatures.
2Measurement precision
If comprehensive resource monitoring is implemented to detect cryptomining malware, then detection accuracy improves, but system complexity and processing overhead increase
Solution Approach 1:
The patent extracts only the critical resource usage parameters necessary for cryptomining detection (CPU utilization, memory consumption, network traffic patterns) from the full system state. By focusing monitoring on these specific extracted parameters rather than comprehensive system analysis, the solution achieves high detection accuracy while minimizing system complexity and processing overhead.
Solution Approach 2:
The security engine performs multiple functions using the same monitoring infrastructure: it simultaneously detects cryptomining malware, analyzes resource usage patterns, and provides baseline behavior establishment. This multi-functionality reduces overall system complexity by consolidating detection capabilities rather than implementing separate specialized systems.
3Measurement precision
If real-time analysis of all scripts and websites is performed, then malware identification accuracy improves, but processing time and system performance degradation increase
Solution Approach 1:
The system performs partial analysis by focusing monitoring efforts on network elements exhibiting suspicious resource usage patterns rather than analyzing all scripts and websites uniformly. When anomalous resource consumption is detected, the security engine then performs comprehensive script analysis only on those specific targets, reducing overall processing time while maintaining high identification accuracy through targeted investigation.
Solution Approach 2:
The patent implements preliminary baseline establishment of normal resource usage patterns for network elements before malware detection begins. This preliminary action creates reference profiles that enable faster subsequent detection, as the system can quickly compare current resource usage against established baselines to identify deviations indicative of malware, avoiding time-consuming analysis from scratch.
4Reliability
If traditional blacklisting methods are used to block malicious websites, then known malware is prevented, but new or obfuscated cryptomining malware can bypass detection
Solution Approach 1:
The system transitions from static blacklisting to dynamic behavior-based detection. Instead of relying on fixed lists of known malicious websites, the security engine continuously monitors resource usage patterns and adapts detection criteria based on observed behavior. This dynamic approach enables the system to identify new and obfuscated cryptomining malware variants that have not been previously blacklisted, as detection is based on behavioral patterns rather than known signatures.
Data Source
AI summary
Particular embodiments described herein provide for a system that can be configured to identify cryptomining malware. The electronic device can be configured to identify a website, determine one or more uniform resource locators associated with the website, determine scripts associated with the website, obtain a string format of each of the determined scripts associated with the website, analyze each of the of the string formats to determine if a specific script is related to malware, and block the website if the specific script is related to malware. In an example, the system can also be configured to determine if usage of the computer processing unit and/or system resources increase more than a threshold amount during access to the website and send the one or more uniform resource locators associated with the website to a network security engine for further analysis.


