EMI Fingerprint Detection for Malicious Cryptomining Software

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current manual detection methods for malicious cryptomining software in cloud systems are time-consuming and inefficient, as they struggle to differentiate between legitimate high CPU utilization and malicious activities, with cryptominers evading detection by distributing computations across multiple accounts.

Innovation Solution

A system that monitors electromagnetic interference (EMI) signals to generate fingerprints, using Fast Fourier Transform, Multivariate State Estimation Technique, and bivariate normalized cross power spectral density to automatically detect malicious cryptomining software by comparing target EMI fingerprints against known malicious patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual detection methods are used to identify malicious cryptomining software, then administrators can examine cloud customer virtual machines with high CPU utilization, but the process is extremely time-consuming and prone to false positives

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual administrative inspection with electromagnetic field-based detection. Instead of administrators manually examining virtual machines with high CPU utilization, the system uses EMI sensors to capture electromagnetic signals emitted by hardware components, automatically identifying malicious cryptomining software through pattern recognition in the electromagnetic spectrum.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces electromagnetic signals as an intermediary for detection. Rather than directly observing software behavior or CPU utilization metrics, the system uses EMI emissions from hardware components as an intermediate indicator that reveals the presence of malicious cryptomining operations without requiring direct software analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If administrators manually examine virtual machines with high CPU utilization, then they can identify suspicious workloads, but legitimate cloud customers running high-performance workloads are often falsely identified

Engineering Contradiction:
Improvedetection reliabilityVSAvoidfalse positives
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by analyzing electromagnetic signal characteristics specific to different hardware components and their operational states. Instead of relying on general CPU utilization metrics that cannot distinguish between legitimate and malicious workloads, the system examines localized EMI patterns from specific components (CPU, GPU, memory) that have distinctive electromagnetic signatures for different types of computational activities.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent uses electromagnetic signal frequency and amplitude variations as analogous to color changes. Different types of computational workloads produce distinct EMI frequency patterns, allowing the system to differentiate between legitimate high-performance computing and malicious cryptomining operations based on the 'electromagnetic color' or spectral characteristics of the emitted signals.

Inventive Principle:
Principle #32Color changes

3Adaptability or versatility

If cryptominers distribute computations across multiple accounts, then they can stay under utilization thresholds to evade detection, but manual examination becomes even more time-consuming

Engineering Contradiction:
Improveevasion capabilityVSAvoiddetection time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent merges multiple detection signals into a unified electromagnetic fingerprint analysis. Instead of examining each virtual machine or account separately as done in manual detection, the system combines EMI data from multiple sources and uses pattern recognition to identify distributed cryptomining operations across multiple accounts, revealing coordinated malicious activity that would be invisible through individual account monitoring.

Inventive Principle:
Principle #5Merging (Combining)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach enables rapid and accurate identification of malicious cryptomining software, reducing the risk of false positives and negatives, and effectively managing workload security without manual intervention.

Implementation Method 1

monitors target electromagnetic interference (EMI) signals generated during operation of the target computing system

Methodology Applied
Scientific EffectElectromagnetic interference (EMI): Electromagnetic Induction

Implementation Method 2

the system performs a Fast Fourier Transform (FFT) operation on the target EMI signals to transform the target EMI signals from a time-domain representation to a frequency-domain representation

Methodology Applied
Scientific EffectFast Fourier Transform:

Data Source

PatentUS10984106B2Using EMI fingerprints to detect malicious cryptomining software
Publication Date: 2021.04.20 ORACLE INT CORP
  • US10984106B2 patent drawing
  • US10984106B2 patent drawing
  • US10984106B2 patent drawing

AI summary

The disclosed embodiments provide a system that detects execution of malicious cryptomining software in a target computing system. During operation, the system monitors target electromagnetic interference (EMI) signals generated during operation of the target computing system. Next, the system generates a target EMI fingerprint from the target EMI signals. The system then compares the target EMI fingerprint against a set of malicious EMI fingerprints for different pieces of malicious cryptomining software to determine whether the target computing system is executing malicious cryptomining software.