EMI Fingerprint Detection for Malicious Cryptomining Software
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current manual detection methods for malicious cryptomining software in cloud systems are time-consuming and inefficient, as they struggle to differentiate between legitimate high CPU utilization and malicious activities, with cryptominers evading detection by distributing computations across multiple accounts.
Innovation Solution
A system that monitors electromagnetic interference (EMI) signals to generate fingerprints, using Fast Fourier Transform, Multivariate State Estimation Technique, and bivariate normalized cross power spectral density to automatically detect malicious cryptomining software by comparing target EMI fingerprints against known malicious patterns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual detection methods are used to identify malicious cryptomining software, then administrators can examine cloud customer virtual machines with high CPU utilization, but the process is extremely time-consuming and prone to false positives
Solution Approach 1:
The patent replaces manual administrative inspection with electromagnetic field-based detection. Instead of administrators manually examining virtual machines with high CPU utilization, the system uses EMI sensors to capture electromagnetic signals emitted by hardware components, automatically identifying malicious cryptomining software through pattern recognition in the electromagnetic spectrum.
Solution Approach 2:
The patent introduces electromagnetic signals as an intermediary for detection. Rather than directly observing software behavior or CPU utilization metrics, the system uses EMI emissions from hardware components as an intermediate indicator that reveals the presence of malicious cryptomining operations without requiring direct software analysis.
2Reliability
If administrators manually examine virtual machines with high CPU utilization, then they can identify suspicious workloads, but legitimate cloud customers running high-performance workloads are often falsely identified
Solution Approach 1:
The patent applies local quality by analyzing electromagnetic signal characteristics specific to different hardware components and their operational states. Instead of relying on general CPU utilization metrics that cannot distinguish between legitimate and malicious workloads, the system examines localized EMI patterns from specific components (CPU, GPU, memory) that have distinctive electromagnetic signatures for different types of computational activities.
Solution Approach 2:
The patent uses electromagnetic signal frequency and amplitude variations as analogous to color changes. Different types of computational workloads produce distinct EMI frequency patterns, allowing the system to differentiate between legitimate high-performance computing and malicious cryptomining operations based on the 'electromagnetic color' or spectral characteristics of the emitted signals.
3Adaptability or versatility
If cryptominers distribute computations across multiple accounts, then they can stay under utilization thresholds to evade detection, but manual examination becomes even more time-consuming
Solution Approach 1:
The patent merges multiple detection signals into a unified electromagnetic fingerprint analysis. Instead of examining each virtual machine or account separately as done in manual detection, the system combines EMI data from multiple sources and uses pattern recognition to identify distributed cryptomining operations across multiple accounts, revealing coordinated malicious activity that would be invisible through individual account monitoring.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach enables rapid and accurate identification of malicious cryptomining software, reducing the risk of false positives and negatives, and effectively managing workload security without manual intervention.
Implementation Method 1
monitors target electromagnetic interference (EMI) signals generated during operation of the target computing system
Implementation Method 2
the system performs a Fast Fourier Transform (FFT) operation on the target EMI signals to transform the target EMI signals from a time-domain representation to a frequency-domain representation
Data Source
AI summary
The disclosed embodiments provide a system that detects execution of malicious cryptomining software in a target computing system. During operation, the system monitors target electromagnetic interference (EMI) signals generated during operation of the target computing system. Next, the system generates a target EMI fingerprint from the target EMI signals. The system then compares the target EMI fingerprint against a set of malicious EMI fingerprints for different pieces of malicious cryptomining software to determine whether the target computing system is executing malicious cryptomining software.


