Network Traffic Evaluation for Cryptocurrency Mining Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to efficiently detect and mitigate cryptocurrency mining malware, which consumes significant resources and causes stress on computer systems, as current detection methods are either computationally expensive or ineffective against encrypted traffic and unknown protocols.

Innovation Solution

Intercepting network traffic to extract IP packet data, evaluating it for patterns characteristic of cryptocurrency mining communication, and using machine learning to identify mining activity, allowing for remedial actions such as blocking traffic or notifying users without requiring deep packet inspection or specialized software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep packet inspection or specialized software is used to detect cryptocurrency mining, then detection accuracy improves, but computational cost and system complexity increase significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the essential network traffic metadata (packet size, timing intervals, protocol type, destination ports) from the full network traffic, eliminating the need for complex deep packet inspection. This extraction approach maintains detection accuracy by focusing on characteristic mining pool communication patterns while significantly reducing computational overhead and system complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces traditional mechanical inspection methods (deep packet inspection, signature-based detection) with a machine learning model that analyzes network traffic patterns. This substitution enables the system to detect cryptocurrency mining activity through statistical patterns in traffic metadata rather than requiring complex packet-by-packet analysis, thereby reducing system complexity while maintaining high detection accuracy

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If deep packet inspection is implemented to detect mining activity, then detection capability improves, but resource consumption increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts only critical traffic characteristics (packet size, timing, protocol type, destination port) from complete network packets, avoiding the resource-intensive process of inspecting entire packet contents. This extraction methodology maintains reliable detection of mining pool communications while significantly reducing CPU, memory, and energy consumption compared to full deep packet inspection approaches

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial inspection by analyzing only the necessary portions of network traffic (metadata and packet headers) rather than performing exhaustive deep packet inspection on all packets. This partial action approach provides sufficient detection capability for identifying cryptocurrency mining activity while consuming far fewer computational resources

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If traditional antivirus or firewall methods are used, then protection against known threats is provided, but detection of unknown mining protocols is ineffective

Engineering Contradiction:
Improveprotocol recognitionVSAvoiddetection effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent employs a dynamic machine learning model that continuously adapts to identify cryptocurrency mining activity based on observed network traffic patterns. Unlike static traditional antivirus or firewall rules, the model learns and adjusts to new mining protocols and communication patterns, enabling reliable detection of both known and unknown mining activities while maintaining versatility across different cryptocurrency protocols

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal detection system that can identify multiple types of cryptocurrency mining activity through a single machine learning model. The model analyzes general network traffic patterns characteristic of mining pool communications rather than requiring protocol-specific detection rules, providing both versatility across different cryptocurrencies and reliable detection effectiveness against unknown mining protocols

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11316880B2Cryptocurrency mining detection using network traffic
Publication Date: 2022.04.26 GEN DIGITAL INC
  • US11316880B2 patent drawing
  • US11316880B2 patent drawing
  • US11316880B2 patent drawing

AI summary

A method of identifying cryptocurrency mining on a networked computerized device includes intercepting network traffic between the networked computerized device and a public network, and extracting Internet Protocol (IP) packet data of the intercepted network traffic. The IP packet data of the intercepted network traffic is evaluated such that if the intercepted network traffic is determined to be characteristic of communication with a cryptocurrency mining pool it is determined that the networked computerized device is mining cryptocurrency. One or more remedial actions are taken if it is determined that the networked computerized device is mining cryptocurrency, such as blocking traffic between the networked computerized device and the mining pool or notifying a user.