Network Traffic Evaluation for Cryptocurrency Mining Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems fail to efficiently detect and mitigate cryptocurrency mining malware, which consumes significant resources and causes stress on computer systems, as current detection methods are either computationally expensive or ineffective against encrypted traffic and unknown protocols.
Innovation Solution
Intercepting network traffic to extract IP packet data, evaluating it for patterns characteristic of cryptocurrency mining communication, and using machine learning to identify mining activity, allowing for remedial actions such as blocking traffic or notifying users without requiring deep packet inspection or specialized software.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If deep packet inspection or specialized software is used to detect cryptocurrency mining, then detection accuracy improves, but computational cost and system complexity increase significantly
Solution Approach 1:
The patent extracts only the essential network traffic metadata (packet size, timing intervals, protocol type, destination ports) from the full network traffic, eliminating the need for complex deep packet inspection. This extraction approach maintains detection accuracy by focusing on characteristic mining pool communication patterns while significantly reducing computational overhead and system complexity
Solution Approach 2:
The patent replaces traditional mechanical inspection methods (deep packet inspection, signature-based detection) with a machine learning model that analyzes network traffic patterns. This substitution enables the system to detect cryptocurrency mining activity through statistical patterns in traffic metadata rather than requiring complex packet-by-packet analysis, thereby reducing system complexity while maintaining high detection accuracy
2Reliability
If deep packet inspection is implemented to detect mining activity, then detection capability improves, but resource consumption increases
Solution Approach 1:
The patent extracts only critical traffic characteristics (packet size, timing, protocol type, destination port) from complete network packets, avoiding the resource-intensive process of inspecting entire packet contents. This extraction methodology maintains reliable detection of mining pool communications while significantly reducing CPU, memory, and energy consumption compared to full deep packet inspection approaches
Solution Approach 2:
The patent applies partial inspection by analyzing only the necessary portions of network traffic (metadata and packet headers) rather than performing exhaustive deep packet inspection on all packets. This partial action approach provides sufficient detection capability for identifying cryptocurrency mining activity while consuming far fewer computational resources
3Adaptability or versatility
If traditional antivirus or firewall methods are used, then protection against known threats is provided, but detection of unknown mining protocols is ineffective
Solution Approach 1:
The patent employs a dynamic machine learning model that continuously adapts to identify cryptocurrency mining activity based on observed network traffic patterns. Unlike static traditional antivirus or firewall rules, the model learns and adjusts to new mining protocols and communication patterns, enabling reliable detection of both known and unknown mining activities while maintaining versatility across different cryptocurrency protocols
Solution Approach 2:
The patent creates a universal detection system that can identify multiple types of cryptocurrency mining activity through a single machine learning model. The model analyzes general network traffic patterns characteristic of mining pool communications rather than requiring protocol-specific detection rules, providing both versatility across different cryptocurrencies and reliable detection effectiveness against unknown mining protocols
Data Source
AI summary
A method of identifying cryptocurrency mining on a networked computerized device includes intercepting network traffic between the networked computerized device and a public network, and extracting Internet Protocol (IP) packet data of the intercepted network traffic. The IP packet data of the intercepted network traffic is evaluated such that if the intercepted network traffic is determined to be characteristic of communication with a cryptocurrency mining pool it is determined that the networked computerized device is mining cryptocurrency. One or more remedial actions are taken if it is determined that the networked computerized device is mining cryptocurrency, such as blocking traffic between the networked computerized device and the mining pool or notifying a user.


