论文标题

Coinhive关闭后,加密劫持死亡吗?

Is Cryptojacking Dead after Coinhive Shutdown?

论文作者

Varlioglu, Said, Gonen, Bilal, Ozer, Murat, Bastug, Mehmet F.

论文摘要

加密劫持是对受害者的计算机资源的开采,以使用恶意脚本来开采加密货币。在2017年攻击者开始利用合法采矿脚本,尤其是共同脚本时,它已变得很流行。 Coinhive实际上是一项合法的采矿服务,为浏览器内采矿活动提供了脚本和服务器。尽管如此,在2019年3月发生的共同关闭之前,每个月都有超过1000万个网络用户是受害者。本文探索了Coinhive停止使用服务后,探索了加密劫持世界的新时代。我们的目的是查看攻击者是否以及如何继续加密劫持,生成新的恶意脚本并开发了新方法。我们使用了Hong等人提出的名为CMTRACKER的强大加密夹克检测器。在2018年。我们自动并手动检查了2770个网站,这些网站已在Coinhive关闭之前已检测到。结果表明,有99%的网站不再继续进行隐式劫持。 1 \%的网站仍然运行8个独特的采矿脚本。通过跟踪这些采矿脚本,我们检测到了632个独特的加密夹克网站。此外,开源调查(OSINT)表明攻击者仍然使用相同的方法。因此,我们列出了加密劫持的典型模式。我们得出的结论是,在共同关闭后,加密劫持并未死亡。它仍然活着,但不像以前那样吸引人。

Cryptojacking is the exploitation of victims' computer resources to mine for cryptocurrency using malicious scripts. It has become popular after 2017 when attackers started to exploit legal mining scripts, especially Coinhive scripts. Coinhive was actually a legal mining service that provided scripts and servers for in-browser mining activities. Nevertheless, over 10 million web users had been victims every month before the Coinhive shutdown that happened in Mar 2019. This paper explores the new era of the cryptojacking world after Coinhive discontinued its service. We aimed to see whether and how attackers continue cryptojacking, generate new malicious scripts, and developed new methods. We used a capable cryptojacking detector named CMTracker that proposed by Hong et al. in 2018. We automatically and manually examined 2770 websites that had been detected by CMTracker before the Coinhive shutdown. The results revealed that 99\% of sites no longer continue cryptojacking. 1\% of websites still run 8 unique mining scripts. By tracking these mining scripts, we detected 632 unique cryptojacking websites. Moreover, open-source investigations (OSINT) demonstrated that attackers still use the same methods. Therefore, we listed the typical patterns of cryptojacking. We concluded that cryptojacking is not dead after the Coinhive shutdown. It is still alive, but not as attractive as it used to be.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源