2021 51st Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN) | 2021

An Application Agnostic Defense Against the Dark Arts of Cryptojacking

 
 
 
 

Abstract


The popularity of cryptocurrencies has garnered interest from cybercriminals, spurring an onslaught of cryptojacking campaigns that aim to hijack computational resources for the purpose of mining cryptocurrencies. In this paper, we present a cross-stack cryptojacking defense system that spans the hardware and OS layers. Unlike prior work that is confined to detecting cryptojacking behavior within web browsers, our solution is application agnostic. We show that tracking instructions that are frequently used in cryptographic hash functions serve as reliable signatures for fingerprinting cryptojacking activity. We demonstrate that our solution is resilient to multi-threaded and throttling evasion techniques that are commonly employed by cryptojacking malware. We characterize the robustness of our solution by extensively testing a diverse set of workloads that include real consumer applications. Finally, an evaluation of our proof-of-concept implementation shows minimal performance impact while running a mix of benchmark applications

Volume None
Pages 314-325
DOI 10.1109/DSN48987.2021.00044
Language English
Journal 2021 51st Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)

Full Text