Mostra el registre d'ítem simple
Detecting cryptocurrency miners with NetFlow/IPFIX network measurements
dc.contributor.author | Zayuelas Muñoz, Jordi |
dc.contributor.author | Suárez-Varela Maciá, José Rafael |
dc.contributor.author | Barlet Ros, Pere |
dc.contributor.other | Universitat Politècnica de Catalunya. Doctorat en Arquitectura de Computadors |
dc.contributor.other | Universitat Politècnica de Catalunya. Departament d'Arquitectura de Computadors |
dc.date.accessioned | 2020-06-09T09:00:44Z |
dc.date.available | 2020-06-09T09:00:44Z |
dc.date.issued | 2019 |
dc.identifier.citation | Zayuelas, J.; Suárez-varela, J.; Barlet, P. Detecting cryptocurrency miners with NetFlow/IPFIX network measurements. A: IEEE International Workshop on Measurements and Networking. "M&N 2019 IEEE International Symposium on Measurements and Networking: Catania, Italy, July 8-10, 2019: proceedings". Institute of Electrical and Electronics Engineers (IEEE), 2019, p. 1-6. |
dc.identifier.isbn | 978-1-7281-1273-2 |
dc.identifier.uri | http://hdl.handle.net/2117/190279 |
dc.description.abstract | In the last few years, cryptocurrency mining has become more and more important on the Internet activity and nowadays is even having a noticeable impact on the global economy. This has motivated the emergence of a new malicious activity called cryptojacking, which consists of compromising other machines connected to the Internet and leverage their resources to mine cryptocurrencies. In this context, it is of particular interest for network administrators to detect possible cryptocurrency miners using network resources without permission. Currently, it is possible to detect them using IP address lists from known mining pools, processing information from DNS traffic, or directly performing Deep Packet Inspection (DPI) over all the traffic. However, all these methods are still ineffective to detect miners using unknown mining servers or result too expensive to be deployed in real-world networks with large traffic volume. In this paper, we present a machine learning-based method able to detect cryptocurrency miners using NetFlow/IPFIX network measurements. Our method does not require to inspect the packets' payload; as a result, it achieves cost-efficient miner detection with similar accuracy than DPI-based techniques. |
dc.description.sponsorship | This work has been supported by the Spanish MINECO under contract TEC2017-90034-C2-1-R (ALLIANCE). |
dc.format.extent | 6 p. |
dc.language.iso | eng |
dc.publisher | Institute of Electrical and Electronics Engineers (IEEE) |
dc.subject | Àrees temàtiques de la UPC::Informàtica::Seguretat informàtica |
dc.subject.lcsh | Computer networks -- Security measures |
dc.subject.lcsh | Data mining |
dc.subject.lcsh | Telecommunication -- Traffic |
dc.subject.lcsh | Cryptocurrencies |
dc.subject.other | Cryptojacking detection |
dc.subject.other | Cryptocurrency mining |
dc.subject.other | Machine learning |
dc.subject.other | NetFlow measurements |
dc.title | Detecting cryptocurrency miners with NetFlow/IPFIX network measurements |
dc.type | Conference report |
dc.subject.lemac | Ordinadors, Xarxes d' -- Mesures de seguretat |
dc.subject.lemac | Mineria de dades |
dc.subject.lemac | Telecomunicació -- Tràfic |
dc.contributor.group | Universitat Politècnica de Catalunya. CBA - Sistemes de Comunicacions i Arquitectures de Banda Ampla |
dc.identifier.doi | 10.1109/IWMN.2019.8804995 |
dc.description.peerreviewed | Peer Reviewed |
dc.relation.publisherversion | https://ieeexplore.ieee.org/document/8804995 |
dc.rights.access | Open Access |
local.identifier.drac | 28610039 |
dc.description.version | Postprint (author's final draft) |
dc.relation.projectid | info:eu-repo/grantAgreement/AEI/Plan Estatal de Investigación Científica y Técnica y de Innovación 2013-2016/TEC2017-90034-C2-1-R/ES/DISEÑANDO UNA INFRAESTRUCTURA DE RED 5G DEFINIDA MEDIANTE CONOCIMIENTO HACIA LA PROXIMA SOCIEDAD DIGITAL/ |
local.citation.author | Zayuelas, J.; Suárez-varela, J.; Barlet, P. |
local.citation.contributor | IEEE International Workshop on Measurements and Networking |
local.citation.publicationName | M&N 2019 IEEE International Symposium on Measurements and Networking: Catania, Italy, July 8-10, 2019: proceedings |
local.citation.startingPage | 1 |
local.citation.endingPage | 6 |