A Two-Stage Encrypted Cryptomining Traffic Detection Mechanism in Campus Network

Haoran Sun,Ruisheng Shi,Lina Lan,Zhiyuan Peng,Chenfeng Wang
DOI: https://doi.org/10.1109/icbc59979.2024.10634446
2024-01-01
Abstract:Cryptomining behaviours pose severe security threats to campus network. However, existing blacklist and DPI-based techniques suffer from delayed blacklist updates and inability to identify encrypted cryptomining traffic. Furthermore, existing encrypted cryptomining traffic detection schemes usually fail to provide detailed information about cryptomining behaviours and do not have a solution to deal with false positives caused by detection models. To meet the needs of campus networks and solve the problems of existing work, this paper proposes an effective and practical encrypted cryptomining traffic detection mechanism in campus network. It consists of a two-stage detection framework, which can effectively provide fine-grained detection results by machine learning and reduce false positives from classifiers through active probing. Based on our collected dataset and extracted time series features, our classifiers detect mining traffic with an 0.99 F 1 score and identify the cryptocurrency being mined with $99.39 \%$ correct recognition rate. Unlike existing schemes, we perform active probing after the traffic classification to reduce false positives. Futhermore, we have extensively evaluated the active probing scheme to verify its effectiveness for different mining pools.
What problem does this paper attempt to address?