Visible to the public Mitigation of Cryptojacking Attacks Using Taint Analysis

TitleMitigation of Cryptojacking Attacks Using Taint Analysis
Publication TypeConference Paper
Year of Publication2019
AuthorsYulianto, Arief Dwi, Sukarno, Parman, Warrdana, Aulia Arif, Makky, Muhammad Al
Conference Name2019 4th International Conference on Information Technology, Information Systems and Electrical Engineering (ICITISEE)
Date PublishedNov. 2019
PublisherIEEE
ISBN Number978-1-7281-5118-2
Keywordsabuse case, Attack Modeling, Browsers, Central Processing Unit, CPU resources, CPU usage, cross-site scripting, cryptocurrency, cryptography, cryptojacking, cryptomining, data mining, Google Chrome, Human Behavior, human factors, in-browsercryptojacking mitigation, malicious cryptocurrency mining, Malware, man-in-the-middle, man-in-the-middle attack, Metrics, mitigation, online front-ends, pubcrawl, resilience, Resiliency, script characteristics, security of data, taint analysis, taint analysis method, threat model, Web site background, Web sites
Abstract

Cryptojacking (also called malicious cryptocurrency mining or cryptomining) is a new threat model using CPU resources covertly "mining" a cryptocurrency in the browser. The impact is a surge in CPU Usage and slows the system performance. In this research, in-browsercryptojacking mitigation has been built as an extension in Google Chrome using Taint analysis method. The method used in this research is attack modeling with abuse case using the Man-In-The-Middle (MITM) attack as a testing for mitigation. The proposed model is designed so that users will be notified if a cryptojacking attack occurs. Hence, the user is able to check the script characteristics that run on the website background. The results of this research show that the taint analysis is a promising method to mitigate cryptojacking attacks. From 100 random sample websites, the taint analysis method can detect 19 websites that are infcted by cryptojacking.

URLhttps://ieeexplore.ieee.org/document/9003742
DOI10.1109/ICITISEE48480.2019.9003742
Citation Keyyulianto_mitigation_2019