Naïve Bayes Cryptojacking Detector
Nikolay Gaidamakin, Dmitry Tanana · 2022
Value and popularity of cryptocurrencies keeps rising, which attracts cybercriminals who seek to profit using blockchain ecosystem. One of the most popular methods used, with several million attacks conducted every month, is cryptojacking – the act of mining cryptocurrencies without owners’ consent. This paper considers Bayesian cryptojacking detector which is based on four major cryptojacking activity metrics – CPU load, RAM usage, network access and cryptographic libraries calls. The first stage of detector operation is comparison of corresponding metrics with thresholds based on empirical research of cryptojackers. Then conditional probabilities of exceeding/not exceeding cryptojacking infection thresholds are estimated using generalized Bayes theorem. After that probability of cryptojacker functioning is calculated based on the comparison results and conditional probabilities. Finally that probability is compared with certain threshold value and detectors’ decision is made. Calculations show that based on such analysis detection rate would be around 0.90, probability of type I error (false positive) – 0.013 and type II error (false negative) – 0.0056. To conclude this paper, potential improvements of cryptojacking detector are discussed.