Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

Circuit: A JavaScript Memory Heap-Based Approach for Precisely Detecting Cryptojacking Websitesopen access

Authors
Hong, HyunjiWoo, SeunghoonPark, SunghanLee, JeongwookLee, Heejo
Issue Date
2022
Publisher
IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
Keywords
Codes; Computer security; Cryptocurrency; Engines; Instruction sets; Behavioral sciences; Syntactics; Cyberattack; Browsers; Browser security; web security; cryptojacking
Citation
IEEE ACCESS, v.10, pp.95356 - 95368
Indexed
SCIE
SCOPUS
Journal Title
IEEE ACCESS
Volume
10
Start Page
95356
End Page
95368
URI
https://scholar.korea.ac.kr/handle/2021.sw.korea/145568
DOI
10.1109/ACCESS.2022.3204814
ISSN
2169-3536
Abstract
Cryptojacking is often used by attackers as a means of gaining profits by exploiting users' resources without their consent, despite the anticipated positive effect of browser-based cryptomining. Previous approaches have attempted to detect cryptojacking websites, but they have the following limitations: (1) they failed to detect several cryptojacking websites either because of their evasion techniques or because they cannot detect JavaScript-based cryptojacking and (2) they yielded several false alarms by focusing only on limited characteristics of cryptojacking, such as counting computer resources. In this paper, we propose CIRCUIT, a precise approach for detecting cryptojacking websites. We primarily focuse on the JavaScript memory heap, which is resilient to script code obfuscation and provides information about the objects declared in the script code and their reference relations. We then extract a reference flow that can represent the script code behavior of the website from the JavaScript memory heap. Hence, CIRCUIT determines that a website is running cryptojacking if it contains a reference flow for cryptojacking. In our experiments, we found 1,813 real-world cryptojacking websites among 300K popular websites. Moreover, we provided new insights into cryptojacking by modeling the identified evasion techniques and considering the fact that characteristics of cryptojacking websites now appear on normal websites as well.
Files in This Item
There are no files associated with this item.
Appears in
Collections
Graduate School > Department of Computer Science and Engineering > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher Lee, Hee jo photo

Lee, Hee jo
컴퓨터학과
Read more

Altmetrics

Total Views & Downloads

BROWSE