[论文解读] A Retrospective Analysis of User Exposure to (Illicit) Cryptocurrency Mining on the Web
本论文通过大学网络、ISP、浏览器扩展以及代理/Tor网络的被动监测,对用户在浏览器中遭遇加密货币挖矿的暴露情况进行了回顾性、纵向分析。研究发现,实际用户暴露极为稀少且短暂,与早期主动扫描估计结果相矛盾,并揭示了一种此前未知的攻击向量:通过低成本设备上的恶意移动应用进行挖矿。
In late 2017, a sudden proliferation of malicious JavaScript was reported on the Web: browser-based mining exploited the CPU time of website visitors to mine the cryptocurrency Monero. Several studies measured the deployment of such code and developed defenses. However, previous work did not establish how many users were really exposed to the identified mining sites and whether there was a real risk given common user browsing behavior. In this paper, we present a retroactive analysis to close this research gap. We pool large-scale, longitudinal data from several vantage points, gathered during the prime time of illicit cryptomining, to measure the impact on web users. We leverage data from passive traffic monitoring of university networks and a large European ISP, with suspected mining sites identified in previous active scans. We corroborate our results with data from a browser extension with a large user base that tracks site visits. We also monitor open HTTP proxies and the Tor network for malicious injection of code. We find that the risk for most Web users was always very low, much lower than what deployment scans suggested. Any exposure period was also very brief. However, we also identify a previously unknown and exploited attack vector on mobile devices.
研究动机与目标
- 测量实际用户在非法浏览器端加密货币挖矿中的暴露程度,超越部署率指标。
- 调查在真实浏览行为下,挖矿代码高部署率是否转化为有意义的用户风险。
- 识别并分析其他攻击向量,包括代理和Tor网络中的注入行为,以及此前未知的移动设备攻击向量。
- 基于被动用户暴露数据,评估现有防御措施(如黑名单)的有效性。
- 提供一种纵向的、多源数据分析,以纠正先前主动扫描研究中对风险的高估。
提出的方法
- 整合多个观测点的被动流量监测数据:大学网络、一家大型欧洲移动ISP,以及拥有大量用户的浏览器扩展。
- 通过主动扫描和分类器识别挖矿网站(包括Coinhive、Authedmine等)的数据对发现结果进行交叉验证。
- 监控开放HTTP代理(每日最多25万个)和Tor出口节点,检测恶意代码注入。
- 追踪会话持续时间与CPU使用模式,以评估用户在挖矿网站上的参与程度。
- 利用2018–2019年的纵向数据,分析暴露趋势与用户行为随时间的变化。
- 通过主动测试验证分类器准确性,并在不同数据集之间交叉比对结果以确保一致性。
实验结果
研究问题
- RQ1在真实浏览行为下,实际网络用户暴露于浏览器端加密货币挖矿的频率如何?
- RQ2代理和Tor网络注入在用户暴露中所占比例有多大?该攻击向量的普遍程度如何?
- RQ3用户是否在挖矿网站上停留足够长时间,以对挖矿池做出实质性贡献?哪些因素影响了会话持续时间?
- RQ4是否存在此前未知或未报告的攻击向量,特别是在移动设备上,导致未经授权的挖矿?
- RQ5实际用户暴露程度与通过主动扫描测得的部署率相比如何?这对风险评估模型有何影响?
主要发现
- 用户暴露于挖矿网站的情况极为罕见:浏览器扩展访问中仅有0.016%至0.287%的访问目标为挖矿网站,且挖矿发生时的会话中位持续时间仅为30秒。
- 尽管早期主动扫描估计的部署率为0.5%–0.87%,但实际用户暴露率远低于此,表明仅依赖部署率指标会高估真实风险。
- 通过开放代理和Tor出口节点的攻击向量真实存在且已被利用,但由于此类服务使用率较低,仅影响极少数用户。
- 发现了一种此前未知的攻击向量:预装恶意应用的低成本移动设备在后台无声挖矿。
- 大多数挖矿会话持续时间过短(中位数30秒),无法对挖矿池做出显著贡献,削弱了攻击者的经济动机。
- 黑名单和网络层防御措施可能比以往认为的更有效,因为暴露事件稀少且短暂,且长尾浏览行为进一步降低了风险。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。