Thieves in the Browser: Web-based Cryptojacking in the Wild

被引:20
|
作者
Musch, Marius [1 ]
Wressnegger, Christian [1 ]
Johns, Martin [1 ]
Rieck, Konrad [1 ]
机构
[1] TU Braunschweig, Braunschweig, Germany
关键词
D O I
10.1145/3339252.3339261
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the introduction of memory-bound cryptocurrencies, such as Monero, the implementation of mining code in browser-based JavaScript has become a worthwhile alternative to dedicated mining rigs. Based on this technology, a new form of parasitic computing, widely called cryptojacking or drive -by mining, has gained momentum in the web. A cryptojacking site abuses the computing resources of its visitors to covertly mine for cryptocurrencies. In this paper, we systematically explore this phenomenon. For this, we propose a 3 -phase analysis approach, which enables us to identify mining scripts and conduct a large-scale study on the prevalence of cryptojacking in the Alexa 1 million websites. We find that cryptojacking is common, with currently 1 out of 500 sites hosting a mining script. Moreover, we perform several secondary analyses to gain insight into the cryptojacking landscape, including a measurement of code characteristics, an estimate of expected mining revenue, and an evaluation of current blacklist-based countermeasures.
引用
收藏
页数:10
相关论文
共 50 条
  • [1] Cytoscape Web: an interactive web-based network browser
    Lopes, Christian T.
    Franz, Max
    Kazi, Farzana
    Donaldson, Sylva L.
    Morris, Quaid
    Bader, Gary D.
    [J]. BIOINFORMATICS, 2010, 26 (18) : 2347 - 2348
  • [2] A first look at browser-based cryptojacking
    Eskandari, Shayan
    Leoutsarakos, Andreas
    Mursch, Troy
    Clark, Jeremy
    [J]. 2018 3RD IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW 2018), 2018, : 58 - 66
  • [3] DNS based In-Browser Cryptojacking Detection
    Sachan, Rohit Kumar
    Agarwal, Rachit
    Shukla, Sandeep Kumar
    [J]. 2022 FOURTH INTERNATIONAL CONFERENCE ON BLOCKCHAIN COMPUTING AND APPLICATIONS (BCCA), 2022, : 259 - 266
  • [4] Progress on Web-based Genome Browser Technology
    Zhang Hai-Chuan
    Li Jie
    Wang Ya-Dong
    [J]. PROGRESS IN BIOCHEMISTRY AND BIOPHYSICS, 2014, 41 (11) : 1182 - 1190
  • [5] Web-Com: Interactive browser for Web-based education
    Kazuki, H
    Yonekura, T
    Shibusawa, S
    [J]. IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2005, E88D (05): : 912 - 918
  • [6] Development of the "Web-Com" interactive browser for Web-based
    Hiraki, K
    Yonekura, T
    Kawahara, S
    Shibusawa, S
    [J]. 2004 INTERNATIONAL CONFERENCE ON CYBERWORLDS, PROCEEDINGS, 2004, : 343 - 350
  • [7] Analyzing In-browser Cryptojacking
    University of Central Florida, United States
    [J]. arXiv, 1600,
  • [8] Analyzing In-browser Cryptojacking
    Saad M.
    Mohaisen D.
    [J]. IEEE Transactions on Dependable and Secure Computing, 2024, 21 (06): : 1 - 13
  • [9] Web Browser Network Based on a BA Model for a Web-Based Virtual World
    Kohana, Masaki
    Sakamoto, Shinji
    Okamoto, Shusuke
    [J]. FUTURE INTERNET, 2019, 11 (07)
  • [10] Gbrowse Moby: a Web-based browser for BioMoby Services
    Wilkinson, Mark
    [J]. SOURCE CODE FOR BIOLOGY AND MEDICINE, 2006, 1 (01)