论文标题
云中的矿工:在公共云中测量和分析加密货币挖掘
Miners in the Cloud: Measuring and Analyzing Cryptocurrency Mining in Public Clouds
论文作者
论文摘要
加密货币,可以说是区块链最突出的应用,随着广泛的主流认可一直在上升。加密货币中的一个核心概念是“采矿池”,这组合加密货币矿工,他们同意按其贡献的矿业能力成比例地分享阻碍奖励。尽管加密货币带来了许多承诺的好处,但它们同样被用于恶意活动。例如,勒索软件付款,隐形命令,控制等。因此,了解加密货币(尤其是采矿池)之间的相互作用以及用于分析和建模的其他基本基础架构很重要。 在本文中,我们通过通过被动域名系统(PDN)痕迹分析其通信关联,研究采矿池和公共云之间的相互作用。我们观察到,从PDNS查询痕迹中观察到的24个云提供商与采矿池有一定的关联,那里流行的公共云提供商,即亚马逊和Google,几乎拥有这种关联的48%。此外,我们发现,云提供商的存在和云提供商对泳池协会都表现出重型分布,强调了带有采矿池和云提供商的内在优先依恋模型。我们衡量云提供商的安全风险和暴露,因为这可能有助于理解采矿的目的:在前两个云提供商中,我们发现,根据Virustotal.com扫描,我们发现其相关终点的几乎35%和30%与恶意活动相关。最后,我们发现数据集中呈现的采矿池主要用于采矿元货币,突出了加密货币的使用转移,并证明了使用公共云的采矿率。
Cryptocurrencies, arguably the most prominent application of blockchains, have been on the rise with a wide mainstream acceptance. A central concept in cryptocurrencies is "mining pools", groups of cooperating cryptocurrency miners who agree to share block rewards in proportion to their contributed mining power. Despite many promised benefits of cryptocurrencies, they are equally utilized for malicious activities; e.g., ransomware payments, stealthy command, control, etc. Thus, understanding the interplay between cryptocurrencies, particularly the mining pools, and other essential infrastructure for profiling and modeling is important. In this paper, we study the interplay between mining pools and public clouds by analyzing their communication association through passive domain name system (pDNS) traces. We observe that 24 cloud providers have some association with mining pools as observed from the pDNS query traces, where popular public cloud providers, namely Amazon and Google, have almost 48% of such an association. Moreover, we found that the cloud provider presence and cloud provider-to-mining pool association both exhibit a heavy-tailed distribution, emphasizing an intrinsic preferential attachment model with both mining pools and cloud providers. We measure the security risk and exposure of the cloud providers, as that might aid in understanding the intent of the mining: among the top two cloud providers, we found almost 35% and 30% of their associated endpoints are positively detected to be associated with malicious activities, per the virustotal.com scan. Finally, we found that the mining pools presented in our dataset are predominantly used for mining Metaverse currencies, highlighting a shift in cryptocurrency use, and demonstrating the prevalence of mining using public clouds.