信息网络安全 ›› 2021, Vol. 21 ›› Issue (7): 87-94.doi: 10.3969/j.issn.1671-1122.2021.07.011

• 理论研究 • 上一篇    下一篇

基于多特征识别的恶意挖矿网页检测及其取证研究

黄子依, 秦玉海()   

  1. 中国刑事警察学院公安信息技术与情报学院,沈阳 110035
  • 收稿日期:2021-01-16 出版日期:2021-07-10 发布日期:2021-07-23
  • 通讯作者: 秦玉海 E-mail:13840392578@163.com
  • 作者简介:黄子依(1997—),女,山东,硕士研究生,主要研究方向为信息网络安全与电子数据取证|秦玉海(1964—),男,辽宁,教授,本科,主要研究方向为信息网络安全与电子数据取证
  • 基金资助:
    辽宁网络安全执法协同创新中心资助项目(WXZX-201912015);中国刑事警察学院研究生创新能力提升项目(2020YCYB24)

Malicious Mining Web Page Detection and Forensics Based on Multi-feature Recognition

HUANG Ziyi, QIN Yuhai()   

  1. College of Public Security Information Technology and Information, Criminal Investigation Police University of China, Shenyang 110035, China
  • Received:2021-01-16 Online:2021-07-10 Published:2021-07-23
  • Contact: QIN Yuhai E-mail:13840392578@163.com

摘要:

针对恶意挖矿网页检测技术存在的漏报率高、时效性低、预测不准、过于依赖规则等问题,文章设计了基于多特征识别的恶意挖矿网页检测模型和多层级证据保存的恶意挖矿网页取证方法。该检测模型通过对Coinhive、Jsecoin、Webmine、Crypto-loot四种挖矿网页的实现方式、代码特点分析,归纳总结其特征,构建出挖矿网页的多特征序列,实现对恶意挖矿网页的自动检测。研究表明,该检测模型能够对用户提交的URL进行自动检测,区分出恶意挖矿网页并判断出其类型,整体检测准确率达到97.83%。多层级取证方法能够从平面层、代码层、网络数据层三个维度对恶意挖矿网页数据进行固定,获取完整、合法、可信的证据,生成取证报告,满足公安机关对恶意挖矿网页检测和取证的需求。

关键词: 恶意挖矿, 网页挖矿, 检测, 取证

Abstract:

In view of the current domestic and foreign malicious mining Web detection technology has a high failure rate, low timeliness, inaccurate prediction, too dependent on rules and other problems, this paper designed a malicious mining web detection model based on multi-feature recognition and multi-level evidence preservation of malicious mining web forensic method. Through analyzing the implementation methods and code characteristics of Coinhive, Jsecoin, Webmine and Crypto-loot mining Web pages, and summarizing their characteristics, the detection model constructed the multi-feature sequence of mining Web pages to realize the automatic detection of malicious mining Web pages. The research shows that the detection model can automatically detect the URLs submitted by users, distinguish malicious mining Web pages and determine their types, and the overall detection accuracy reaches 97.83%. The multi-level forensics method can fix the malicious mining Web page data from the three dimensions of plane layer, code layer and network data layer, obtain complete, legal and credible evidence, generate the forensics report, and meet the public security organs' requirements for malicious mining Web page detection and forensics.

Key words: malicious mining, Web mining, detection, forensics

中图分类号: