检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:傅继晗 沈炜 FU Ji-han;SHEN Wei(School of Information Science and Technology,Zhejiang Sci-Tech University,Hangzhou 310018,China)
出 处:《软件导刊》2022年第11期110-115,共6页Software Guide
摘 要:随着整治虚拟货币“挖矿”活动的开展,一些利用显卡、硬盘等主动挖矿的行为已得到有效遏制,但通过网页挖矿劫持攻击达到挖矿目的的被动挖矿行为,由于其具有容易入侵、隐秘性强的特点,用户难以察觉。为了能自动判断这种被动挖矿行为,以一个被植入挖矿程序的网站为例,提出基于Chrome DevTools Protocol的特征分析方法,分别通过抓取websocket流量和CPU导出性能剖析报告进行分析与判断。经过验证,该方法可有效检测与判断网页挖矿劫持攻击行为,具有一定的参考价值。With the regulation of virtual currency "mining" activities,some active mining behaviors such as using graphics cards and hard disk mining have been effectively curbed,but the passive mining behaviors that achieve the purpose of mining through web mining hijacking attacks are difficult to be detected by users because of their easy invasion and stealthy characteristics. In order to automatically judge the passive mining beharior,take a website embedded with a mining program as an example,proposes a feature analysis method based on Chrome DevTools Protocol to analyze and judge the websocket traffic and export CPU performance profiling report respectively. After verification,This method can effectively detect and judge web mining hijacking attacks,it has certain reference value.
分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:3.140.184.203