4 ms·
We, a medium-sized hosting provider, just do it using the process name. Works much better than you'd expect, since most miners are using very similar software.
by luto 6y ago
We, a medium-sized hosting provider, just do it using the process name. Works much better than you'd expect, since most miners are using very similar software. No interesting engineering challenge here, sadly.
- plasma 6y agoWonder if you could check the repeated use of cryptographic functions in a process as a sign.
- ant6n 6y agoDo miners heavily rely on crush instructions? Then it could perhaps be possible to reduce the performance of these instructions 100-fold, making mining useless but other code still run.
- nostoc 6y agoAs a bonus, you'll also see ransomwares, disk encryption software, http servers, browsers... And what if the miner uses it's own crypto lib, and doesn't rely on the OS crypto API?
- londons_explore 6y agoSsssh.... If you tell everyone that's what you do, people will just rename the binary... The trick to protections like this is to not tell anyone how they work, and to run them only occasionally. Ie. once a week, ban half of users who are running xmrig.exe. Also include users who signed up with the same email address, phone number or IP address as the detected users and who have a consistently high CPU use - these are probably successful bypasses of your simple process name based filter. That way bad actors have a very hard time figuring out exactly what your protections are or how they work. If they were to get an immediate ban as soon as they fired up xmrig.exe, then they'd quickly think to rename it or recompile it or run it under wine or a host of other ideas. Yet having a random selection of their accounts banned seemingly at random means they learn nothing. Obviously you need a process for users accidentally caught in the net to get their accounts reactivated, and if you're a service like githuib you should probably let the user have a grace period to do that before killing their entire business...
- luto 6y agoGood luck finding that post and linking it to the provider. That set aside, except for DDoS defense, we've run into no problems at all when talking very openly about how we operate. Seems naive at first glance, but we've had a good 10+ year run (so far!). Works for us, might not for others.
- faeyanpiraat 6y agoDelayed banning seems to work well for multiplayer game anti cheat systems (like VAC). These problems are essentially the same, some of the know-how can be easily adapted between them.
- thaumasiotes 6y ago> Good luck finding that post and linking it to the provider. No need to link it to the provider. If one provider does things that way, you want to block their method. (And, of course, the odds are overwhelming that the other providers are doing the same thing.)
- frenchman99 6y agoIt seems like a Whois search about the domain that's in your Hacker News profile yields lots of interesting information. Your previous comments seem to indicate that's a provider you work for. Maybe it's not related though. Or maybe it's just a way of doing PR. I know nothing.
- vntok 6y agoSo if you only ban half of illegitimate accounts once a week, does this mean I just need to launch my mining code registration scripts also once a week, ideally just after I see some of my accounts have been banned? And doing this will get me a full week's of free mining on half my miners (if I'm the only one in the world pursuing this strategy) or most of my miners if the banning campaign is capped and also hits other abusers? It sounds like a great deal, honestly.
- londons_explore 6y ago
- jfoster 6y agoYou could also just address it through your rate table by appropriately pricing for intense workloads, couldn't you?
- luto 6y agoWe're offering shared hosting for web apps and other hacker/toy projects. Intense compute workloads are just not what our product is built for, so we let other providers handle that part of the market.
- jfoster 6y agoThat's what I mean. So make it very expensive to run them on your service and the coin miners will go elsewhere.
- luto 6y agoWe're aiming to make our service accessible to everyone, which involves customers choosing their own price. So there isn't a fixed price we could raise. Additionally, there is a free trial month, which adversaries typically make use of, instead of paying for the service. Hiking he price without deep additional changes is not in our interest and wouldn't change anything in our case.