惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

爱范儿
爱范儿
MyScale Blog
MyScale Blog
Recent Announcements
Recent Announcements
N
Netflix TechBlog - Medium
GbyAI
GbyAI
Vercel News
Vercel News
The GitHub Blog
The GitHub Blog
阮一峰的网络日志
阮一峰的网络日志
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
Visual Studio Blog
Martin Fowler
Martin Fowler
腾讯CDC
大猫的无限游戏
大猫的无限游戏
aimingoo的专栏
aimingoo的专栏
云风的 BLOG
云风的 BLOG
J
Java Code Geeks
WordPress大学
WordPress大学
P
Proofpoint News Feed
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
有赞技术团队
有赞技术团队
人人都是产品经理
人人都是产品经理
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Y
Y Combinator Blog

Datadog | The Monitor blog

Introducing our open source AI-native SAST Instrument and monitor Boomi integration flows with OpenTelemetry and Datadog Not all index scans are equal: How we cut query latency by over 99% Platform engineering metrics: What to measure and what to ignore Integrate Recorded Future threat intelligence with Datadog Cloud SIEM CI/CD security: threat modeling using a MITRE-style threat matrix CI/CD security: How to secure your GitHub ecosystem Ingress NGINX is EOL: A practical guide for migrating to Kubernetes Gateway API Operating agentic AI with Amazon Bedrock AgentCore and Datadog LLM Observability: Lessons from NTT DATA Introducing the Datadog Code Security MCP Capture and analyze custom heatmaps in Session Replay Understand session replays faster with AI summaries and smart chapters Monitor ClickHouse query performance with Datadog Database Monitoring How we designed empathetic alert sounds for on-call engineers Search and act across Datadog to resolve issues faster with Bits Assistant Measure the business impact of every product change with Datadog Experiments Analyzing round trip query latency Configuring JavaScript caches for better performance Introducing Bits AI Dev Agent for Code Security Datadog achieves ISO 42001 certification for responsible AI Monitor Nutanix clusters, hosts, and VMs with Datadog Monitor Juniper Mist in Datadog A new Host Map for modern infrastructure Annotate traces to improve LLM quality with Datadog LLM Observability What’s new in Cloud SIEM: AI-powered investigations, enhanced threat intelligence, and scalable security operations Explore Kubernetes with native OpenTelemetry data Monitor Oracle Fusion Cloud Applications with Datadog Announcing the Datadog Terraform provider v4.0.0 Scaling Kubernetes workloads on custom metrics How to design cloud environments for AI-powered threat analysis
Detect cryptocurrency mining in your environment with Dat...
Mallory Mooney, Dany Kanes, Partha Naidu · 2022-04-27 · via Datadog | The Monitor blog
Mallory Mooney

Mallory Mooney

Dany Kanes

Dany Kanes

Partha Naidu

Partha Naidu

Product Manager

Cryptocurrency mining (or crypto mining) can be a lucrative yet resource-intensive operation, so cyber threat actors are targeting more organizations in order to take advantage of their cloud resources for mining. Datadog Cloud SIEM can now help you monitor your cloud-based systems for unwanted crypto mining via a built-in detection rule. All you need to get started is to configure your resource logs with Datadog’s @network.client.ip standard attribute.

Crypto mining attacks, known as resource hijacking, can quickly produce a significant amount of strain on servers and cloud-based systems, leading to hundreds of thousands of dollars in unexpected computing costs. Datadog’s crypto mining detection rule scans log data from all your cloud resources for activity from IP or domain addresses that are known to be associated with a mining server or pool.

Accelerate investigations and find the source of mining activity

Once the rule is enabled, Datadog Cloud SIEM will generate a security signal as soon as it detects a flagged IP or domain in your logs. Each signal provides key insights about affected hosts, such as performance metrics and a list of running processes. You can leverage this information to investigate additional signs of mining activity in your environment, such as sudden spikes in a host’s CPU or RAM usage or several hosts suddenly running the same unauthorized process.

View the CPU metrics associated with crypto mining

The example signal above shows a significant spike in CPU usage for a host that Datadog determined was communicating with a crypto mining server. If a particular host does not typically execute CPU-intensive operations, the sudden increase may indicate that an attacker has successfully installed a mining client and is actively using it. You can confirm your theory by pivoting to related processes running on the affected host in order to search for any that are unexpected or unauthorized. For example, you might observe a tool like apt-get downloading a shell script from an unknown IP address. This type of activity can be the initial sign of a threat actor attempting to download a cryptominer onto a host.

Pivot to related processes to search for suspicious activity

Identifying the processes associated with a cryptominer can also help you determine the scope of an attack. For example, a threat actor may only run cryptominers on a few compromised hosts at a time in order to avoid detection. You can easily search for other hosts that are running the same suspicious processes in order to determine which ones are compromised. To mitigate this kind of activity, you can kill unauthorized processes and remove associated clients from compromised hosts. You can also block a threat actor from your environment by adding the IP or domain address captured in the signal to your firewall’s deny list, which reduces the risk of another attack from the same source.

Fine-tune rules with suppression lists

Datadog suppression lists enable you to reduce false positives by controlling when security signals are generated for mining activity. For example, some organizations may support legitimate cryptocurrency applications or services, so activity from these sources should not generate a signal. You can account for these use cases by adding a suppression list to the crypto mining rule, which will prevent it from triggering security signals for specific hosts, environments, or IP addresses.

Add suppression lists to your crypto mining detection rules.

The example list above includes a group of environments that are used for testing new features for a cryptocurrency application, which would otherwise be flagged as malicious activity because it is associated with mining servers.

Detect cryptocurrency mining with Datadog

Datadog Cloud SIEM enables you to quickly catch signs of unwanted mining activity in your environment, so you can protect your cloud resources, maintain application performance, and prevent unexpected costs. To learn more about the crypto mining detection rule, as well as our other available rules, check out our documentation. If you don’t already have a Datadog account, you can sign up for a free 14-day trial.