Fusão de Características em Espaços Vetoriais para Detecção Estática de Cryptojacking em WebAssembly
Resumo
A proliferação do WebAssembly (Wasm) tem impulsionado campanhas de cryptojacking cujos binários opacos burlam a detecção convencional. Este artigo propõe um método de análise estática baseado na fusão de características em espaços vetoriais: a Árvore de Sintaxe Abstrata do binário é segmentada em fragmentos funcionais (chunks), e embeddings semânticos são fundidos a métricas estruturais determinísticas associadas a rotinas de Proof-of-Work. Três estratégias independentes operam sobre a base vetorial resultante: similaridade topológica, aprendizado supervisionado e inferência zero-shot via LLM. A avaliação em 74 binários, totalizando 53.888 fragmentos, demonstrou que a classificação agregada via SVM Linear atinge um F1-Score de 0,95, enquanto a triagem topológica alcança um MRR de 0,92 com latência sub-segundo e invariante ao tamanho do binário, permitindo tanto a triagem síncrona em larga escala quanto a auditoria forense assíncrona, sem a necessidade de instrumentação dinâmica.
Referências
Cao, S., He, N., Guo, Y., and Wang, H. (2024). Wasmixer: Binary obfuscation for webassembly. In Computer Security – ESORICS 2024. Springer.
Chawla, N. V., Bowyer, K. W., Hall, L. O., and Kegelmeyer, W. P. (2002). Smote: synthetic minority over-sampling technique. Journal of artificial intelligence research, 16:321–357.
Cortes, C. and Vapnik, V. (1995). Support-vector networks. Machine learning, 20(3):273–297.
Cside (2025). Cryptojacking is dead: long live cryptojacking. acessado em 15-10-2025.
Géron, A. (2022). Hands-on machine learning with Scikit-Learn, Keras, and TensorFlow. ”O’Reilly Media, Inc.”.
Haas, A., Rossberg, A., Schuff, D. L., Titzer, B. L., Holman, M., Gohman, D., Wagner, L., Zakai, A., and Bastien, J. (2017). Bringing the web up to speed with webassembly. SIGPLAN Not., 52(6):185–200.
Harnes, H. and Morrison, D. (2024a). Cryptic bytes: Webassembly obfuscation for evading cryptojacking detection. arXiv preprint arXiv:2403.15197.
Harnes, H. and Morrison, D. (2024b). Sok: Analysis techniques for webassembly. Future Internet, 16(3):84.
Hoffman, K. (2019). Programming WebAssembly with Rust: unified development for web, mobile, and embedded applications. The Pragmatic Bookshelf.
Hong, G., Yang, Z., Yang, S., Zhang, L., Nan, Y., Zhang, Z., Yang, M., Zhang, Y., Qian, Z., and Duan, H. (2018). How you get shot in the back: A systematical study about cryptojacking in the real world. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, CCS ’18, page 1701–1713, New York, NY, USA. Association for Computing Machinery.
Kharraz, A., Ma, Z., Murley, P., Lever, C., Mason, J., Miller, A., Borisov, N., Antonakakis, M., and Bailey, M. (2019). Outguard: Detecting in-browser covert cryptocurrency mining in the wild. In The World Wide Web Conference, WWW ’19, page 840–852, New York, NY, USA. Association for Computing Machinery.
Konoth, R. K., Vineti, E., Moonsamy, V., Lindorfer, M., Kruegel, C., Bos, H., and Vigna, G. (2018). Minesweeper: An in-depth look into drive-by cryptocurrency mining and its defense. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, CCS ’18, page 1714–1730, New York, NY, USA. Association for Computing Machinery.
Loose, N., Mächtle, F., Pott, C., Bezsmertnyi, V., and Eisenbarth, T. (2023). Madvex: instrumentation-based adversarial attacks on machine learning malware detection. In International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, pages 69–88. Springer.
Ma, W., Liu, S., Lin, Z., Wang, W., Hu, Q., Liu, Y., Zhang, C., Nie, L., Li, L., and Liu, Y. (2023). Lms: Understanding code syntax and semantics for code analysis. arXiv preprint arXiv:2305.12138.
Malkov, Y. A. and Yashunin, D. A. (2018). Efficient and robust approximate nearest neighbor search using hierarchical navigable small world graphs. IEEE transactions on pattern analysis and machine intelligence, 42(4):824–836.
Musch, M., Wressnegger, C., Johns, M., and Rieck, K. (2019). Thieves in the browser: Web-based cryptojacking in the wild. In Proceedings of the 14th International Conference on Availability, Reliability and Security, ARES ’19, New York, NY, USA. Association for Computing Machinery.
Naseem, F. N., Aris, A., Babun, L., Tekiner, E., and Uluagac, A. S. (2021). Minos: A lightweight real-time cryptojacking detection system. In NDSS.
Pan, J. J., Wang, J., and Li, G. (2023). Survey of vector database management systems. arXiv preprint arXiv:2310.14021.
Pedregosa, F., Varoquaux, G., Gramfort, A., Michel, V., Thirion, B., Grisel, O., Blondel, M., Prettenhofer, P., Weiss, R., Dubourg, V., et al. (2011). Scikit-learn: Machine learning in python. Journal of Machine Learning Research, 12:2825–2830.
Peng, J. and outros (2025). Wasmguard: Enhancing web security through robust raw-binary detection of webassembly malware. In Proceedings of the ACM Web Conference 2025 (WWW ’25). ACM.
Perrone, G. and Romano, S. P. (2025). Webassembly and security: a review. Computer Science Review, 56:100728.
QDRANT (2026). Qdrant: High-performance vector search engine. Qdrant Technologies. Versão 1.18.
Romano, A., Zheng, Y., and Wang, W. (2020). Minerray: Semantics-aware analysis for ever-evolving cryptojacking detection. In Proceedings of the 35th IEEE/ACM International Conference on Automated Software Engineering, pages 1129–1140.
Sonic Wall (2024). Sonicwall cyber threat report. [link]. acessado em 17-Dez-2024.
Taipalus, T., Grahn, H., Turtiainen, H., and Costin, A. (2024). Utilizing vector database management systems in cyber security. In Proceedings of the 23th European Conference on Cyber Warfare and Security. Academic Conferences International Ltd.
Xia, Y., He, P., Zhang, X., Liu, P., Ji, S., and Wang, W. (2023). Static semantics reconstruction for enhancing javascript-webassembly multilingual malware detection. In European Symposium on Research in Computer Security, pages 255–276. Springer.
