{"id":"https://openalex.org/W4288057763","doi":"https://doi.org/10.1109/sp46214.2022.9833803","title":"Robbery on DevOps: Understanding and Mitigating Illicit Cryptomining on Continuous Integration Service Platforms","display_name":"Robbery on DevOps: Understanding and Mitigating Illicit Cryptomining on Continuous Integration Service Platforms","publication_year":2022,"publication_date":"2022-05-01","ids":{"openalex":"https://openalex.org/W4288057763","doi":"https://doi.org/10.1109/sp46214.2022.9833803"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp46214.2022.9833803","pdf_url":null,"source":{"id":"https://openalex.org/S4363606603","display_name":"2022 IEEE Symposium on Security and Privacy (SP)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100382323","display_name":"Zhi Li","orcid":"https://orcid.org/0000-0002-9510-1888"},"institutions":[{"id":"https://openalex.org/I47720641","display_name":"Huazhong University of Science and Technology","ror":"https://ror.org/00p991c53","country_code":"CN","type":"education","lineage":["https://openalex.org/I47720641"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhi Li","raw_affiliation_strings":["Huazhong Univ. of Sci. & Tech,School of Cyber Science and Engineering,China","National Engineering Research Center for Big Data Tech. and Sys., Cluster and Grid Computing Lab, Services Computing Tech. and Sys. Lab, and Big Data Security Engineering Research Center, Huazhong Univ. of Sci. & Tech, China","School of Computer Science and Technology, Huazhong Univ. of Sci. & Tech, China"],"affiliations":[{"raw_affiliation_string":"National Engineering Research Center for Big Data Tech. and Sys., Cluster and Grid Computing Lab, Services Computing Tech. and Sys. Lab, and Big Data Security Engineering Research Center, Huazhong Univ. of Sci. & Tech, China","institution_ids":[]},{"raw_affiliation_string":"Huazhong Univ. of Sci. & Tech,School of Cyber Science and Engineering,China","institution_ids":["https://openalex.org/I47720641"]},{"raw_affiliation_string":"School of Computer Science and Technology, Huazhong Univ. of Sci. & Tech, China","institution_ids":["https://openalex.org/I47720641"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100668780","display_name":"Weijie Liu","orcid":"https://orcid.org/0000-0002-3054-766X"},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Weijie Liu","raw_affiliation_strings":["Indiana University Bloomington, USA"],"affiliations":[{"raw_affiliation_string":"Indiana University Bloomington, USA","institution_ids":["https://openalex.org/I4210119109"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100452321","display_name":"Hongbo Chen","orcid":"https://orcid.org/0000-0001-9922-4351"},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Hongbo Chen","raw_affiliation_strings":["Indiana University Bloomington, USA"],"affiliations":[{"raw_affiliation_string":"Indiana University Bloomington, USA","institution_ids":["https://openalex.org/I4210119109"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100333259","display_name":"Xiaofeng Wang","orcid":"https://orcid.org/0000-0003-0091-3865"},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"XiaoFeng Wang","raw_affiliation_strings":["Indiana University Bloomington, USA"],"affiliations":[{"raw_affiliation_string":"Indiana University Bloomington, USA","institution_ids":["https://openalex.org/I4210119109"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5084889167","display_name":"Xiaojing Liao","orcid":"https://orcid.org/0000-0001-7555-1673"},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Xiaojing Liao","raw_affiliation_strings":["Indiana University Bloomington, USA"],"affiliations":[{"raw_affiliation_string":"Indiana University Bloomington, USA","institution_ids":["https://openalex.org/I4210119109"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5036446600","display_name":"Luyi Xing","orcid":"https://orcid.org/0000-0002-1036-1163"},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Luyi Xing","raw_affiliation_strings":["Indiana University Bloomington, USA"],"affiliations":[{"raw_affiliation_string":"Indiana University Bloomington, USA","institution_ids":["https://openalex.org/I4210119109"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5002143912","display_name":"Mingming Zha","orcid":"https://orcid.org/0000-0002-7827-9369"},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Mingming Zha","raw_affiliation_strings":["Indiana University Bloomington, USA"],"affiliations":[{"raw_affiliation_string":"Indiana University Bloomington, USA","institution_ids":["https://openalex.org/I4210119109"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5065741507","display_name":"Hai Jin","orcid":"https://orcid.org/0009-0003-8055-3587"},"institutions":[{"id":"https://openalex.org/I47720641","display_name":"Huazhong University of Science and Technology","ror":"https://ror.org/00p991c53","country_code":"CN","type":"education","lineage":["https://openalex.org/I47720641"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hai Jin","raw_affiliation_strings":["Huazhong Univ. of Sci. & Tech,School of Computer Science and Technology,China","National Engineering Research Center for Big Data Tech. and Sys., Cluster and Grid Computing Lab, Services Computing Tech. and Sys. Lab, and Big Data Security Engineering Research Center, Huazhong Univ. of Sci. & Tech, China"],"affiliations":[{"raw_affiliation_string":"Huazhong Univ. of Sci. & Tech,School of Computer Science and Technology,China","institution_ids":["https://openalex.org/I47720641"]},{"raw_affiliation_string":"National Engineering Research Center for Big Data Tech. and Sys., Cluster and Grid Computing Lab, Services Computing Tech. and Sys. Lab, and Big Data Security Engineering Research Center, Huazhong Univ. of Sci. & Tech, China","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5074676946","display_name":"Deqing Zou","orcid":"https://orcid.org/0000-0001-8534-5048"},"institutions":[{"id":"https://openalex.org/I47720641","display_name":"Huazhong University of Science and Technology","ror":"https://ror.org/00p991c53","country_code":"CN","type":"education","lineage":["https://openalex.org/I47720641"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Deqing Zou","raw_affiliation_strings":["Huazhong Univ. of Sci. & Tech,School of Cyber Science and Engineering,China","National Engineering Research Center for Big Data Tech. and Sys., Cluster and Grid Computing Lab, Services Computing Tech. and Sys. Lab, and Big Data Security Engineering Research Center, Huazhong Univ. of Sci. & Tech, China"],"affiliations":[{"raw_affiliation_string":"Huazhong Univ. of Sci. & Tech,School of Cyber Science and Engineering,China","institution_ids":["https://openalex.org/I47720641"]},{"raw_affiliation_string":"National Engineering Research Center for Big Data Tech. and Sys., Cluster and Grid Computing Lab, Services Computing Tech. and Sys. Lab, and Big Data Security Engineering Research Center, Huazhong Univ. of Sci. & Tech, China","institution_ids":[]}]}],"institution_assertions":[],"countries_distinct_count":2,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":2.955,"has_fulltext":false,"cited_by_count":12,"citation_normalized_percentile":{"value":0.99968,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":92,"max":93},"biblio":{"volume":null,"issue":null,"first_page":"2397","last_page":"2412"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10270","display_name":"Blockchain Technology Applications and Security","score":0.9987,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10270","display_name":"Blockchain Technology Applications and Security","score":0.9987,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.998,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9956,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/devops","display_name":"DevOps","score":0.94336855}],"concepts":[{"id":"https://openalex.org/C9903902","wikidata":"https://www.wikidata.org/wiki/Q3025536","display_name":"DevOps","level":3,"score":0.94336855},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.55345106},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.47261503},{"id":"https://openalex.org/C2780378061","wikidata":"https://www.wikidata.org/wiki/Q25351891","display_name":"Service (business)","level":2,"score":0.43881878},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.31962308},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.114905745},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.09821054},{"id":"https://openalex.org/C162853370","wikidata":"https://www.wikidata.org/wiki/Q39809","display_name":"Marketing","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp46214.2022.9833803","pdf_url":null,"source":{"id":"https://openalex.org/S4363606603","display_name":"2022 IEEE Symposium on Security and Privacy (SP)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Decent work and economic growth","score":0.56,"id":"https://metadata.un.org/sdg/8"}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":26,"referenced_works":["https://openalex.org/W1985247771","https://openalex.org/W2170467352","https://openalex.org/W2290426788","https://openalex.org/W2552182158","https://openalex.org/W2733244695","https://openalex.org/W2887682444","https://openalex.org/W2890228473","https://openalex.org/W2890978676","https://openalex.org/W2897385569","https://openalex.org/W2899118382","https://openalex.org/W2899822557","https://openalex.org/W2911975451","https://openalex.org/W2920526824","https://openalex.org/W2932551155","https://openalex.org/W2941922059","https://openalex.org/W2963603877","https://openalex.org/W2976499200","https://openalex.org/W2980839873","https://openalex.org/W2983931619","https://openalex.org/W2986642681","https://openalex.org/W3002277530","https://openalex.org/W3024201913","https://openalex.org/W3048711002","https://openalex.org/W3104717442","https://openalex.org/W3113493392","https://openalex.org/W3197565351"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W4287554096","https://openalex.org/W4282831387","https://openalex.org/W4220665054","https://openalex.org/W3154253302","https://openalex.org/W3113480566","https://openalex.org/W3111012486","https://openalex.org/W3101146292","https://openalex.org/W2899084033","https://openalex.org/W2748952813"],"abstract_inverted_index":{"The":[0],"recent":[1],"wave":[2],"of":[3,14,21,134,155,171,188,198,219,236,274,281],"in-browser":[4,64],"cryptojacking":[5,199],"has":[6,104,268],"ebbed":[7],"away,":[8],"due":[9],"to":[10,76,105,115,131,160,202,212,216,223,231],"the":[11,19,98,102,117,124,132,153,161,167,169,172,186,189,217,226,260,272],"new":[12],"updates":[13],"mainstream":[15,146],"cryptocurrrencies,":[16],"which":[17],"demand":[18],"level":[20],"mining":[22,100,112,173,227],"resources":[23],"browsers":[24],"cannot":[25],"afford.":[26],"As":[27],"replacements,":[28],"resource-rich,":[29],"loosely":[30],"protected":[31],"free":[32],"Internet":[33],"services,":[34],"such":[35,82,107],"as":[36,68,83,108,177,245],"Continuous":[37],"Integration":[38],"(CI)":[39],"platforms,":[40,129,168],"have":[41],"become":[42],"attractive":[43],"targets.":[44],"In":[45,93],"this":[46],"paper,":[47],"we":[48,96,205],"report":[49],"a":[50,207,220,234,285],"systematic":[51],"study":[52,151],"on":[53,57,127,144,233,247,271],"real-world":[54],"illicit":[55],"cryptomining":[56],"public":[58],"CI":[59,69,80,128,147,221,252,275,282],"platforms":[60],"(called":[61],"Cijacking).":[62],"Unlike":[63],"cryptojacking,":[65],"Cijacks":[66],"masquerade":[67],"jobs":[70,174,228,276,283],"and":[71,87,111,123,180,243,250,277],"are":[72],"therefore":[73],"more":[74],"difficult":[75],"detect,":[77],"since":[78],"legitimate":[79],"workflows":[81],"container":[84],"image":[85],"building":[86],"testing":[88],"also":[89],"entail":[90],"intensive":[91],"computing.":[92],"our":[94,150,256],"research,":[95],"leveraged":[97],"critical":[99],"information":[101],"adversary":[103],"specify,":[106],"wallet":[109],"addresses":[110],"pool":[113],"domains,":[114],"recover":[116],"attack":[118,156],"traces":[119],"from":[120],"GitHub":[121],"repositories":[122],"log":[125],"files":[126],"leading":[130],"discovery":[133],"1,974":[135],"Cijacking":[136],"instances,":[137],"30":[138],"campaigns":[139],"across":[140],"12":[141],"different":[142],"cryptocurrencies":[143],"11":[145],"platforms.":[148],"Further,":[149],"unveils":[152],"evolution":[154],"strategies,":[157],"in":[158,164],"response":[159],"protection":[162],"put":[163],"place":[165],"by":[166],"duration":[170],"(as":[175],"long":[176],"33":[178],"months),":[179],"their":[181],"lifecycle.":[182],"Further":[183],"discovered":[184],"is":[185,200],"revenue":[187],"attack,":[190],"over":[191],"${\\$}$20,000":[192],"per":[193],"month.":[194],"Since":[195],"robust":[196],"detection":[197],"known":[201],"be":[203],"hard,":[204],"developed":[206],"novel":[208],"technique,":[209],"called":[210],"Cijitter,":[211],"strategically":[213],"inject":[214],"delays":[215],"execution":[218],"workflow":[222],"disproportionally":[224],"penalize":[225],"that":[229,255],"need":[230],"work":[232],"series":[235],"tasks":[237],"under":[238],"time":[239],"constraints.":[240],"Our":[241],"analysis":[242],"evaluation,":[244],"conducted":[246],"both":[248],"benchmarks":[249],"common":[251],"jobs,":[253],"show":[254],"approach":[257],"substantially":[258],"suppresses":[259],"miner's":[261],"revenues,":[262],"rendering":[263],"them":[264],"unprofitable,":[265],"but":[266],"only":[267],"small":[269],"impacts":[270],"performance":[273],"developer":[278],"productivity":[279],"(94.3%":[280],"see":[284],"less":[286],"than":[287],"10%":[288],"delay).":[289]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4288057763","counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":9},{"year":2022,"cited_by_count":2}],"updated_date":"2024-12-20T09:29:56.524163","created_date":"2022-07-28"}