CESNET / Nemea-Detectors

Detection modules of the Nemea system.
Other
21 stars 14 forks source link

Miner detector does not detect minergate.com #33

Open thorgrin opened 5 years ago

thorgrin commented 5 years ago

i've been running miner_detector in order to detect connection to the minergate pool at xmr.pool.minergate.com:45560. However, even when I lowered the threshold to 7 (default was 9, the readme seems to be outdated), it did not detect the communication. Moreover, I was running tcpdump the whole time looking for communication to the port 45560 and it seems that the active stratum check was never performed.

I think that this module needs to be updated so that it detects current crypto miners, otherwise it is of no use to anybody.

thorgrin commented 5 years ago

Oh, and the miner that was used for this test was https://github.com/lucasjones/cpuminer-multi

thorgrin commented 5 years ago

I've tried another miner software wit the same effect: https://minergate.com/downloads/gui

On the other hand, there are so many false positive checks, that my collector gets blocked by firewalls.