The global higher education sector has seen a sharp increase in potentially damaging cryptocurrency mining behaviours with universities the target of more than half of known attacks. Academic networks in Asian countries are the most heavily targeted, followed by institutions in North America and Europe, a new report has found.
Cryptocurrency mining is the process of generating cryptocurrencies such as Bitcoin. Encryption is used to generate and transfer funds – hence the term cryptocurrency.
There is no central authority over the generation of the currencies, which instead are created by individuals – miners – who are competing to create blocks of transactions and append them to a blockchain, for which they get rewarded. The task requires solving complex mathematical calculations called proof of work, and its complexity is meant to prevent devaluation of the currency.
As the value of cryptocurrencies rise, hackers exploit laxer controls of university computer networks to mine cryptocurrencies. Attacks can include leveraging devices “for external gain, such as Bitcoin mining or outbound spam", according to the report from Vectra Networks, a United States company whose products monitor network traffic for cyberattacks while they are in progress.
These early threat indicators usually precede other stages of an attack and are often associated with opportunistic botnet behaviours, explained Vectra’s 2018 RSA Conference Edition of its Attacker Behavior Industry Report published on 29 March.
Botnet activity controlled by malware occurs most often in higher education, with 151 detections per 10,000 devices – five-times the industry average of 33 detections per 10,000 devices, the report said.
Vectra’s traffic analysis and meta-data from more than 4.5 million devices, customer cloud, data-centres and enterprises across 14 industries during August 2017 to January 2018, found that higher education is a fertile field for growing crypto-mining attacks – 60% of cryptocurrency mining detections occurred in higher education, followed by entertainment and leisure (6%), financial services (3%), technology (3%) and healthcare (2%).
Asian hotspots
Open computer networks consisting of more than two million devices at some 100 Asian universities were targeted, with hotspots in Singapore, Japan and South Korea.
The region accounts for three-quarters of known crypto-mining detections. This is followed by North America (20%) with California, Texas and Ontario reported to be top crypto-mining locations, and Europe (4%) with hotspots in Croatia, the United Kingdom and Belgium, according to Vectra.
"This is not surprising as Asia has long been one of Bitcoin’s biggest supporters with Japan, South Korea and Singapore being the world’s largest Bitcoin market," ICT expert Hamza Alfrmawi told University World News. "Crypto-mining activities on universities’ open networks make them work abnormally slowly and make it easy to be attacked by cyber-criminals," he said.
Mining overall has surged with the rising price of cryptocurrencies. The value of Bitcoin, for instance, peaked at US$19,000 in January 2018.
In one example that recently came to light, researchers at another cybersecurity company, California-based AlienVault, identified a mysterious cryptocurrency miner sending any mined currencies to Kim Il Sung University in Pyongyang, North Korea, according to a Reuters news agency report from Seoul, South Korea, published in January.
Universities are a soft target
"Higher education is a prime arena given that students are usually not protected by universities’ open networks,” Vectra said. "Free electrical power and internet access for students might account for the spike in higher education."
Although not considered by experts to be as dangerous as a targeted cyberattack, cryptocurrency mining still puts personally identifiable information, protected health information and financial data at risk, says Vectra.
"As universities have the ideal conditions for crypto-jackers including large student populations and internet-linked computing resources with weak security controls, awareness programmes must be organised for students about phishing emails, suspicious websites and web ads, as well as ways to protect universities' open networks by installing operating system patches," Alfrmawi said.
"Students’ online activities through the use of untrusted websites that host crypto-mining malware could represent the indirect weak backdoor to attack universities' high-bandwidth capacity networks," Alfrmawi said.
Source link: http://www.universityworldnews.com/article.php?story=20180405143533700 | https://www.google.co.in/search?rlz=1C1CHBF_enIN790IN790&biw=1350&bih=594&tbm=isch&sa=1&ei=2pzUWpv4I4flvgSQ8oHADA&q=Cryptocurren





