| CPC H04L 63/145 (2013.01) [H04L 63/1416 (2013.01); H04L 63/1425 (2013.01)] | 18 Claims |

|
1. A method for identifying a malicious mining behavior, comprising:
obtaining operation data corresponding to a target operation, on capturing of the target operation;
extracting a wallet address from the operation data to obtain a wallet address set;
obtaining data of a network outgoing connection for external access, and determining whether the data of the network outgoing connection comprises a wallet address belonging to the wallet address set; and
determining that the data of the network outgoing connection corresponds to the malicious mining behavior, on determining that the data of the network outgoing connection comprises a wallet address belonging to the wallet address set.
|