Title :
Malicious Data Leak Prevention and Purposeful Evasion Attacks: An approach to Advanced Persistent Threat (APT) management
Author :
Mustafa, Tarique
Author_Institution :
nexTier Networks, Inc., Santa Clara, CA, USA
Abstract :
Existing Data Leak Prevention (DLP) solutions are inherently incapable of scaling beyond trivial scenarios of “Accidental Data Leak” wherein no “Purposeful Evasion Attack” is encountered. Nevertheless, these attacks can render a DLP system completely useless (or greatly depreciate the effectiveness/usefulness of any DLP solution). A true DLP solution, therefore, must support “Malicious Data Leak Prevention” capability wherein “Purposeful Evasion Attacks” can be effectively detected and prevented. With the advent of Advanced Persistent Threats (APTs) against Information Security and DLP Systems, “Purposeful Evasion Attacks” have emerged as the most sophisticated class of threats against DLP solutions. Unfortunately, “Purposeful Evasion Attacks” have also remained un-addressed in their most basic forms. This paper presents (1) an insight into the lifecycle of APTs launched against Information Security and DLP systems, (2) a classification of real-life “Purposeful Evasion Attacks” against Information Security and DLP systems, (3) a reference model for enabling Malicious Data Leak Prevention (called 3-D Correlation Paradigm).
Keywords :
security of data; 3D correlation paradigm; APT management; DLP systems; accidental data leak; advanced persistent threat management; information security; malicious data leak prevention; purposeful evasion attacks; Classification algorithms; Context; Correlation; Fingerprint recognition; Information security; Pattern matching; APT; Advanced Persistent Threat; Data Leak Prevention; Egress Control; Evasion Attack; False Negative; Information Security; Malicious DLP;
Conference_Titel :
Electronics, Communications and Photonics Conference (SIECPC), 2013 Saudi International
Conference_Location :
Fira
Print_ISBN :
978-1-4673-6196-5
Electronic_ISBN :
978-1-4673-6194-1
DOI :
10.1109/SIECPC.2013.6551028