DocumentCode
614409
Title
Malicious Data Leak Prevention and Purposeful Evasion Attacks: An approach to Advanced Persistent Threat (APT) management
Author
Mustafa, Tarique
Author_Institution
nexTier Networks, Inc., Santa Clara, CA, USA
fYear
2013
fDate
27-30 April 2013
Firstpage
1
Lastpage
5
Abstract
Existing Data Leak Prevention (DLP) solutions are inherently incapable of scaling beyond trivial scenarios of “Accidental Data Leak” wherein no “Purposeful Evasion Attack” is encountered. Nevertheless, these attacks can render a DLP system completely useless (or greatly depreciate the effectiveness/usefulness of any DLP solution). A true DLP solution, therefore, must support “Malicious Data Leak Prevention” capability wherein “Purposeful Evasion Attacks” can be effectively detected and prevented. With the advent of Advanced Persistent Threats (APTs) against Information Security and DLP Systems, “Purposeful Evasion Attacks” have emerged as the most sophisticated class of threats against DLP solutions. Unfortunately, “Purposeful Evasion Attacks” have also remained un-addressed in their most basic forms. This paper presents (1) an insight into the lifecycle of APTs launched against Information Security and DLP systems, (2) a classification of real-life “Purposeful Evasion Attacks” against Information Security and DLP systems, (3) a reference model for enabling Malicious Data Leak Prevention (called 3-D Correlation Paradigm).
Keywords
security of data; 3D correlation paradigm; APT management; DLP systems; accidental data leak; advanced persistent threat management; information security; malicious data leak prevention; purposeful evasion attacks; Classification algorithms; Context; Correlation; Fingerprint recognition; Information security; Pattern matching; APT; Advanced Persistent Threat; Data Leak Prevention; Egress Control; Evasion Attack; False Negative; Information Security; Malicious DLP;
fLanguage
English
Publisher
ieee
Conference_Titel
Electronics, Communications and Photonics Conference (SIECPC), 2013 Saudi International
Conference_Location
Fira
Print_ISBN
978-1-4673-6196-5
Electronic_ISBN
978-1-4673-6194-1
Type
conf
DOI
10.1109/SIECPC.2013.6551028
Filename
6551028
Link To Document