• DocumentCode
    614409
  • Title

    Malicious Data Leak Prevention and Purposeful Evasion Attacks: An approach to Advanced Persistent Threat (APT) management

  • Author

    Mustafa, Tarique

  • Author_Institution
    nexTier Networks, Inc., Santa Clara, CA, USA
  • fYear
    2013
  • fDate
    27-30 April 2013
  • Firstpage
    1
  • Lastpage
    5
  • Abstract
    Existing Data Leak Prevention (DLP) solutions are inherently incapable of scaling beyond trivial scenarios of “Accidental Data Leak” wherein no “Purposeful Evasion Attack” is encountered. Nevertheless, these attacks can render a DLP system completely useless (or greatly depreciate the effectiveness/usefulness of any DLP solution). A true DLP solution, therefore, must support “Malicious Data Leak Prevention” capability wherein “Purposeful Evasion Attacks” can be effectively detected and prevented. With the advent of Advanced Persistent Threats (APTs) against Information Security and DLP Systems, “Purposeful Evasion Attacks” have emerged as the most sophisticated class of threats against DLP solutions. Unfortunately, “Purposeful Evasion Attacks” have also remained un-addressed in their most basic forms. This paper presents (1) an insight into the lifecycle of APTs launched against Information Security and DLP systems, (2) a classification of real-life “Purposeful Evasion Attacks” against Information Security and DLP systems, (3) a reference model for enabling Malicious Data Leak Prevention (called 3-D Correlation Paradigm).
  • Keywords
    security of data; 3D correlation paradigm; APT management; DLP systems; accidental data leak; advanced persistent threat management; information security; malicious data leak prevention; purposeful evasion attacks; Classification algorithms; Context; Correlation; Fingerprint recognition; Information security; Pattern matching; APT; Advanced Persistent Threat; Data Leak Prevention; Egress Control; Evasion Attack; False Negative; Information Security; Malicious DLP;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Electronics, Communications and Photonics Conference (SIECPC), 2013 Saudi International
  • Conference_Location
    Fira
  • Print_ISBN
    978-1-4673-6196-5
  • Electronic_ISBN
    978-1-4673-6194-1
  • Type

    conf

  • DOI
    10.1109/SIECPC.2013.6551028
  • Filename
    6551028