SIMPLE MECHANISM FOR POSSIBLE INFORMATION LEAK DETECTION ON DATA NETWORKS

The leakage of sensitive information is one of the main problems faced by institutions. Traditional rules-based tools like Snort or Suricata are able to efficiently detect known threats, but are useless against APTs (Advanced Persistent Threats). APTs use unknown vulnerabilities and standard protoco...

Full description

Bibliographic Details
Main Author: Javier Alfonso Valdés
Format: Article
Language:Spanish
Published: Departamento de Telecomunicaciones y Telemática 2021-03-01
Series:Telemática
Subjects:
Online Access:https://revistatelematica.cujae.edu.cu/index.php/tele/article/view/431
id doaj-03056193c4f24bd48199266ba6b78d0e
record_format Article
spelling doaj-03056193c4f24bd48199266ba6b78d0e2021-05-03T18:56:57ZspaDepartamento de Telecomunicaciones y TelemáticaTelemática1729-38042021-03-012012735337SIMPLE MECHANISM FOR POSSIBLE INFORMATION LEAK DETECTION ON DATA NETWORKSJavier Alfonso Valdés0Fiscalía General de la RepúblicaThe leakage of sensitive information is one of the main problems faced by institutions. Traditional rules-based tools like Snort or Suricata are able to efficiently detect known threats, but are useless against APTs (Advanced Persistent Threats). APTs use unknown vulnerabilities and standard protocols with encryption, simulating normal behavior. In this research a simple method based on the standard deviation of the times between the arrival of flows is proposed. It seeks to detect periodic outgoing connections that can be analyzed by specialists in search of information leakage. Suspicious periodic connections were identified, one of them corresponding to a poorly configured service that reported user data, effectively identifying a case of information leakage.https://revistatelematica.cujae.edu.cu/index.php/tele/article/view/431fuga de información, periodicidad, tráfico de red, desviación estándar
collection DOAJ
language Spanish
format Article
sources DOAJ
author Javier Alfonso Valdés
spellingShingle Javier Alfonso Valdés
SIMPLE MECHANISM FOR POSSIBLE INFORMATION LEAK DETECTION ON DATA NETWORKS
Telemática
fuga de información, periodicidad, tráfico de red, desviación estándar
author_facet Javier Alfonso Valdés
author_sort Javier Alfonso Valdés
title SIMPLE MECHANISM FOR POSSIBLE INFORMATION LEAK DETECTION ON DATA NETWORKS
title_short SIMPLE MECHANISM FOR POSSIBLE INFORMATION LEAK DETECTION ON DATA NETWORKS
title_full SIMPLE MECHANISM FOR POSSIBLE INFORMATION LEAK DETECTION ON DATA NETWORKS
title_fullStr SIMPLE MECHANISM FOR POSSIBLE INFORMATION LEAK DETECTION ON DATA NETWORKS
title_full_unstemmed SIMPLE MECHANISM FOR POSSIBLE INFORMATION LEAK DETECTION ON DATA NETWORKS
title_sort simple mechanism for possible information leak detection on data networks
publisher Departamento de Telecomunicaciones y Telemática
series Telemática
issn 1729-3804
publishDate 2021-03-01
description The leakage of sensitive information is one of the main problems faced by institutions. Traditional rules-based tools like Snort or Suricata are able to efficiently detect known threats, but are useless against APTs (Advanced Persistent Threats). APTs use unknown vulnerabilities and standard protocols with encryption, simulating normal behavior. In this research a simple method based on the standard deviation of the times between the arrival of flows is proposed. It seeks to detect periodic outgoing connections that can be analyzed by specialists in search of information leakage. Suspicious periodic connections were identified, one of them corresponding to a poorly configured service that reported user data, effectively identifying a case of information leakage.
topic fuga de información, periodicidad, tráfico de red, desviación estándar
url https://revistatelematica.cujae.edu.cu/index.php/tele/article/view/431
work_keys_str_mv AT javieralfonsovaldes simplemechanismforpossibleinformationleakdetectionondatanetworks
_version_ 1721482221783613440