SIMPLE MECHANISM FOR POSSIBLE INFORMATION LEAK DETECTION ON DATA NETWORKS
The leakage of sensitive information is one of the main problems faced by institutions. Traditional rules-based tools like Snort or Suricata are able to efficiently detect known threats, but are useless against APTs (Advanced Persistent Threats). APTs use unknown vulnerabilities and standard protoco...
Main Author: | |
---|---|
Format: | Article |
Language: | Spanish |
Published: |
Departamento de Telecomunicaciones y Telemática
2021-03-01
|
Series: | Telemática |
Subjects: | |
Online Access: | https://revistatelematica.cujae.edu.cu/index.php/tele/article/view/431 |
id |
doaj-03056193c4f24bd48199266ba6b78d0e |
---|---|
record_format |
Article |
spelling |
doaj-03056193c4f24bd48199266ba6b78d0e2021-05-03T18:56:57ZspaDepartamento de Telecomunicaciones y TelemáticaTelemática1729-38042021-03-012012735337SIMPLE MECHANISM FOR POSSIBLE INFORMATION LEAK DETECTION ON DATA NETWORKSJavier Alfonso Valdés0Fiscalía General de la RepúblicaThe leakage of sensitive information is one of the main problems faced by institutions. Traditional rules-based tools like Snort or Suricata are able to efficiently detect known threats, but are useless against APTs (Advanced Persistent Threats). APTs use unknown vulnerabilities and standard protocols with encryption, simulating normal behavior. In this research a simple method based on the standard deviation of the times between the arrival of flows is proposed. It seeks to detect periodic outgoing connections that can be analyzed by specialists in search of information leakage. Suspicious periodic connections were identified, one of them corresponding to a poorly configured service that reported user data, effectively identifying a case of information leakage.https://revistatelematica.cujae.edu.cu/index.php/tele/article/view/431fuga de información, periodicidad, tráfico de red, desviación estándar |
collection |
DOAJ |
language |
Spanish |
format |
Article |
sources |
DOAJ |
author |
Javier Alfonso Valdés |
spellingShingle |
Javier Alfonso Valdés SIMPLE MECHANISM FOR POSSIBLE INFORMATION LEAK DETECTION ON DATA NETWORKS Telemática fuga de información, periodicidad, tráfico de red, desviación estándar |
author_facet |
Javier Alfonso Valdés |
author_sort |
Javier Alfonso Valdés |
title |
SIMPLE MECHANISM FOR POSSIBLE INFORMATION LEAK DETECTION ON DATA NETWORKS |
title_short |
SIMPLE MECHANISM FOR POSSIBLE INFORMATION LEAK DETECTION ON DATA NETWORKS |
title_full |
SIMPLE MECHANISM FOR POSSIBLE INFORMATION LEAK DETECTION ON DATA NETWORKS |
title_fullStr |
SIMPLE MECHANISM FOR POSSIBLE INFORMATION LEAK DETECTION ON DATA NETWORKS |
title_full_unstemmed |
SIMPLE MECHANISM FOR POSSIBLE INFORMATION LEAK DETECTION ON DATA NETWORKS |
title_sort |
simple mechanism for possible information leak detection on data networks |
publisher |
Departamento de Telecomunicaciones y Telemática |
series |
Telemática |
issn |
1729-3804 |
publishDate |
2021-03-01 |
description |
The leakage of sensitive information is one of the main problems faced by institutions. Traditional rules-based tools like Snort or Suricata are able to efficiently detect known threats, but are useless against APTs (Advanced Persistent Threats). APTs use unknown vulnerabilities and standard protocols with encryption, simulating normal behavior. In this research a simple method based on the standard deviation of the times between the arrival of flows is proposed. It seeks to detect periodic outgoing connections that can be analyzed by specialists in search of information leakage. Suspicious periodic connections were identified, one of them corresponding to a poorly configured service that reported user data, effectively identifying a case of information leakage. |
topic |
fuga de información, periodicidad, tráfico de red, desviación estándar |
url |
https://revistatelematica.cujae.edu.cu/index.php/tele/article/view/431 |
work_keys_str_mv |
AT javieralfonsovaldes simplemechanismforpossibleinformationleakdetectionondatanetworks |
_version_ |
1721482221783613440 |