Data exfiltration: a review of external attack vectors and countermeasures

dc.contributor.authorUllah, F.
dc.contributor.authorEdwards, M.
dc.contributor.authorRamdhany, R.
dc.contributor.authorChitchyan, R.
dc.contributor.authorBabar, M.
dc.contributor.authorRashid, A.
dc.date.issued2018
dc.description.abstractContext: One of the main targets of cyber-attacks is data exfiltration, which is the leakage of sensitive or private data to an unauthorized entity. Data exfiltration can be perpetrated by an outsider or an insider of an organization. Given the increasing number of data exfiltration incidents, a large number of data exfiltration countermeasures have been developed. These countermeasures aim to detect, prevent, or investigate exfiltration of sensitive or private data. With the growing interest in data exfiltration, it is important to review data exfiltration attack vectors and countermeasures to support future research in this field. Objective: This paper is aimed at identifying and critically analysing data exfiltration attack vectors and countermeasures for reporting the status of the art and determining gaps for future research. Method: We have followed a structured process for selecting 108 papers from seven publication databases. Thematic analysis method has been applied to analyse the extracted data from the reviewed papers. Results: We have developed a classification of (1) data exfiltration attack vectors used by external attackers and (2) the countermeasures in the face of external attacks. We have mapped the countermeasures to attack vectors. Furthermore, we have explored the applicability of various countermeasures for different states of data (i.e., in use, in transit, or at rest). Conclusion: This review has revealed that (a) most of the state of the art is focussed on preventive and detective countermeasures and significant research is required on developing investigative countermeasures that are equally important; (b) Several data exfiltration countermeasures are not able to respond in real-time, which specifies that research efforts need to be invested to enable them to respond in real-time (c) A number of data exfiltration countermeasures do not take privacy and ethical concerns into consideration, which may become an obstacle in their full adoption (d) Existing research is primarily focussed on protecting data in ‘in use’ state, therefore, future research needs to be directed towards securing data in ‘in rest’ and ‘in transit’ states (e) There is no standard or framework for evaluation of data exfiltration countermeasures. We assert the need for developing such an evaluation framework.
dc.description.statementofresponsibilityFaheem Ullah, Matthew Edwards, Rajiv Ramdhany, Ruzanna Chitchyan, M. Ali Babar, Awais Rashid
dc.identifier.citationJournal of Network and Computer Applications, 2018; 101:18-54
dc.identifier.doi10.1016/j.jnca.2017.10.016
dc.identifier.issn1084-8045
dc.identifier.issn1095-8592
dc.identifier.orcidBabar, M. [0000-0001-9696-3626]
dc.identifier.urihttp://hdl.handle.net/2440/116549
dc.language.isoen
dc.publisherElsevier
dc.rights© 2017 Elsevier Ltd. All rights reserved.
dc.source.urihttps://doi.org/10.1016/j.jnca.2017.10.016
dc.subjectData exfiltration; data leakage; data theft; data breach; external attack vector; countermeasure
dc.titleData exfiltration: a review of external attack vectors and countermeasures
dc.typeJournal article
pubs.publication-statusPublished

Files