Comparison and Analysis of Anomaly Detection Methods for Detecting Data Exfiltration
데이터 유출 탐지를 위한 이상 행위 탐지 방법의 비교 및 분석

Wongi Lim, Koohyung Kwon, Jung-Jae Kim, Jong-Eon Lee, Si-Ho Cha
2016 Journal of the Korea Academia-Industrial cooperation Society  
Military secrets or confidential data of any organization are extremely important assets. They must be discluded from outside. To do this, methods for detecting anomalous attacks and intrusions inside the network have been proposed. However, most anomaly-detection methods only cover aspects of intrusion from outside and do not deal with internal leakage of data, inflicting greater damage than intrusions and attacks from outside. In addition, applying conventional anomaly-detection methods to
more » ... a exfiltration creates many problems, because the methods do not consider a number of variables or the internal network environment. In this paper, we describe issues considered in data exfiltration detection for anomaly detection (DEDfAD) to improve the accuracy of the methods, classify the methods as profile-based detection or machine learning-based detection, and analyze their advantages and disadvantages. We also suggest future research challenges through comparative analysis of the issues with classification of the detection methods.
doi:10.5762/kais.2016.17.9.440 fatcat:wimavmjksvgchccnnnff2oqc6e