Data Exfiltration : A Review of External Attack Vectors and Countermeasures

Ullah, Faheem and Edwards, Matthew and Ramdhany, Rajiv and Chitchyan, Ruzanna and Babar, M. Ali and Rashid, Awais (2018) Data Exfiltration : A Review of External Attack Vectors and Countermeasures. Journal of Network and Computer Applications, 101. pp. 18-54. ISSN 1084-8045

[thumbnail of 1-s2.0-S1084804517303569-main]
PDF (1-s2.0-S1084804517303569-main)
1_s2.0_S1084804517303569_main.pdf - Accepted Version
Available under License Creative Commons Attribution-NonCommercial-NoDerivs.

Download (1MB)


AbstractContext One of the main targets of cyber-attacks is data exfiltration, which is the leakage of sensitive or private data to an unauthorized entity. Data exfiltration can be perpetrated by an outsider or an insider of an organization. Given the increasing number of data exfiltration incidents, a large number of data exfiltration countermeasures have been developed. These countermeasures aim to detect, prevent, or investigate exfiltration of sensitive or private data. With the growing interest in data exfiltration, it is important to review data exfiltration attack vectors and countermeasures to support future research in this field. Objective This paper is aimed at identifying and critically analysing data exfiltration attack vectors and countermeasures for reporting the status of the art and determining gaps for future research. Method We have followed a structured process for selecting 108 papers from seven publication databases. Thematic analysis method has been applied to analyse the extracted data from the reviewed papers. Results We have developed a classification of (1) data exfiltration attack vectors used by external attackers and (2) the countermeasures in the face of external attacks. We have mapped the countermeasures to attack vectors. Furthermore, we have explored the applicability of various countermeasures for different states of data (i.e., in use, in transit, or at rest). Conclusion This review has revealed that (a) most of the state of the art is focussed on preventive and detective countermeasures and significant research is required on developing investigative countermeasures that are equally important; (b) Several data exfiltration countermeasures are not able to respond in real-time, which specifies that research efforts need to be invested to enable them to respond in real-time (c) A number of data exfiltration countermeasures do not take privacy and ethical concerns into consideration, which may become an obstacle in their full adoption (d) Existing research is primarily focussed on protecting data in ‘in use’ state, therefore, future research needs to be directed towards securing data in ‘in rest’ and ‘in transit’ states (e) There is no standard or framework for evaluation of data exfiltration countermeasures. We assert the need for developing such an evaluation framework.

Item Type:
Journal Article
Journal or Publication Title:
Journal of Network and Computer Applications
Additional Information:
This is the author’s version of a work that was accepted for publication in Journal of Network and Computer Applications. Changes resulting from the publishing process, such as peer review, editing, corrections, structural formatting, and other quality control mechanisms may not be reflected in this document. Changes may have been made to this work since it was submitted for publication. A definitive version was subsequently published in Journal of Network and Computer Applications, 101, 2018 DOI: 10.1016/j.jnca.2017.10.016
Uncontrolled Keywords:
?? data exfiltrationdata leakagedata theftdata breachexternal attack vectorcountermeasurehardware and architecturecomputer networks and communicationscomputer science applications ??
ID Code:
Deposited By:
Deposited On:
24 Nov 2017 14:16
Last Modified:
23 Apr 2024 00:24