A Small Leak will Sink a Great Ship: An Empirical Study of DLP Solutions
Matthias Luft, Thorsten Holz · Vieweg+Teubner eBooks · 2011
Data Leakage Prevention (DLP) is the general term for a new approach to avoid data breaches. To achieve this goal, all currently available implementations of this concept perform an analysis of intercepted data to detect breaches in a generic way. The analysis is typically based on user-defined policies which specify what data is valuable. There are several different approaches to both define these content policies and to intercept data to enable analysis. In this paper, we introduce a methodology to evaluate DLP solutions and we exemplify the method by testing two DLP implementations in detail. Our review process is an essential step in the life cycle of every new software or concept: there should be a continuous cycle of test phases and examinations before a solution can be regarded to be dependable. To perform such an analysis in a structured way, we develop a set of generic tests which evaluate critical parts of important functionality in a DLP solution. We focus on the development of a set of tests that evaluate the DLP specific functionality, instead of performing a traditional vulnerability assessment. Our empirical tests reveal security vulnerabilities in the tested products. The vulnerabilities have different impact, like the fact that data breaches can still happen or even new leakage vectors can arise. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.