EXFILD: A TOOL FOR THE DETECTION OF DATA EXFILTRATION USING ENTROPY AND ENCRYPTION CHARACTERISTICS OF NETWORK TRAFFIC
Tyrell William Fawcett · Library, Museums and Press - UDSpace (University of Delaware) · 2010
The twin goals of easy communication and privacy protection have always been in conflict. Everyone can agree that important information such as social security numbers, credit card numbers, proprietary information, and classified government information should not be shared with untrusted and unknown entities. The Internet makes it rather simple for an attacker to steal this information from even security conscious users without the victims ever discovering the theft. All it takes is one lapse in judgment and an attacker can have access to sensitive information. Currently the computer and network security industry places its focus on tools and techniques that are concerned with what is entering a system and not what is exiting a system. The industry has no reason to not inspect the outgoing traffic. Many attacks’ success and effectiveness rely heavily on traffic exiting the computer system. Outgoing traffic is just as, if not more important to inspect as incoming traffic to detect attacks involving theft of confidential information or interaction between the attacker and victim’s computer systems. Frequently recurring data breaches reinforce the necessity of tools and techniques capable of alerting the users when data is being exfiltrated from their computer systems. This thesis explores the use of entropy characteristics of network traffic to ascertain whether egress traffic from computer systems is encrypted. The inspection of network traffic at the session level instead of the packet is proposed to improve the accuracy of the entropy values. It establishes that entropy can indeed be used as an accurate metric of the traffic’s actual state of encryption.