Research on improved network data-leakage detection scheme

Zhao Genli · Computer Engineering and Applications Journal · 2016

Preventing flow of confidential data out of a network is a fundamental problem faced by network operators.This problem gets even more complex in the context of cloud computing. The existing data-leakage prevention solutions are based on generic search for keywords in outgoing data, and hence severely lack the ability to control data flow at a fine granularity with low false positives. In order to solve this problem, in this paper, a data-leakage prevention architecture based on the white-listing is designed, which uses a white-listing for providing the strong security of data transmission, on this basis, a data leakage detection algorithm by combining document fingerprinting with Bloom filters is proposed. The optimal locations for checking are computed by using dynamic programming to minimize the memory overhead and enable high-speed implementation. The simulation results show the algorithm for checking the fingerprints on the-fly scales to a large amount of documents at very low cost. For example, for one TB of documents, the solution only requires 340 MB memory to achieve worst case expected detection lag(i.e.leakage length)of 1000 bytes.

Read the paper · More papers on PaperTik