Detecting Data Exfiltration Using Seeds Based Graph Clustering
Adriel Cheng, Kyle Millar · 2022
Identifying devices of interest within Internet Protocol (IP) networks is essential for Cyber security and network management. However, the large variety and number of devices within networks, and the ubiquitous encryption of network traffic poses significant barriers. We present a scalable and encryption resilient technique to identify devices of interest based solely on their affiliation to public internet services. In this work, devices of interest are those that are suspected of engaging with suspicious or unexpected servers; e.g., facilitating the malicious exfiltration of sensitive intellectual property data. Graph-based clustering was used to reveal devices of interest based on the similarity of their network behaviour to a set of pre-known malicious devices acting as seeds. The motivation for our technique was driven by a case study for which a subset of malicious devices were known; however, the vast majority remained undiscovered. We conducted experiments to demonstrate viability of our technique as applied to this use-case. Detection accuracies of 94% were achieved, and malicious devices from the case study were successfully identified to aid data driven decisions by Cyber analysts.