首页 | 本学科首页   官方微博 | 高级检索  
     


Empirical Evaluation of Information Leakage Detection Using Net-flow Analysis
Authors:Jing Xu  Fei Xu  Xiao-Jun Chen  Jin-Qiao Shi and Cheng Qi
Affiliation:Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China;Dept.of Computer Science, Beijing University of Technology, Beijing 100124, China;Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China;Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China;Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China;Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China
Abstract:Because of the widespread of Trojans, organizations and Internet users become more vulnerable to the threat of information leakage. This paper describes an information leakage detection system (ILDS) to detect sensitive information leakage caused by Trojan. In particular, the principles of the system are based on the analysis of net-flows in four perspectives: heartbeat behavior analysis, DNS abnormal analysis, upload-download ratio and content analysis. Heartbeat behavior analysis and DNS abnormal analysis are used to detect the existence of Trojans while upload-download ratio and content analysis can quickly detect when the information leakage happens. Experiments indicate that the system is reliable and efficient in detecting information leakage. The system can also help to collect and preserve digital evidence when information leakage incident occurs.
Keywords:information leakage  heartbeat behavior  Trojan detection  digital forensics
本文献已被 维普 等数据库收录!
点击此处可从《哈尔滨工业大学学报(英文版)》浏览原始摘要信息
点击此处可从《哈尔滨工业大学学报(英文版)》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号