Data Exfiltration: Preventive and Detective Countermeasures
preprint
OA: closed
Abstract
Owing to the COVID-19 pandemic that has forced several businesses into the notion of work from home, theft of sensitive and private data has become a more prominent threat. Given that the exfiltrated data closely resembles the normal network traffic, detecting data hoarding and exfiltration attempts has become much more challenging since data flows in and out of the enterprise network on a routine basis. The threat actors to data exfiltration exist both. outside and inside the network. The prime reason of concern relating to data exfiltration is the potential risk of misuse of sensitive information and reputational and financial damage to the enterprise. In consideration to this, it is essential to provide an in-depth review of existing countermeasures to pave the path for future research in this field and enhance development efforts towards devising, evaluating, and deploying effective and feasible countermeasures that protect against data exfiltration attacks. Our review provides a structured overview and in-depth analysis of common preventive and detective countermeasures taken against data exfiltration. We have identified text classification and access control as the most commonly adopted preventive measures against data exfiltration. For detection, however, there is a vast domain of research amongst which we have provided a thorough review of the advanced persistent threat detection (APT), insider threat detection, deep packet inspection (DPI) and Domain Name System (DNS) exfiltration and tunneling techniques. Along with reporting the status of current state of art it determines and highlights various challenges and issues that are left untouched and require research attention.
My notes (saved in your browser only)
Citation neighborhood (no data yet)
We don't have any in-corpus citations linked to this paper yet. The paper's references may be in our DB but unresolved to ``paper_id`` (resolution happens at ingest when the cited DOI matches a row we already have). Run the cross-source citation reconcile pass to retry.
Source provenance
- europepmc
- last seen: 2026-05-19T01:45:01.086888+00:00
- unpaywall
- last seen: 2026-06-02T02:00:03.124865+00:00