Solved

Monitoring and Identifying Data Leaving the Newtork

Posted on 2016-10-14
3
115 Views
Last Modified: 2016-11-24
Thinking specifically about an attack on our network, how could we monitor or what tools are out there for preventing data theft from our network?  I'm talking about suddenly a large amount of data leaving our network which may be as a result of a compromise.  Is there anything that could identify this?

We do use LANGaurdian here and there which has a quota function I believe but I'm not sure if this is for users.  I.e. it alerts when a user exceeds their daily quota, not necessarily when an unknown or external user is shifting vast amount of data from a file server.
0
Comment
Question by:jdc1944
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 6

Expert Comment

by:Niten Kumar
ID: 41843399
Try PRTG's free network sniffer
1
 
LVL 38

Accepted Solution

by:
Rich Rumble earned 500 total points
ID: 41843475
The issue is, you need to be context aware, and data doesn't have to leave all at once, it can be siphoned slowly which is actually how a lot of the elite groups do their exfiltration. You need to look into DLP technology, and into securing data that is vital. The first step is to ID your data, you can do that with DLP trials, where they sniff and scan for data they typically flag on (SSN, CC, DoB, PII) or you specify your own search terms. Second, securing that data, make sure there are ACL's and controls in place to prevent just anyone getting the data. Only allow those with the need to access the data, Then you can go into a full fledged DLP where it can try to stop or at least alert on the possible exfil of data. It can be quota based by the way. Have a look at the Gartner DLP Quadrant, I like ForcePpoint
https://digitalguardian.com/sites/default/files/2016-gartner-magic-quadrant-for-enterprise-data-loss-prevention-new.png
-rich
1
 
LVL 5

Expert Comment

by:Kimberley from Paessler
ID: 41843723
PRTG can help you detect a sudden increase in the amount of data leaving the network, or in the amount of data leaving a file server.  However, we don't look into the payload, so we can't tell you if the increased traffic is a security breach, or just an increase in traffic.
0
Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
CCNP Exam question 6 37
ransomware backup 8 136
Recommended raid configuration for ESXi host 7 94
internal SLA's for IT provision 6 36
Ransomware continues to grow in reach and sophistication, putting data everywhere at risk. Learn how to avoid being caught in its sinister clutches with these 11 key tips.
This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question