Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Monitoring and Identifying Data Leaving the Newtork

Posted on 2016-10-14
3
Medium Priority
?
157 Views
Last Modified: 2016-11-24
Thinking specifically about an attack on our network, how could we monitor or what tools are out there for preventing data theft from our network?  I'm talking about suddenly a large amount of data leaving our network which may be as a result of a compromise.  Is there anything that could identify this?

We do use LANGaurdian here and there which has a quota function I believe but I'm not sure if this is for users.  I.e. it alerts when a user exceeds their daily quota, not necessarily when an unknown or external user is shifting vast amount of data from a file server.
0
Comment
Question by:jdc1944
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 7

Expert Comment

by:Niten Kumar
ID: 41843399
Try PRTG's free network sniffer
1
 
LVL 38

Accepted Solution

by:
Rich Rumble earned 2000 total points
ID: 41843475
The issue is, you need to be context aware, and data doesn't have to leave all at once, it can be siphoned slowly which is actually how a lot of the elite groups do their exfiltration. You need to look into DLP technology, and into securing data that is vital. The first step is to ID your data, you can do that with DLP trials, where they sniff and scan for data they typically flag on (SSN, CC, DoB, PII) or you specify your own search terms. Second, securing that data, make sure there are ACL's and controls in place to prevent just anyone getting the data. Only allow those with the need to access the data, Then you can go into a full fledged DLP where it can try to stop or at least alert on the possible exfil of data. It can be quota based by the way. Have a look at the Gartner DLP Quadrant, I like ForcePpoint
https://digitalguardian.com/sites/default/files/2016-gartner-magic-quadrant-for-enterprise-data-loss-prevention-new.png
-rich
1
 
LVL 5

Expert Comment

by:Kimberley from Paessler
ID: 41843723
PRTG can help you detect a sudden increase in the amount of data leaving the network, or in the amount of data leaving a file server.  However, we don't look into the payload, so we can't tell you if the increased traffic is a security breach, or just an increase in traffic.
0
Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I don't pretend to be an expert at this, but I have found a few things that are useful. I hope that sharing them here will help others, so they will not have to face some rather hard choices. Since I felt this to be a topic of enough importance and…
It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…

609 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question