Can Content-Based Data Loss Prevention Solutions Prevent Data Leakage in Web Traffic?

The effectiveness of data loss prevention (DLP) solutions remains obscure, especially with respect to the types of attacks they claim to protect against. A systematic analysis of HTTP data leakage vectors and a test of three content-based DLP solutions give insight into these solutions' vulnerabilities.

[1]  Carla E. Brodley,et al.  IP covert timing channels: design and detection , 2004, CCS '04.

[2]  Lior Rokach,et al.  A Survey of Data Leakage Detection and Prevention Solutions , 2012, SpringerBriefs in Computer Science.

[3]  Qing Zhang,et al.  Glavlit: Preventing Exfiltration at Wire Speed , 2006, HotNets.

[4]  Nick Feamster,et al.  Infranet: Circumventing Web Censorship and Surveillance , 2002, USENIX Security Symposium.

[5]  Kevin Borders,et al.  Quantifying Information Leaks in Outbound Web Traffic , 2009, 2009 30th IEEE Symposium on Security and Privacy.

[6]  Eric Ouellet,et al.  Magic Quadrant for Endpoint Protection Platforms , 2013 .