Y
Hacker News
new
|
ask
|
show
|
jobs
by
bdibs
2604 days ago
Proper audit logs that are regularly checked.
2 comments
drb91
2604 days ago
Assuming the exfiltration can be differentiated from normal behavior!
link
auiya
2603 days ago
Seeing large amounts of encrypted traffic leaving via a DNS tunnel during non-standard business hours for instance would be an example of such an anomaly. It's not always that easy to detect however.
link
mirimir
2604 days ago
Didn't Sony pick up exfiltration through exceptional data flows?
link
IncRnd
2604 days ago
Sony was hacked 19 times in two weeks. There was a lot they didn't pick up on due to the difficulties involved with that.
link