Detecting Low-and-Slow Data Exfiltration: A Behavioural and Cumulative-Signal Approach to Identifying Slow-Moving Data Extraction
Abstract
Most exfiltration controls are built to catch a single large transfer: a threshold on session size, a daily-volume cap, a DLP rule tuned to a file-size or record-count trigger. An adversary who instead moves data out in small increments over an extended period – kilobytes at a time, spread across days or weeks, often through channels that are individually unremarkable – can stay under every one of those thresholds indefinitely. This paper sets out a detection approach for that low-and-slow pattern. It argues that no single log source or single-session threshold is sufficient, and that reliable detection instead requires stitching together weak, individually-tolerable signals across along observation window, using periodicity, cumulative volume against an adaptive baseline, and entity-relative behavioural scoring. A practical detection architecture is proposed, built primarily on SIEM correlation logic over proxy, DNS, endpoint and database logs, with worked detection logic, tuning guidance to control false positives, and a discussion of the specific evasion techniques – protocol choice, timing jitter, channel rotation – that a slow exfiltration campaign is likely to use against exactly this kind of detection.