Skip to content
Open access

Detecting Low-and-Slow Data Exfiltration: A Behavioural and Cumulative-Signal Approach to Identifying Slow-Moving Data Extraction

Aug 2026 · Indian Journal of Computer Science and Technology · 0 citations

Abstract

Most exfiltration controls are built to catch a single large transfer: a threshold on session size, a daily-volume cap, a DLP rule tuned to a file-size or record-count trigger. An adversary who instead moves data out in small increments over an extended period – kilobytes at a time, spread across days or weeks, often through channels that are individually unremarkable – can stay under every one of those thresholds indefinitely. This paper sets out a detection approach for that low-and-slow pattern. It argues that no single log source or single-session threshold is sufficient, and that reliable detection instead requires stitching together weak, individually-tolerable signals across along observation window, using periodicity, cumulative volume against an adaptive baseline, and entity-relative behavioural scoring. A practical detection architecture is proposed, built primarily on SIEM correlation logic over proxy, DNS, endpoint and database logs, with worked detection logic, tuning guidance to control false positives, and a discussion of the specific evasion techniques – protocol choice, timing jitter, channel rotation – that a slow exfiltration campaign is likely to use against exactly this kind of detection.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.