About data exfiltration detection

Prev Next

A SmartVision appliance can detect data exfiltration (data theft) activity. When data exfiltration detection is enabled, the appliance monitors the egress traffic from the network hosts you specify in the home network (homenet) list. Data exfiltration detection is enabled by default on SmartVision Edition appliances and on SmartVision-capable Network Security sensors and integrated appliances.

Note

If you use a SmartVision appliance for data exfiltration detection only, you can install the appliance either at the network perimeter or in the network core, depending on the locations of the hosts and networks being monitored.

The home network list

For each host or network in the homenet list, the appliance builds a baseline profile of the egress traffic. If subsequent egress traffic significantly deviates from the baseline profile, the appliance generates a Data Exfiltration alert, which is a SmartVision alert subtype.

To specify the hosts and networks to monitor for data theft activity, add IP addresses and address ranges to the home network list.

If the homenet list is empty, private IP address ranges—the network ranges defined in RFC 1918 for IPv4 networks or RFC 4193 for IPv6 networks—are used in place of a configured homenet list. The homenet list is empty by default.

Important

After you configure or edit the homenet list, it takes 72 hours to build baseline egress traffic profiles for the specified hosts and networks.

The data exfiltration detection whitelist

The data exfiltration detection whitelist specifies destination IP addresses.

This is described in Managing noisy data exfiltration alerts.