JISE


  [1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] [14] [15] [16] [17] [18] [19]


Journal of Information Science and Engineering, Vol. 31 No. 1, pp. 23-42


Keystroke and Mouse Movement Profiling for Data Loss Prevention


JAIN-SHING WU1,2, CHIH-TA LIN1,2, YUH-JYE LEE2 AND SONG-KONG CHONG3
1CyberTrust Technology Institute
Institute for Information Industry
Taipei, 105 Taiwan
2Department of Computer Science and Information Engineering
National Taiwan University of Science and Technology
Taipei, 106 Taiwan
3UBIC Taiwan, Inc.
Taipei, Taiwan
E-mail: {jsw; cheetah}@iii.org.tw; yuh-jye@mail.ntust.edu.tw; alex_chong@ubictw.com 

 


    Data leakage is a serious problem for many large organizations. In order to provide the user with information about confidential data, many prevalent data leakage prevention (DLP) solutions rely on scanning the content of the relevant files. This approach requires the capability to parse various file formats. However, risks of data breach persist for unsupported file formats. To address this issue, we propose in this paper an active behavior-based DLP model that hooks the keyboard and mouse application programming interfaces (APIs) to track and profile user behavior. This model has two major advantages: (1) it can help discover sensitive data without parsing file formats, and (2) a data creator can be identified according to his/her keystroke and mouse movement behavior. Since this model is based on profiling user behavior, it eliminates the risk of data leakage from unsupported file formats and can identify the creator of a file. The experiments showcase the effectiveness of the proposed model with data creator identification method yields an accuracy rate of 92.64%, which is promising considering that the features of keystroke and mouse movement behavior are dealing together. 


Keywords: keystroke profiling, data leakage prevention, file parser, data creator identification, sensitive data protection, mouse movement behavior, machine learning

  Retrieve PDF document (JISE_201501_02.pdf)