Table 7. An example of identifying exception subset.
Si S-Si C(S-Si) DF(S-Si) SF (S-Si)
{28} {26, 17, 13, 5, 3, 2, 2, 2, 1, 1, 1} 11 63.5 325.3
{28, 26} {17, 13, 5, 3, 2, 2, 2, 1, 1, 1} 10 28.61 644.7
{28, 26, 17} {13, 5, 3, 2, 2, 2, 1, 1, 1} 9 13.11 719.7
{28, 26, 17, 13} {5, 3, 2, 2, 2, 1, 1, 1} 8 1.61 731.7
{28, 26, 17, 13, 5} {3, 2, 2, 2, 1, 1, 1} 7 0.49 648.1
{28, 26, 17, 13, 5, 3} {2, 2, 2, 1, 1, 1} 6 0.25 557
{28, 26, 17, 13, 5, 3, 2} {2, 2, 1, 1, 1} 5 0.24 464.2
{28, 26, 17, 13, 5, 3, 2, 2} {2, 1, 1, 1} 4 0.19 371.6
{28, 26, 17, 13, 5, 3, 2, 2, 2} {1, 1, 1} 3 0 279.2
{28, 26, 17, 13, 5, 3, 2, 2, 2, 1} {1, 1, 1} 2 0 186.2
{28, 26, 17, 13, 5, 3, 2, 2, 2, 1, 1} {1} 1 0 93.08
4 Conclusions
Studies showed that a significant number of businesses have traced the loss of sensi-
tive or confidential information to USB flash memory sticks. In this paper, we present
a novel model for identifying data exfiltration activities by mining Microsoft Win-
dows Registry. When a USB removable device is connected to a Windows system,
footprints are left in the Registry. By analyzing the concentration and dispersion of
USB device access operations we can identify anomalous USB device uses during a
certain time frame. Further computer forensic investigations are performed to confirm
the case of data exfiltration activities.
1. InformationWeek,
2. Randazzo, M., Keeney, M., Kowalski, E., Cappelli, D. and Moore, A.: Insider Threat
Study: Illicit Cyber Activity in the Banking and Finance Sector, CERT and the National
Threat Assessment Center (2004).
3. Cappelli,D.: Risk mitigation strategies: lessons learned from actual insider attacks, In Pro-
ceedings of the Sixth Annual Workshop on Cyber Security and Information Intelligence
Research (2010).
4. Cole, E., Ring, S.: Insider Threat, Protecting the Enterprise from Sabotage, Spying, and
Theft, 1st edition. Syngress (2005).
5. Gandhi, M.: Data Profiling and the Access Path Model, A Step Towards Addressing Insider
Misuse in Database Systems, Dissertation, University of California Davis (2005).
6. Carvey, H.: Windows Forensic Analysis DVD Toolkit, 2
Edn, Syngress (2009).
7. Financial Soundness Indicators: Compilation Guide, International Monetary Fund,
8. USB History,
9. Arning, A., Agrawal, R., Raghavan, P.:A linear method for deviation detection in large
database, In the Proceedings of 1996 International Conference on Knowledge Discovery
and Data Mining (1996).