DT-Leak: Process Mining-Based Behavioral Detection of Data Exfiltration
Resumo
The increasing sophistication of cyber threats, particularly Advanced Persistent Threats (APTs) focused on data exfiltration, has challenged the effectiveness of traditional perimeter-based and signature-based defenses. Conventional approaches rely heavily on tools such as Security Information and Event Management (SIEM), Intrusion Detection Systems (IDS), and event correlation to identify malicious activities based on isolated Indicators of Compromise (IoCs). However, these methods often fail to detect ’low and slow’ or ’live off the land’ behavioral sequences that mimic legitimate protocols, due to the lack of systematic mechanisms to transform fragmented log telemetry into verifiable behavioral models. To bridge this gap, this research proposes DT-Leak, a process mining-based approach to discover and analyze the behavioral dynamics of data exfiltration in corporate environments. The solution employs semantic abstraction strategies to mitigate the complexity of raw logs. This work offers a new analytical perspective that views cyberattacks as structured, discoverable processes, providing a formal framework to convert security telemetry into actionable behavioral intelligence. Experimental results demonstrate that the Heuristics Miner achieved the best balance between behavioral fidelity and model interpretability.
Referências
Alshamrani, A., Myneni, S., Chowdhary, A., and Huang, D. (2019). A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities. IEEE Communications Surveys & Tutorials, 21(2):1851–1877.
ATT&CK, M. (2024). Exfiltration over alternative protocol: Exfiltration over unencrypted non-c2 protocol. [link]. Acedido em: 4 de março de 2025.
Augusto, A., Carmona, J., and Verbeek, E. (2022). Advanced process discovery techniques. In Process Mining Handbook, pages 76–107. Springer.
Berti, A., van Zelst, S. J., and van der Aalst, W. M. P. (2019). Process mining for python (PM4Py): Bridging the gap between process- and data science. In Proceedings of the ICPM Demo Track 2019 co-located with the 1st International Conference on Process Mining (ICPM 2019), volume 2374 of CEUR Workshop Proceedings, pages 13–16. CEUR-WS.org. Aachen, Germany, June 24-26, 2019.
Booij, D. (2019). Agent tesla: A credential stealer using smtp on port 587. SANS Internet Storm Center Diary. Accessed: 2026-03-16.
Buchta, R., Gkoktsis, G., Heine, F., and Kleiner, C. (2024). Advanced persistent threat attack detection systems: A review of approaches, challenges, and trends. Digital Threats, 5(4).
Buijs, J. C., van Dongen, B. F., and van der Aalst, W. M. (2012). On the role of fitness, precision, generalization and simplicity in process discovery. In OTM Confederated International Conferences ”On the Move to Meaningful Internet Systems”, pages 305–322. Springer.
CrowdStrike (2026). 2026 global threat report. Technical report, CrowdStrike Holdings, Inc., Sunnyvale, CA, USA. Acesso em: 16 mar. 2026.
Davidpur, A. (2026). Unmasking agent tesla: A deep dive into a multi-stage campaign. [link]. Fortinet Threat Research Blog. Accessed: 03-Mar-2026.
Di Ciccio, C. and Montali, M. (2022). Declarative process specifications: reasoning, discovery, monitoring. In Process mining handbook, pages 108–152. Springer.
European Union Agency for Cybersecurity (ENISA) (2025). Enisa threat landscape 2025: July 2024 to june 2025. Technical report, ENISA, Attiki, Greece. Acesso em: 16 mar. 2026.
Jain, R. (1990). The art of computer systems performance analysis: techniques for experimental design, measurement, simulation, and modeling. John Wiley & Sons.
Krishnapriya, S. and Singh, S. (2024). A comprehensive survey on advanced persistent threat (apt) detection techniques. Computers, Materials and Continua, 80(2):2675–2719.
Lajevardi, A. M. and Amini, M. (2021). Big knowledge-based semantic correlation for detecting slow and low-level advanced persistent threats. Journal of Big Data, 8(1):148.
Leemans, S. J. J., Fahland, D., and van der Aalst, W. M. P. (2013). Discovering block-structured process models from event logs - a constructive approach. In Colom, J.-M. and Desel, J., editors, Application and Theory of Petri Nets and Concurrency, pages 311–329, Berlin, Heidelberg. Springer Berlin Heidelberg.
Macak, M., Vanát, I., Merjavý, M., Jevočin, T., and Buhnova, B. (2020). Towards process mining utilization in insider threat detection from audit logs. In 2020 Seventh International Conference on Social Networks Analysis, Management and Security (SNAMS), pages 1–6.
MITRE ATT&CK (2024). Agent tesla — software s0331. MITRE ATT&CK Framework. Accessed: 2026-03-16.
Myers, D., Suriadi, S., Radke, K., and Foo, E. (2018). Anomaly detection for industrial control systems using process mining. Computers & Security, 78:103–125.
OECD (2020). OECD Digital Economy Outlook 2020. OECD Publishing, Paris.
Pratap Singh, S. and Afzal, N. (2024). The MESA Security Model 2.0: A Dynamic Framework for Mitigating Stealth Data Exfiltration. arXiv e-prints, page arXiv:2405.10880.
Rodríguez, M., Betarte, G., and Calegari, D. (2024). A process mining-based method for attacker profiling using the mitre att&ck taxonomy. Journal of Internet Services and Applications, 15(1):212–232.
Schwab, K. (2016). The Fourth Industrial Revolution. World Economic Forum, Geneva.
Silva, J., Cordeiro, A., Lima, M., Lins, F., Santos, W. R. M., and Lima, R. (2025). Modelling advanced persistent threats to support cyber incident response. In 2025 IEEE International Conference on Systems, Man, and Cybernetics (SMC), pages 1–4.
Singh, S. P. and Afzal, N. (2024). The mesa security model 2.0: A dynamic framework for mitigating stealth data exfiltration. International Journal of Network Security & Its Applications (IJNSA), 16(3):1–18.
van der Aalst, W., Weijters, T., and Maruster, L. (2004). Workflow mining: discovering process models from event logs. IEEE Transactions on Knowledge and Data Engineering, 16(9):1128–1142.
van der Aalst, W. M. P. (2016). Process Mining: Data Science in Action. Springer, Berlin, Heidelberg, 2 edition.
van der Aalst, W. M. P. and Carmona, J., editors (2022). Process Mining Handbook, volume 448 of Lecture Notes in Business Information Processing. Springer.
Van der Aalst, W. M. P. and De Medeiros, A. K. A. (2005). Process mining and security: Detecting anomalous process executions and checking process conformance. Electronic Notes in Theoretical Computer Science, 121:3–21.
Weijters, A., {Aalst, van der}, W., and {Alves De Medeiros}, A. (2006). Process mining with the HeuristicsMiner algorithm. BETA publicatie : working papers. Technische Universiteit Eindhoven.
