Does outbound traffic volume prove data theft?¶
The practical answer¶
No. Outbound traffic volume does not by itself prove data theft.
The key evidential caution¶
The dangerous assumption is that a large transfer must represent stolen information.
Legitimate causes include:
Key points¶
- backups
- cloud synchronisation
- software distribution
- video or audio calls
- remote desktop
- system updates
- database replication
- security telemetry
- business file transfer
What investigators should establish¶
Investigators should establish:
Key points¶
- which device and process generated the traffic
- which account was involved
- the destination
- the time
- the application or protocol
- whether the transfer matched normal activity
- what source data was accessed beforehand
- whether the destination recorded receipt
Traffic volume may support an exfiltration hypothesis when combined with staging, file access, suspicious process activity and an unusual destination.
But it cannot normally identify the content by itself.
Small transfers can also be significant where the data is compressed, selected or highly sensitive.
Evidential limits¶
Do not treat the absence of a large spike as proof that no exfiltration occurred.
Baseline comparison should use the same device, process, destination and period where possible. Organisation-wide averages can hide normal high-volume activity on one system or make a modest but unusual transfer look insignificant. The surrounding file and account activity remains essential.
Destination reputation should also be treated cautiously. A well-known cloud provider may host unauthorised uploads, while an unfamiliar address may still support legitimate business activity.
Also compare whether the destination was already approved for that device, user or business process. A normally permitted service can still be misused, while an unfamiliar destination may have an innocent operational explanation.
Operational takeaway¶
Use outbound volume as contextual evidence, and require process, source-data and destination records before concluding that data was stolen.