12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Managing conceptsTypes of concepts 11Types of conceptsTwo concept types are used to find related patterns of data in network traffic or data repositories.• Content concepts contain text patterns and regular expressions to match patterns to data on theApplication layer (Layer 7).• Session concepts target exchanges of data between applications on the Session layer (Layer 5).They can be used to recognize content found in multiple objects contained in a single flow.How content concepts workContent concepts contain related patterns of data that can be matched to data in motion or at rest.They find collections of significant data related to a single issue in application data.Most of the concepts that are shipped with your <strong>McAfee</strong> DLP appliances are listed under the User‐Definedtab. Only a few Built‐in concepts are constructed with proprietary algorithms. For example, a contentconcept can be used to collect credit card numbering patterns that can be matched to network data.You might use one of the factory default concepts (AMEX, CCN, DISCOVER, MASTERCARD) to findstandard payment card violations quickly, or you can add one that focuses only on patterns used byretail cards.If you are an advanced user, you can construct session concepts to identify data that is beingexchanged between clients and servers, or to find multiple objects in a single flow (for example, emailand attachments).Regular expression syntax for conceptsRegular expressions are used to build <strong>McAfee</strong> DLP concepts. Unlike those used by <strong>McAfee</strong> DLPEndpoint, they do not use POSIX syntax.Table 11-1 Supported regular expressionsExpression Definition\n line feed\r carriage return\f form feed\b backspace\a bell\t tab\k disables Perl/POSIX set range restrictions\K enables Perl/POSIX set range restrictions\0xN\nnn\d digit 0‐9\D not digit 0‐9the hex ascii character equivalent to Nthe octal character of value nnn\c any alpha A‐Z or a‐z\C not any alpha A‐Z or a‐z\w any alphanumeric \c or \d\W not alphanumeric ^\w<strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong> 233

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!