12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

11Managing conceptsAdd, apply, restore, and delete conceptsSet conditions for matching conceptsSet limitations on concepts that instruct the system to report matches only if certain conditions aremet.Before you beginThe concept to which conditions are to be added should be retrieving predictable results.Only User‐Defined or custom concepts accept conditions.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Policies | Concepts.• On your <strong>McAfee</strong> DLP appliance, select Policies | Concepts.2 Open a concept category and click a Concept Name.3 On the Edit Concept page, define one or more concept conditions to modify the circumstances underwhich a match is reported.• Count — Incidents are not reported unless the expression is found at least, or more than aspecific number of times.• Percentage — Incidents are not reported unless the expressions are found within a percentage ofthe text in a file. For example, if less than 50 percent is configured, the concept is a match if thepatterns exist within the first 50 percent of the text in the file — but in a 3MB file, only 4K mightbe text, so the match would have to be found within the first 2K. Alternatively, if the setting isgreater than 75 percent, then the match would occur only if the pattern was found toward theend of the file (3 to 4KB).• Number of lines from beginning — Incidents must not be reported unless the expression is found in aspecified range of lines from the beginning of the file.• Number of bytes from beginning — Incidents must not be reported unless the expression is found in aspecified number of bytes from the beginning of the file.• Proximity — Incidents must not be reported unless the expression is found at a numeric bytelocation.4 Click Save.Add session conceptsAdd session concepts to inspect all communications between two parties when a pattern is matched.Because the session layer is monitored, you will be able to find multiple objects contained in a singleflow (for example, an email attachment as well as the mail body).When creating concepts that have multiple words, you must escape spaces between words with abackslash (for example, \_).Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Policies | Concepts.• On your <strong>McAfee</strong> DLP appliance, select Policies | Concepts.2 Click Add Concept.3 In the Advanced category, select the Session Type option.236 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!