12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

13Managing <strong>McAfee</strong> DLP systemsUsing capture filtersTypes of content capture filter actionsContent capture filter actions drop elements or sessions from network traffic, or store only metadata.There are three types of content capture filter action.• Drop element keeps a particular type of content from being captured. For example, if your networkhas a large cache of video files that you know are not a security threat because you have controlledthem with configuration management software, you can set up a filter that drops these secure files,saving time and resources for analysis of data at risk.• Drop Sessions filters out sessions containing the defined elements from being captured. For example,if your employees are authorized to send or receive any SMTP content that is processed by yourcompany's mail server, you can drop those communications.• Drop element; store metadata only keeps all content from being captured, but retains all of the attributesthat define the objects captured and stored in the database. For example, if you want to know whatkind of data is moving through the network data stream without storing its content, storingmetadata allows you to keep incidental information (like the source and destination of the data,data types being transmitted, and protocols being used to transmit it).Types of network capture filter actionsNetwork capture filter actions ignore or store network data, depending on port or protocol used.There are two types of network capture filter action.• Ignore keeps a particular type of traffic from being captured. For example, you can ignore all webtraffic by using HTTP filters, or eliminate authorized email by ignoring traffic using port 25 (SMTP).• Store stores a particular type of network traffic. For example, you can store chat traffic by creating afilter that identifies and keeps data transmitted using AOL_Chat, MSN_Chat, or Yahoo_Chatprotocols.Add content capture filtersAdd content capture filters to identify types of Application Layer traffic that can be stored or ignored.After these blocks of data are identified, the capture engine will not capture or parse any of the trafficcontaining them.Before you beginMake a note of the types of Flow A traffic you want the capture engine to store or ignore.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Sys Config | System Administration |Capture Filters.• On your <strong>McAfee</strong> DLP appliance, select System | System Administration | Capture Filters.2 Click Create Content Filter.3 Type in a filter name and optional description.4 Select the devices to which the capture filter is to be deployed.If you want to deploy a capture filter at a later time, select None.5 Select a capture action to indicate what portion of traffic is to be stored or dropped.6 Open each category and define parameters that describe the traffic.254 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!