12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

4Using <strong>McAfee</strong> DLP DiscoverRegistering documents and structured dataWhen registered text is plagiarized, it is unlikely that a 100 percent match will be found to the originaldocument. Therefore, searching for a percentage match of the registered material is more likely toexpose intellectual property theft.Use the high granularity signature type to detect percentages of matching signatures.Table 4-1 Definitions of signature typesSignature typeHigh granularityDefinitionHigh granularity signatures provide full plagiarism detection and protection bygenerating overlapping tiles over every bit of text. The original document can beidentified, even if words are transposed or the contents differ by a couple oflines of text. Only High Granularity signature types are generated for WebUploaded documents.Medium granularity Medium granularity signatures provide basic plagiarism detection and protectionby generating tiles over every eighth word. The original document can beidentified even if the contents differ by a couple of pages of text.Low granularityLow granularity signatures include a single compact digital signature for eachdocument registered. Exact copies of the file can be detected.How signatures are shared with managed systemsWhen <strong>McAfee</strong> DLP Discover is managed by <strong>McAfee</strong> DLP Manager, the signatures generated from scansor web uploads are distributed to other <strong>McAfee</strong> DLP appliances in the built‐in concepts DocReg andDBReg. The signatures stored in those concepts are used to locate registered data in network trafficand remote repositories.When <strong>McAfee</strong> DLP Discover and <strong>McAfee</strong> DLP Monitor are in communication through <strong>McAfee</strong> DLPManager, the registration records produced on a <strong>McAfee</strong> DLP Discover appliance are automaticallyshared with the <strong>McAfee</strong> DLP Monitor signature agents.Signatures are automatically transferred from the <strong>McAfee</strong> DLP Discover appliance to any managed<strong>McAfee</strong> DLP Monitor or <strong>McAfee</strong> DLP Discover when a registration scan is run. Rescanning is notnecessary.When signatures are shared, protection for content that has been identified in data at rest is extendedto <strong>Data</strong> in Motion and <strong>Data</strong> in Use on the network.Add DocReg or DBReg to a ruleAdd the DocReg or DBReg concepts to a rule to match signatures to data at rest in file systems anddatabase repositories.You can add up to two scan tasks to a rule, but only one of each type (<strong>Data</strong>‐in‐Motion or <strong>Data</strong> at Rest). Thedefinition of the rule determines which type is targeted.If you add a scan task to a rule after the DocReg or DBReg concept is added, you can apply existingsignatures to the data that was registered or discovered by that task.If a Registration task is used with the DocReg or DBReg concepts, the rule will also be evaluated by anyDiscover scan that uses its policy. You must manually configure the rule to include the concept if youwant to register the same document across multiple rules.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Policies.• On your <strong>McAfee</strong> DLP appliance, select Policies.76 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!