McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide McAfee Data Loss Prevention 9.2.2 Product Guide

kb.mcafee.com
from kb.mcafee.com More from this publisher
12.07.2015 Views

4Using McAfee DLP DiscoverManaging scansTable 4-16 Types of scans (continued)Scan typeRegistrationscanDiscover scanDescriptionUse this scan to register sensitive data by generating digital fingerprints, orsignatures, that identify documents to be protected. You can register partialdocuments by defining excluded text within the documents. For database scans,this mode is known as Data Match.When scanning large databases, McAfee recommends registering only sensitivedata, such as bank account numbers or Social Security numbers. Registering anentire database is neither practical nor useful.Use this scan to find data that has been registered, or is residing on a file share inviolation of a policy. In this mode, McAfee DLP Discover can monitor, encrypt, copy,delete, or move files to a secure location (quarantine). All actions produceincidents that are reported to dashboards.Remediation actions cannot be performed on database repositories.After an incident is reported to the dashboard, it can be sorted, filtered, exported,saved, and remediated to prevent future violations.File system repositories supportedWhen you access a repository, you connect to a central network location where data is stored,organized, and maintained. McAfee DLP Discover supports most common file system repository types.The repository type is determined by the protocol used to access data on the device.Table 4-17 File system repositories supportedRepository typeCIFS (Common Internet File System)Windows Server 2008NFS (Network File System)FTP (File Transport Protocol)HTTP/HTTPS (Hypertext TransportProtocol/over Secure Sockets Layer)Documentum 5.3, 6.0, 6.5SharePoint 2007, 2010DescriptionFormerly Microsoft SMB (Server Message Block) filesystem. Windows XP supported.Windows Server 2008 R2 clusters supported.Sun Microsystems file systemOpen source file transfer system — both passive andactive FTP scanning are supported.Web server systems — only HTTP‐based authentication issupported.EMC documentation server, access through the defaultdocbase port.Microsoft SharePoint supported.Database repositories supportedWhen you access a repository, you are connecting to a central network location where data is stored,organized and maintained. McAfee DLP Discover supports several common database repository types.McAfee DLP Discover supports JDBC (Java Database Connectivity).Table 4-18 Database repositories supportedRepository typeDescriptionDB2Versions 5x iSeries, 6.1 iSeries, 7.x‐9.xMS SQL Server Versions 2000, 2005, 2008, 7.0, MSDE 2000My SQL (Enterprise) Versions 5.0.x, 5.1OracleVersions 8i, 9i, 10g, 11g92 McAfee Data Loss Prevention 9.2.2 Product Guide

Using McAfee DLP DiscoverManaging scans 4Scanning network attached storageMcAfee DLP Discover scans storage devices by using the protocols that are used to access them.Table 4-19 Common network storage typesStorage typeAccess methodNetwork Attached Storage Network Attached Storage presents a conventional file system to thenetwork, and can be accessed directly by McAfee DLP systems.Storage Area NetworksStore data in an unusable format using physical blocks of disk space, butMcAfee DLP Discover can connect through any server that owns a pool ofdata on that device.Firewall options for scanningBefore scanning a repository, its firewall must be configured to allow scans.Source ports are randomly chosen unless explicitly noted. Network and host‐based firewalls typicallypermit connections only on certain ports and might have to be configured to permit connections onothers.Table 4-20 Firewall optionsRepository type Direction PortsCIFSFTP Active Mode (triedby Discover if PassiveMode fails)FTP Active ModeFTP Passive Mode (triedfirst by Discover)HTTPHTTPSNFSDatabaseDiscover to Server TCP 139 and 445 on serverDiscover to Server TCP destination port 21 on server (control)Server to Discover TCP source port 20 (from server), and destination port(on Discover) chosen by Discover (data)Discover to Server TCP destination port 21 on server (control), andanother port on server (data) chosen by the serverDiscover to Server TCP destination port 80 on server, unless port ismanually configured in the URL itselfDiscover to Server TCP destination port 443 on server, unless port ismanually configured in the URL itselfDiscover to Server TCP and UDP destination ports 111; 2049 on serverDiscover to Server Standard ports, by database:• DB2 — 50000• Microsoft SQL — 1433• MySQL — 3306• Oracle — 1521If the database server is running on a non‐standardport, that port number must be punctured in a firewall.EMC DocumentumMicrosoft SharePointDiscover to Server TCP destination port 1489 on serverDiscover to Server TCP destination ports 80 (HTTP) or 443 (HTTPS) onserver, unless port is manually configured in the URLitselfMcAfee Data Loss Prevention 9.2.2 Product Guide 93

4Using <strong>McAfee</strong> DLP DiscoverManaging scansTable 4-16 Types of scans (continued)Scan typeRegistrationscanDiscover scanDescriptionUse this scan to register sensitive data by generating digital fingerprints, orsignatures, that identify documents to be protected. You can register partialdocuments by defining excluded text within the documents. For database scans,this mode is known as <strong>Data</strong> Match.When scanning large databases, <strong>McAfee</strong> recommends registering only sensitivedata, such as bank account numbers or Social Security numbers. Registering anentire database is neither practical nor useful.Use this scan to find data that has been registered, or is residing on a file share inviolation of a policy. In this mode, <strong>McAfee</strong> DLP Discover can monitor, encrypt, copy,delete, or move files to a secure location (quarantine). All actions produceincidents that are reported to dashboards.Remediation actions cannot be performed on database repositories.After an incident is reported to the dashboard, it can be sorted, filtered, exported,saved, and remediated to prevent future violations.File system repositories supportedWhen you access a repository, you connect to a central network location where data is stored,organized, and maintained. <strong>McAfee</strong> DLP Discover supports most common file system repository types.The repository type is determined by the protocol used to access data on the device.Table 4-17 File system repositories supportedRepository typeCIFS (Common Internet File System)Windows Server 2008NFS (Network File System)FTP (File Transport Protocol)HTTP/HTTPS (Hypertext TransportProtocol/over Secure Sockets Layer)Documentum 5.3, 6.0, 6.5SharePoint 2007, 2010DescriptionFormerly Microsoft SMB (Server Message Block) filesystem. Windows XP supported.Windows Server 2008 R2 clusters supported.Sun Microsystems file systemOpen source file transfer system — both passive andactive FTP scanning are supported.Web server systems — only HTTP‐based authentication issupported.EMC documentation server, access through the defaultdocbase port.Microsoft SharePoint supported.<strong>Data</strong>base repositories supportedWhen you access a repository, you are connecting to a central network location where data is stored,organized and maintained. <strong>McAfee</strong> DLP Discover supports several common database repository types.<strong>McAfee</strong> DLP Discover supports JDBC (Java <strong>Data</strong>base Connectivity).Table 4-18 <strong>Data</strong>base repositories supportedRepository typeDescriptionDB2Versions 5x iSeries, 6.1 iSeries, 7.x‐9.xMS SQL Server Versions 2000, 2005, 2008, 7.0, MSDE 2000My SQL (Enterprise) Versions 5.0.x, 5.1OracleVersions 8i, 9i, 10g, 11g92 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!