Web protection rules monitor or block data from being posted to websites, including web-based email sites. They are supported on Trellix DLP Endpoint for Windows, Trellix DLP Endpoint for Mac, and Trellix DLP Network Prevent. Trellix DLP Network Monitor also supports web protection rules, but can't block data.
Web protection rules enforced on Trellix DLP Network Monitor and Trellix DLP Network Prevent can be saved as DLP Capture searches so you can tune the settings without affecting the live rule analysis.
Four conditions define web protection rules:
Classification
End User
Web address (URL)
Upload type
Define the rule by adding URL List definitions to the web address condition. You can use built-in URL List definitions as is or with changes that you define. Internet Explorer, Firefox, Chrome and Microsoft Edge (Chromium-based) allow you to exclude URLs in web protection rules. Enter the URLs you want to exclude on the Web Protection page of the client configuration.
Note
For more information about URL list definitions, see KB90846.
Use the upload type is file upload to limit the rule to files only. This option allows other data types, such as webmail or web forms, to be uploaded without inspection.
Web protection rules aggregate repeat incidents. If you try to upload the same file to a website several times, or if the website automatically tries repeated uploads, it produces a single incident in the DLP Incident Manager.
Working with Chrome and Microsoft Edge browsers
Trellix DLP web post protection rules can block file uploads posted with Chrome and Microsoft Edge (Chromium-based) browsers. The web protection rule evaluates the Web Address (URL) condition with the browser address bar URL.
For text posts, the web protection rule evaluates the Web Address (URL) condition with the HTTP request URL. Because HTTP requests rely on the Chrome browser extensions, text posts can only be monitored.
Note
We recommend disabling Chrome guest and incognito mode in the Windows Client Configuration. If either of these are enabled, the active web URL on the endpoint might be unavailable.
One alternative to blocking web posts at the endpoint is to apply Trellix DLP web protection rules by enforcing the same web post protection rules on Trellix DLP Network Prevent. You can also use Skyhigh® Security Secure Web Gateway (SWG), which has native DLP capabilities.
To integrate Trellix DLP Endpoint with Google Chrome Enterprise, see Integration with Google Chrome Enterprise