How Trellix DLP categorizes applications used in classifications and rule sets can affect system performance.
Note
Categorization is not supported on Trellix DLP Endpoint for Mac.
Trellix DLP divides applications into four categories called strategies. These affect how the software works with different applications. You can change the strategy to achieve a balance between security and the computer’s operating efficiency.
The strategies, in order of decreasing security, are:
Editor — Any application that can modify file content. This includes “classic” editors like Microsoft Word and Microsoft Excel, as well as browsers, graphics software, accounting software, and so forth. Most applications are editors. Trellix DLP Endpoint client always analyzes files opened or created by editors.
Explorer — An application that copies or moves files without changing them, such as Microsoft Windows Explorer or certain shell applications.
Trusted — An application that needs unrestricted access to files for scanning purposes. Examples are Trellix Enterprise or backup software. Use the trusted strategy when you want to make sure that the Trellix DLP Endpoint client doesn't analyze files opened or created by the application.
Archiver — An application that can reprocess files. Examples are compression software such as WinZip, and encryption applications such as Trellix Endpoint Encryption software or PGP.
How to work with DLP strategies
Application strategies are set on the Application Template page in DLP Policy Manager → Definitions. Use the built-in templates, or create your own custom templates.
Note
You can't edit strategies in the built-in templates. You can create overrides on the DLP Policy → Settings → Application Strategy page. Create and remove overrides as needed to experiment with fine-tuning the policy.
Change the strategy as needed to optimize performance. For example, the high level of observation that an editor application receives is not consistent with the frequent processing of backup software. The performance penalty is high and the risk of a data leak from such an application is low, so we don't recommend using the trusted strategy with these applications.
You can also create more than one template for an application and assign it more than one strategy. Use the different templates in different classifications and rules to achieve different results in different contexts. You must be careful in assigning such templates within rule sets to avoid conflicts. Trellix DLP resolves potential conflicts according to the following hierarchy: archiver > trusted > explorer > editor. That is, editor has the lowest ranking. If an application is an editor in one template and anything else in another template in the same rule set, Trellix DLP does not treat the application as an editor.
Trusted strategy vs ignored processes
Trellix DLP uses two mechanisms to bypass processing files when no analysis is needed.
Trusted strategy is the general mechanism to use when you want to make sure that files opened or created by the application are not analyzed by the Trellix DLP Endpoint client. Use this mechanism for applications that always need unrestricted access to files.
Ignored processes are used to create exceptions to rules. Ignored URLs create exceptions for web protection rules. You can ignore applications to create exceptions to clipboard and printer protection rules, and to define exceptions for content tracking when creating content fingerprints.