Identifying and tracking content with classifications

Prev Next

Trellix DLP uses user-defined classifications to identify and track sensitive content and files in data protection and discovery rules.

Trellix DLP uses two mechanisms and two modes to classify sensitive content.

The two modes are automatic and manual classification.

  • Automatic classifications are defined in Trellix DLP and distributed by ePO - On-prem in the deployed policies. They can then be applied to content with data protection rules or discovery rules.

  • Manual classifications are applied by authorized users to files and emails on their computers.

    The manual classification dialog is supported on Trellix DLP Endpoint for Windows and Trellix DLP Endpoint for Mac.

    Note

    Trellix DLP Network Prevent and Trellix DLP Network Monitor can enforce data protection rules based on manual classifications, but cannot set or view them.

The two mechanisms are content classifications and content fingerprinting.

Note

Trellix DLP Endpoint only supports content classifications.

  • Content classifications are applied differently for manual and automatic classifications

    • For automatic classification, the classification criteria are compared to the content each time a rule is triggered.

    • For manual classification, the classification is embedded as a physical tag inside the file or email.

  • Content fingerprint signatures are stored in a file's extended file attributes (EA), alternate data stream (ADS), or in a hidden folder (ODB$).

All Trellix DLP products support content classifications, that is, can apply them by assigning them to data protection or discovery rules.

On deployment, Trellix DLP displays many predefined classifications. Predefined classifications include, amongst others, classifications for personal data specific to different European Union countries, that can be used for detection accuracy, specifically when scanning for personal data for European Union Citizens.

You can use predefined classifications as is in protection rules, but if you want to customize a classification you must duplicate it first. The classifications reduce false positives.

The Classification module in Trellix DLP stores content classification and fingerprinting criteria, and the definitions used to configure them. It is also the place for setting up registered documents repositories, user authorization for manual classification, and ignored text.

The module provides these features:

  • Manual Classification — Configures the user groups allowed to manually classify or fingerprint content.

  • Definitions — Defines the content, properties, and location of files for classification.

  • Classification — Creates classifications and defines content classification and fingerprinting criteria.

  • Classification Tester — Tests classifications by checking if a phase or file triggers the classifications.

  • Register Documents — Uploads files containing known sensitive content for distribution to endpoints; displays Trellix DLP Discover registration scan information.

  • Ignored Text — Uploads files containing ignored text for distribution to endpoints.

Content classification

Content classifications include data and file conditions that define sensitive content. For automatic classification, the classification criteria are compared to the content each time a data protection, endpoint discovery, or network discovery rule is triggered. For manual classification, the classification is embedded as a physical tag inside the file or email. Manual content classifications are persistent, and remain in the file when copied to storage, attached to an email, or uploaded to a website such as SharePoint.

Automatic content classifications are supported on all Trellix DLP products. Data protection rules based on manual classifications are enforced on all Trellix DLP products but only Trellix DLP Endpoint (both Windows and Mac versions) have the manual classification dialog that allows users to classify files.

Content classification criteria identify sensitive text patterns, dictionaries, and keywords, alone or in combinations. Combinations can be multiple named properties, or properties with a defined relationship known as proximity. They can also specify file conditions such as the file type, document properties, file encryption, or location in the file (header/body/footer).

Content fingerprints

Content fingerprints are used by Trellix DLP products in the following ways:

  • Trellix DLP Endpoint for Windows can apply content fingerprints to data protection rules and enforce the rules.

  • Trellix DLP Network Prevent and Trellix DLP Network Monitor can enforce content fingerprints in rules but can't apply them to content.

  • Trellix DLP Discover can use Location, SharePoint, or Box content fingerprint classification criteria in registration scans, but can't use or apply them in classification or remediation scans.

Content fingerprint criteria are applied to files or content based one of these options:

  • Application-based — The application that created or changed the file.

  • Location-based — The network share or the removable storage definition of where the file is stored.

  • Web-based — The web addresses that opened or downloaded the files.

All data and file conditions available to classification criteria are also available to content fingerprint criteria, allowing fingerprints to combine the functionality of both criteria types.

Content fingerprint signatures are stored in a file's extended file attributes (EA), alternate data stream (ADS), or in a hidden folder (ODB$). You can select the preferred technology on the Windows client configuration Content Tracking page. They are applied to a file when the file is saved. The mechanism is the same for automatic and manual content fingerprints. If a user copies or moves fingerprinted content to another file, the fingerprint criteria are applied to that file. If the fingerprinted content is removed from the file, the content fingerprint signatures are also removed. If the file is copied to a system that doesn't support EA or ADS (such as SharePoint), the fingerprint criteria are lost.

Note

Trellix DLP Endpoint applies content fingerprint criteria to files after a policy is applied regardless of whether the classification is used in a protection rule or not.

Applying classification criteria

Trellix DLP applies criteria to a file, email, or web request in one of the following ways:

  • Trellix DLP Network Prevent applies criteria when an email or web request matches a configured classification.

  • Trellix DLP Network Monitor applies criteria when network traffic matches a configured classification.

  • Trellix DLP Endpoint applies criteria when:

    • The file matches a configured classification.

    • The file or sensitive content is moved or copied to a new location.

    • A file is matched during a discovery scan.

    • An email or a web request matches a configured classification.

  • A user with permission manually applies criteria to a file.