Trellix DLP – SaaS uses user-defined classifications to identify and track sensitive content and files in data protection and discovery rules.
Trellix DLP – SaaS uses two mechanisms and two modes to classify sensitive content.
The two modes are automatic and manual classification.
Automatic classifications are defined in Trellix DLP – SaaS and distributed by ePO - SaaS in the deployed policies. They can then be applied to content with data protection rules or discovery rules.
Manual classifications are applied by authorized users to files and emails on their computers.
Note
Trellix DLP Network Prevent – SaaS and Trellix DLP Network Monitor – SaaS can enforce data protection rules based on manual classifications, but cannot set or view them.
The two mechanisms are content classifications and content fingerprinting.
Note
Trellix DLP Endpoint - SaaS only supports content classifications.
Content classifications are applied differently for manual and automatic classifications
For automatic classification, the classification criteria are compared to the content each time a rule is triggered.
For manual classification, the classification is embedded as a physical tag inside the file or email.
Content fingerprint signatures are stored in a file's extended file attributes (EA), alternate data stream (ADS), or in a hidden folder (ODB$).
All Trellix DLP – SaaS products support content classifications, that is, can apply them by assigning them to data protection or discovery rules.
On deployment, Trellix DLP – SaaS displays many predefined classifications. Predefined classifications include, amongst others, classifications for personal data specific to different European Union countries, that can be used for detection accuracy, specifically when scanning for personal data for European Union Citizens.
You can use predefined classifications as is in protection rules, but if you want to customize a classification you must duplicate it first. The classifications reduce false positives.
The Classification module in Trellix DLP – SaaS stores content classification and fingerprinting criteria, and the definitions used to configure them. It is also the place for setting up registered documents repositories, user authorization for manual classification, and ignored text.
The module provides these features:
Manual Classification — Configures the user groups allowed to manually classify or fingerprint content.
Definitions — Defines the content, properties, and location of files for classification.
Classification — Creates classifications and defines content classification and fingerprinting criteria.
Classification Tester — Tests classifications by checking if a phase or file triggers the classifications.
Ignored Text — Uploads files containing ignored text for distribution to endpoints.
Content classification
Content classifications include data and file conditions that define sensitive content. For automatic classification, the classification criteria are compared to the content each time a data protection, endpoint discovery, or network discovery rule is triggered. For manual classification, the classification is embedded as a physical tag inside the file or email. Manual content classifications are persistent, and remain in the file when copied to storage, attached to an email, or uploaded to a website such as SharePoint.
Automatic content classifications are supported on all Trellix DLP – SaaS products. Data protection rules based on manual classifications are enforced on all Trellix DLP – SaaS products but only Trellix DLP Endpoint - SaaS (both Windows and Mac versions) have the manual classification dialog that allows users to classify files.
Content classification criteria identify sensitive text patterns, dictionaries, and keywords, alone or in combinations. Combinations can be multiple named properties, or properties with a defined relationship known as proximity. They can also specify file conditions such as the file type, document properties, file encryption, or location in the file (header/body/footer).
Content fingerprints
Content fingerprints are used by Trellix DLP – SaaS products in the following ways:
Trellix DLP Endpoint - SaaS for Windows can apply content fingerprints to data protection rules and enforce the rules.
Trellix DLP Network Prevent – SaaS and Trellix DLP Network Monitor – SaaS can enforce content fingerprints in rules but can't apply them to content.
Content fingerprint criteria are applied to files or content based one of these options:
Application-based — The application that created or changed the file.
Location-based — The network share or the removable storage definition of where the file is stored.
Web-based — The web addresses that opened or downloaded the files.
All data and file conditions available to classification criteria are also available to content fingerprint criteria, allowing fingerprints to combine the functionality of both criteria types.
Content fingerprint signatures are stored in a file's extended file attributes (EA), alternate data stream (ADS), or in a hidden folder (ODB$). You can select the preferred technology on the Windows client configuration Content Tracking page. They are applied to a file when the file is saved. The mechanism is the same for automatic and manual content fingerprints. If a user copies or moves fingerprinted content to another file, the fingerprint criteria are applied to that file. If the fingerprinted content is removed from the file, the content fingerprint signatures are also removed. If the file is copied to a system that doesn't support EA or ADS (such as SharePoint), the fingerprint criteria are lost.
Note
Trellix DLP Endpoint - SaaS applies content fingerprint criteria to files after a policy is applied regardless of whether the classification is used in a protection rule or not.
Applying classification criteria
Trellix DLP – SaaS applies criteria to a file, email, or web request in one of the following ways:
Trellix DLP Network Prevent – SaaS applies criteria when an email or web request matches a configured classification.
Trellix DLP Network Monitor – SaaS applies criteria when network traffic matches a configured classification.
Trellix DLP Endpoint - SaaS applies criteria when:
The file matches a configured classification.
The file or sensitive content is moved or copied to a new location.
A file is matched during a discovery scan.
An email or a web request matches a configured classification.
A user with permission manually applies criteria to a file.