The registered documents feature is an extension of location-based content fingerprinting. It gives administrators another way to define sensitive information, to protect it from being distributed in unauthorized ways. Ignored text is text that Trellix DLP ignores when processing file content.
To create registered documents, Trellix DLP categorizes and fingerprints the contents of files predefined as sensitive. For example, sales estimate spreadsheets for the upcoming quarter. It uses the fingerprints to create signatures that are stored as registered documents. The signatures created are language-agnostic, that is, the process works for all languages.
Trellix DLP supports two types of registered documents, manual and automatic.
Manual registration
Create manually registered documents by uploading files in the Classification module on the Register Documents page. Then create packages from the uploaded files, to create signatures. These signatures are made available to and downloaded by the endpoints from the shared location, and used in rules enforced on the endpoints.
When you create a package, Trellix DLP processes all files on the list, and loads the fingerprints (signatures) to ePO - On-prem. When you add or delete documents, you must re-create a package. The software makes no attempt to calculate whether some of the files have already been fingerprinted. It always processes the entire list.
Trellix DLP Network also uses manual registration. Signatures of the files are uploaded to ePO - On-prem from Trellix DLP when you manually upload files and create a package. These signatures are made available to and downloaded by the appliances from the shared location. The appliance is then able to track any content copied from one of these documents and classify it according to the classification of the registered document signature.
Setting the confidence threshold — Trellix DLP allows you to configure the number of fingerprints that must be matched in a manually fingerprinted document to trigger a violation. This helps increase detection confidence as it minimizes false positives by triggering more accurate detections and reduces analysis time. An incident is triggered when the number of matches is equal to or higher than the set confidence threshold. You can set the Confidence Threshold percentage between 10 to 100 percent. For example, if a fingerprinted document generates 100 signatures, and if you select 10%, then 10 signatures are matched at random in the scanned document. To set the percentage go to, Classification → Register Documents → Manual Registration → Confidence Threshold.
Note
Selecting the Default setting triggers an incident when two signatures from the registered document match and has the potential to be noisy and might trigger false positives. It is recommended to use this setting only for testing purposes.
Ignored Text — Upload ignored text files on the Ignored Text page. Ignored text does not cause content to be classified, even if parts of it match content classification or content fingerprinting criteria. ignored text that commonly appear in files, such as boilerplates, legal disclaimers, and copyright information. ignored text packages are created separately from the registered documents packages, and are distributed to the endpoints in a similar manner.
Files that must be ignored must contain at least 400 characters.
If a file contains both classified and ignored data, the system does not ignore it. All relevant content classification and content fingerprinting criteria associated with the content remain in effect.
Automatic registration
Create automatically registered documents by running Trellix DLP Discover document registration scans. Use them to define classification and remediation scans, or protection rules for Trellix DLP Network Prevent and Trellix DLP Network Monitor.
Trellix DLP Discover registration scans create signature files that are stored as registered documents packages on the network, typically in the evidence storage share. A DLP Server assigned to act as the signature database loads the signatures from all storage shares. Each server configuration in the Policy Catalog can specify a DLP Server to distribute registered documents packages, so there can be more than one DLP Server in a network. In such a case, we recommend configuring each DLP Server to load signatures from all storage shares, as the signature databases are no longer synchronized. When a Trellix DLP Discover scan wants to match fingerprints, or Trellix DLP Network Monitor or Trellix DLP Network Prevent need to access the database to create a policy, they send an HTTP call using REST API.
You can run registration scans on File Server, SharePoint, or Box repositories. Assign a classification to the registered documents on the Scan Details page when setting up the scan. You can view the scans on the Register Documents page when you select Type: Automatic Registration.
Setting confidence threshold — You can set a threshold to be met to trigger a violation or incident for matching signatures or fingerprints generated from Automatic Document registration. You can set the confidence threshold percentage between 10 percent to 100 percent. To set the percentage go to, Classification → Register Documents → Automatic Registration → Confidence Threshold.
Note
Selecting the Default setting triggers an incident even if a single signature from the registered document matches and has the potential to be noisy and might trigger false positives. It is recommended to use this setting only for testing purposes.
Viewing registered documents data
The default Statistics view displays totals for number of files, file size, number of signatures, and so forth, in the left pane, and statistics per file in the right pane. Use this data to remove less important packages if the signature limit is approached.
The Group by view for manual registration allows grouping by classification or type/extension. It displays uploaded files per classification or type. You can filter the data by classification or with a custom filter. Information about last package creation and changes to the file list are displayed in the upper right.
For automatic registration, Group by allows grouping by classification, repository server, scan, or True File type. You can filter the data by scan, classification, or with a custom filter.