Trellix DLP can track content based on storage location or the application used to create it.
The mechanisms used to track content are:
Content fingerprinting — Supported on Trellix DLP Endpoint for Windows and Trellix DLP Network.
Registered documents — Supported on all Trellix DLP products except Trellix DLP Endpoint for Mac.
Note
Only Manual registration, performed in the Classification module, is supported on Trellix DLP Endpoint for Windows, Trellix DLP Network Prevent, and Trellix DLP Network Monitor.
Automatic registration, performed by Trellix DLP Discover registration scans, is supported on Trellix DLP Discover, Trellix DLP Network Prevent, and Trellix DLP Network Monitor.
Manual classifications — Created by Trellix DLP Endpoint and Trellix DLP Endpoint for Mac users, but supported on all Trellix DLP products.
Content fingerprinting
Content fingerprinting is a technique for identifying and tracking content. The administrator creates a set of content fingerprinting criteria. The criteria define either the file location or the application used to access the file, and the classification to place on the files. The Trellix DLP Endpoint client tracks any file that is opened from the locations, or by the applications, defined in the content fingerprinting criteria and creates fingerprint signatures of these files in real time when the files are accessed. It then uses these signatures to track the files or fragments of the files. You can define content fingerprinting criteria by application, UNC path (location), or URL (web application).
Support for persistent fingerprint information
Content fingerprint signatures are stored in a file's extended file attributes (EA) or alternate data streams (ADS). When such files are accessed, Trellix DLP Endpoint software tracks data transformations and maintains the classification of the sensitive content persistently, regardless of how it is being used. For example, if you open a fingerprinted Word document, copy a few paragraphs of it into a text file, and attach the text file to an email message, the outgoing text file has the same signatures as the original document.
For file systems that do not support EA or ADS, Trellix DLP Endpoint software stores signature information as a metafile on the disk. The metafiles are stored in a hidden folder named ODB$, which the Trellix DLP Endpoint client software creates automatically.
Note
Signatures and content fingerprinting criteria are not supported in Trellix Device Control.
Registered documents
The registered documents feature is based on pre-scanning all files in specified repositories (such as the engineering SharePoint) and creating signatures of fragments of each file in these repositories. Trellix DLP Endpoint and the network Trellix DLP products use registered documents, but differ in the way the signatures of files are distributed.
Manual registration in Trellix DLP Endpoint for Windows — Signatures of the files are uploaded to ePO - On-prem from when you manually upload files and create a package. These signatures are made available and downloaded by the endpoints from the shared location. The Trellix DLP Endpoint client is then able to track any content copied from one of these documents and classify it according to the classification of the registered document signature.
Manual registration in Trellix DLP Network products — Signatures of the files are uploaded to ePO - On-prem from Trellix DLP when you manually upload files and create a package. A package of these signatures of files is saved in an evidence share. These signatures are made available and downloaded by Trellix DLP Network from the shared location. Trellix DLP Network is then able to track any content copied from one of these documents and classify it according to the classification of the registered document signature.
Automatic registration in Trellix DLP network products — Trellix DLP Discover runs registration scans on file repositories. The signatures created are stored in signature databases on servers designated as DLP Servers. Trellix DLP Discover uses them to create classification and remediation scans. Trellix DLP Network Prevent and Trellix DLP Network Monitor use them to define rules.
Registered documents use extensive memory, which might affect performance, because each document that the Trellix DLP software inspects is compared to all registered document signatures to identify its origin.
Tip
To minimize the number of signatures and the performance implications of this technique, use registered documents to track only the most sensitive documents.
Manual classification
When working with manual classification, you have the option of applying content fingerprints or content classifications to files. Manually applied content fingerprinting is identical to the automatically applied fingerprinting described previously.
Manually applied content classifications embed a physical tag in the file which can be used to track the file wherever it is copied, but do not create signatures. Content copied from these files into other files can't be tracked.
Manual classification is supported on Microsoft Windows and macOS computers. If you try to classify a file type that doesn't support tagging (for example, TXT files), an error message displays.