Trellix DLP – SaaS can track content based on storage location or the application used to create it.
The mechanisms used to track content are:
Content fingerprinting — Supported on Trellix DLP Endpoint - SaaS for Windows and Trellix DLP – SaaS appliances.
Registered documents — Supported on all Trellix DLP – SaaS products except Trellix DLP Endpoint – SaaS for Mac.
Note
Only Manual registration, performed in the Classification module, is supported on Trellix DLP Endpoint - SaaS for Windows, Trellix DLP Network Prevent – SaaS, and Trellix DLP Network Monitor – SaaS.
Automatic registration, performed by Trellix DLP Discover registration scans, is currently not supported.
Manual classifications — Created by Trellix DLP Endpoint - SaaS and Trellix DLP Endpoint – SaaS for Mac users, but supported on all Trellix DLP – SaaS products.
Content fingerprinting
Content fingerprinting is a technique for identifying and tracking content. The administrator creates a set of content fingerprinting criteria. The criteria define either the file location or the application used to access the file, and the classification to place on the files. The Trellix DLP Endpoint - SaaS client tracks any file that is opened from the locations, or by the applications, defined in the content fingerprinting criteria and creates fingerprint signatures of these files in real time when the files are accessed. It then uses these signatures to track the files or fragments of the files. You can define content fingerprinting criteria by application, UNC path (location), or URL (web application).
Support for persistent fingerprint information
Content fingerprint signatures are stored in a file's extended file attributes (EA) or alternate data streams (ADS). When such files are accessed, Trellix DLP Endpoint - SaaS software tracks data transformations and maintains the classification of the sensitive content persistently, regardless of how it is being used. For example, if you open a fingerprinted Word document, copy a few paragraphs of it into a text file, and attach the text file to an email message, the outgoing text file has the same signatures as the original document.
For file systems that do not support EA or ADS, Trellix DLP Endpoint - SaaS software stores signature information as a metafile on the disk. The metafiles are stored in a hidden folder named ODB$, which the Trellix DLP Endpoint - SaaS client software creates automatically.
Note
Signatures and content fingerprinting criteria are not supported in Trellix Device Control – SaaS.
Registered documents (Only manual registration of documents is supported)
The registered documents (manual registration) feature is based on pre-scanning all files in specified repositories (such as the engineering SharePoint) and creating signatures of fragments of each file in these repositories. Trellix DLP Endpoint - SaaS and the Trellix DLP – SaaS appliances use manual registration.
Manual registration in Trellix DLP Endpoint - SaaS for Windows — Signatures of the files are uploaded to ePO - SaaS from Trellix DLP – SaaS when you manually upload files and create a package. These signatures are made available to and downloaded by the endpoints from the S3 bucket. The Trellix DLP Endpoint - SaaSclient is then able to track any content copied from one of these documents and classify it according to the classification of the registered document signature. For more information about storing registered document signatures, see Storing evidence and fingerprint files topic in theTrellix DLP Endpoint - SaaSInstallation Guide
Manual registration in Trellix DLP – SaaS appliances — Signatures of the files are uploaded to ePO - SaaS from Trellix DLP – SaaS when you manually upload files and create a package. A package of these signatures of files is saved in an Amazon S3 bucket. These signatures are made available to and downloaded by the appliances from the S3 bucket. The appliance is then able to track any content copied from one of these documents and classify it according to the classification of the registered document signature. For more information about storing registered document signatures, see Storing evidence and fingerprint files topic in theTrellix DLP Network Prevent – SaaS or Trellix DLP Network Monitor – SaaSInstallation Guide.
Registered documents use extensive memory, which might affect performance, because each document that the Trellix DLP – SaaS software inspects is compared to all registered document signatures to identify its origin.
Tip
To minimize the number of signatures and the performance implications of this technique, use registered documents to track only the most sensitive documents.
Manual classification
When working with manual classification, you have the option of applying content fingerprints or content classifications to files. Manually applied content fingerprinting is identical to the automatically applied fingerprinting described previously.
Manually applied content classifications embed a physical tag in the file which can be used to track the file wherever it is copied, but do not create signatures. Content copied from these files into other files can't be tracked.
Manual classification is supported on Microsoft Windows and macOS computers. If you try to classify a file type that doesn't support tagging (for example, TXT files), an error message displays.