Data Loss Prevention

 View Only
  • 1.  DLP "Network Security" policy, Hacker Tools

    Posted Dec 17, 2013 11:02 AM

    We installed one of the solution packs that included a policy called "Network Security".  There are predefined rules for hacker tools, keyloggers, and GoToMyPC Activity. I am trying to determine if this policy is even worthwhile to leave enabled.

    I keep finding incidents that are created on terms like "AMAC", "sfind", etc. But I don't understand how I would know if those incidents are actual threats or just false positives.  For instance, most of our PDF files that people email out seem to contain at least one instance of "aMaC", or something similar.  The rest of the document is just the regular jumbled mess you would expect to see in a PDF, with an occaisional recognizable word, phrase, or sentence.

    Other phrases causing false positive incidents to be created are RAYTOWN (there is a real Raytown, Missouri), and Kismet (we have a valid user whose name is Kismet).  I have added exceptions for these, but they still seem to slip through in various forms at least a few times a week.

    Has anyone else here had a reason to keep this policy enabled?

     



  • 2.  RE: DLP "Network Security" policy, Hacker Tools
    Best Answer

    Posted Dec 19, 2013 03:35 PM

    We found it to be worthless and have it disabled.



  • 3.  RE: DLP "Network Security" policy, Hacker Tools

    Trusted Advisor
    Posted Dec 20, 2013 11:16 AM

    we have disabled most of default policy to build our own even if sometimes we used rules from default policies. They are usually too generic so used them as a template to create new ones closer to your business activity.



  • 4.  RE: DLP "Network Security" policy, Hacker Tools

    Posted Dec 21, 2013 06:51 PM
    Which solution packs you installed.................