Data Loss Prevention

 View Only
  • 1.  Monitoring video files

    Posted Jun 21, 2018 03:18 AM

    Hi Everyone,

    We are using DLPVersion 15.0, We have been having problems in creating a Policy that monitors video file transfers with "video" as the keyword in the filename. I also want the detection to be case insensitive so that if the users changed the name to Video or videO, it can still be logged as an incident. Hoping you can assist me on this one.

     

    Thank you,

    Jay



  • 2.  RE: Monitoring video files

    Posted Jun 21, 2018 03:02 PM

    Hi Jay,

    Is there no way in a rule to select case sensitivity?

    Thanks!



  • 3.  RE: Monitoring video files

    Posted Jun 25, 2018 01:31 AM

    Hi Craig,

     

    I already tried that but it seems that it is not working on my end.

     

    Thank you.



  • 4.  RE: Monitoring video files

    Posted Jun 25, 2018 03:36 AM
    Hi Jay, A couple of questions: - How is the policy setup? File type + File name? Or just File name? - Is this Endpoint or Network? - What detection channel are you testing with? - Have any other tests for different file name keywords worked? - Does the keyword rule (“video”) work with other components or detection channels? - Does case sensitivity (or insensitivity) work on other detections channels or components? This might be an issue with the file name being extracted within the body of a Web POST or something similar...


  • 5.  RE: Monitoring video files

    Posted Jun 25, 2018 03:36 AM
    Hi Jay, A couple of questions: - How is the policy setup? File type + File name? Or just File name? - Is this Endpoint or Network? - What detection channel are you testing with? - Have any other tests for different file name keywords worked? - Does the keyword rule (“video”) work with other components or detection channels? - Does case sensitivity (or insensitivity) work on other detections channels or components? This might be an issue with the file name being extracted within the body of a Web POST or something similar...


  • 6.  RE: Monitoring video files

    Posted Jun 26, 2018 01:54 AM

    Hi KollKash

    To answer your question

    - How is the policy setup? File type + File name? Or just File name?

    []the policy is setup by file type and file name

    - Is this Endpoint or Network?

    []Endpoint


    - What detection channel are you testing with?

    []what do you mean detection chanenel? sorry i am not yet that familliar with the system


    - Have any other tests for different file name keywords worked?

    []yes, i tried "torrent"


    - Does the keyword rule (“video”) work with other components or detection channels?

    []Not Sure with this one


    - Does case sensitivity (or insensitivity) work on other detections channels or components?

    []Not familliar with this as well

    Thank you,

    Jay



  • 7.  RE: Monitoring video files

    Posted Jun 28, 2018 08:34 AM

    Hey Jay,

    Sorry for the delay.

    Thanks for the answers. I've replied to some of the follow ups below.

    Apologies if I’m not precisely with my instructions or questions; I’m not in front of an Enforce console at the moment. J

     

    --------------------

    - How is the policy setup? File type + File name? Or just File name?

    []the policy is setup by file type and file name

    - Is this Endpoint or Network?

    []Endpoint

     

    - What detection channel are you testing with?

    []what do you mean detection chanenel? sorry i am not yet that familliar with the system

    Are you attempting to detect over HTTP(s), SMTP, USB, other?

     

    - Have any other tests for different file name keywords worked?

    []yes, i tried "torrent"

    When the “torrent” test worked, what “component” did the yellow highlighted match appear in within the Incident Match details in the Enforce console? I assume you’re using something akin to “*torrent*” and “*video*” – with wildcards in front and back of the keyword(s)…

    Are you using separate detection policies for the “torrent” detection and the “video” detection? If so, that might indicate a difference in policy setup. If not and you’re simply switching out the keyword, then there’s something else going on.

     

    - Does the keyword rule (“video”) work with other components or detection channels?

    []Not Sure with this one

    This one might be an interesting item to test, to ensure that “video” detects if it’s in the body of an email or within the content of the file…especially, since “torrent” in the filename seemed to work.

     

    - Does case sensitivity (or insensitivity) work on other detections channels or components?

    []Not familliar with this as well

    We probably should first focus on getting just “video” to work without accounting for any changes in case sensitivity; we can circle back to this one.

     

    Are your familiar with pulling logs from the Agent? I might also suggest opening a case with Symantec, as sometimes it can take them a bit of time to respond, and then they’ll likely ask some for logs and such.