Data Loss Prevention

 View Only
  • 1.  Mounted Device Detection

    Posted Jan 16, 2014 01:47 PM

    Currently we have discovered that DLP does not detect mounted divices like smartphones when connected to a desktop, any phi, pci, pii data does not get detected.  However it does work on usb drives.  We are using version 11.6 with agent 11.5.1



  • 2.  RE: Mounted Device Detection

    Broadcom Employee
    Posted Jan 17, 2014 12:17 AM

    Some kind of the mounted devices like smartphones can be detected by adding the application to the application monitor list.



  • 3.  RE: Mounted Device Detection

    Trusted Advisor
    Posted Jan 17, 2014 03:11 PM

    Greg..

    When it comes to SmartPhones, there are many ways that they coonect to the Endpoints. IN some cases they act like a USB devices. In other cases they look like a camera or use another application to transfer files.

    In each of those cases you will need to know what application they are using. So for example when connecting an iPhone it will use the Itunes program.. so you will need to make sure that iTunes is an application that you are monitoring when it accesses files and trys to copy thgem to the phone.

    Follow this process to add or monitor the programs that are connecting to the phones..

    You can change or add this value in the Application Monitoring setting for the iTunes application. To do this, perform the following steps:

    • For version 10.5: Login as Administrator into the hidden page at: https://<enforceserver>/ProtectManager/EndpointApplicationControlList.do .
    • For version 11 and later: Login as Administrator, then navigate to System -> Agents -> Application Monitoring.
    • Click on Add Fingerprint (Add Application in v11) and create a new application:
      • Name: Apple iTunes
      • Binary name: <leave empty>
      • Internal name: iTunes
      • Original Filename: iTunes\.exe
      • Enable "Write CD/DVDs?" option
    • Click on Save.
    • Recycle the Endpoint server.
    • Restart the EDPA service on the Endpoint Agent.

     

    Hope this makes sense.

    If this solves your questions please marked as solved.

    Ronak