摘要:
A computer-implemented method for data loss prevention may include 1) identifying a file hierarchy within a file system (where, e.g., the file hierarchy includes a plurality of files and folders), 2) identifying a defined file hierarchy structure that is associated with a data loss prevention policy (where, e.g., the defined file hierarchy structure identifies the relative locations of files and folders), 3) determining that the file hierarchy is implicated in the data loss prevention policy by determining that the defined file hierarchy structure corresponds to the file hierarchy, and 4) applying the data loss prevention policy to at least a portion of the file hierarchy based on determining that the file hierarchy is implicated in the data loss prevention policy. Various other methods, systems, and computer-readable media are also disclosed.
摘要:
A computer-implemented method for end-user initiated data-loss-prevention content analysis may include identifying an end-user application that handles content subject to data-loss-prevention policies. The computer-implemented method may also include receiving a request through a user interface associated with the end-user application to analyze selected content for data-loss-prevention policy compliance. The computer-implemented method may further include performing an analysis of the selected content for data-loss-prevention policy compliance. The computer-implemented method may additionally include providing a result of the analysis through the user interface associated with the end-user application. Various other methods, systems, and computer-readable media are also disclosed.
摘要:
A method and apparatus for monitoring network-based printing for data loss prevention (DLP). A DLP system may monitor outbound data transfers performed by a computing system, and detect a network print request in a current one of the outbound data transfers being sent to a network-based printer over a network, the network print request identifying data to be printed by the network-based printer. The DLP system determines whether the identified data of the current outbound data transfer violates a DLP policy and prevents the current outbound data transfer when the current outbound data transfer violates the DLP policy.
摘要:
A method and apparatus for detection of DLP violations with language detection are described. A DLP product may monitor data content associated with the computing system, and identify a language of the data content. Based on the identified language, the DLP product identifies from among multiple DLP policies a first set of one or more DLP policies that are applicable for the identified language (referred to herein as language-specific DLP policies). The DLP product scans the data content using the first set to detect a violation of one of the DLP policies in the data content, and performs a DLP action in response to the detected violation.
摘要:
A method and apparatus submitting information to be protected before permitting an outbound data transfer with the information is described. A DLP agent, incorporating a DLP submission tool, receives information of an outbound data transfer by the client computing system. The DLP agent can temporarily block the outbound data transfer and send a request to update a DLP policy to protect the information before permitting the outbound data transfer. The DLP agent subsequently receives receiving an indication that the DLP policy is updated to protect the information. After receiving the indication, the DLP agent permits the outbound data transfer.
摘要:
A computer-implemented method for data loss prevention may include intercepting a packet sent by an application of an endpoint. The computer-implemented method may also include extracting file-identification information from the packet. The computer-implemented method may further include identifying a list of opened files and matching the file-identification information to a file in the list of opened files. The computer-implemented method may additionally include identifying a data-loss-prevention policy that applies to the file. The computer-implemented method may moreover include filtering the packet based on the data-loss-prevention policy. Various other methods, systems, and computer-readable media are also disclosed.
摘要:
A web page running on a client computing device accesses a web application hosted by a remote server. The local application receives data from the web application. The client computing device uses a data loss prevention (DLP) policy to determine whether the web application is a sensitive web application. In response to determining that the web application is a sensitive web application, the client computing device restricts a capability of at least one of the local application or the client computing device to perform one or more operations associated with the data received from the web application.
摘要:
A computer-implemented method for data loss prevention may include intercepting a packet sent by an application of an endpoint. The computer-implemented method may also include extracting file-identification information from the packet. The computer-implemented method may further include identifying a list of opened files and matching the file-identification information to a file in the list of opened files. The computer-implemented method may additionally include identifying a data-loss-prevention policy that applies to the file. The computer-implemented method may moreover include filtering the packet based on the data-loss-prevention policy. Various other methods, systems, and computer-readable media are also disclosed.