Content-aware Mechanisms Parent topic

Trend Micro Data Loss Prevention uses five content-aware mechanisms to identify digital assets stored on laptops, desktops, servers, and (with Network Monitor) in network traffic.
  • Expression matching: DLP identifies digital assets using predefined and customized expressions. Expression matching is best used with structured content, such as credit card numbers, national ID numbers, or phone numbers.
  • File attribute matching: DLP identifies digital assets using file attributes, such as file type and file size. DLP performs true file type detection to determine the correct file type even if the extension is altered.
  • Fingerprint matching: DLP acquires fingerprints from a stored document and compares these with fingerprints acquired from a transmitted file. If the number of common fingerprints matches the number specified in a template, DLP determines that the transmitted file is sensitive. Fingerprint matching works best with unstructured content.
  • Keyword list matching: DLP identifies digital assets using predefined and customized keyword lists.
  • Template matching: DLP identifies digital assets using predefined and customized templates that combine data identifiers (expressions, file attributes, fingerprints, and keyword lists) with operators (such as AND and OR) to form condition statements. If conditions are met, DLP takes actions based on policy settings.