This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Is Data Control buggy?

Dear All,

Bit of background :- we are using Sophos 9.5 clients on XP and Windows 7 endpoints with SEC 4.5.x

I have implemented Data Control in Alert mode only across the firm.  So far I have some interesting results.  I have implemented just 4 rules, all UK, Bank Routing numbers, credit or debit, national id and PII.  We use Lotus Notes for email and am I right in thinking that Data Control simply monitors Windows Explorer transfers, thus we can send a plain text email breaching the rules, but Sophos will never pick it up?  It appears that way for me?  Attachments are scanned but plain text in an email is not?  is that right?

Also, on one OU I have implemented Data Control to Allow transfer on acceptance.  What I have found here makes no sense to me at all.  I create a blank Excel 2007 document and attaching that to an email breaches all rules and flags up a message box?  I create the same file but save it as a 2003 xls file and I am not prompted?  I have also added tons of attachments with all sorts of bank details and nothing is stopped, yet when I added a spreadsheet with a list of my servers it was flagged by the rules again!?

I have enabled verbose logging on my PC for data control but this adds nothing to normal logs, i.e. it does not drill down to the phrase that has breached the rule in the file, it simply records the file name of the document.

Please can anyone offer any advice as we are looking at creating a policy asap to combat DLP, but if the technology is failing its a no go-er.

Thanks in advance

Stuart

:5930


This thread was automatically locked due to age.
Parents
  • Thanks for the replies.

    After reading the help (which is always a good idea:smileywink:) I realise that it will not scan the email content, but the VMware image of the appliance sounds very interesting, so I will call our rep to arrange a trial when it is out.

    As for the Excel attachment issue, it affects other computer users too, so it is not just an issue on my test PC.  The scenario is if you create a blank excel spreadsheet in 2007 it will be stopped by Sophos as containing credit card numbers etc, but if you save the exact same file as a 2003 spreadsheet it sails through without any warnings.

    Could anybody else out there please try this procedure and see if you can reproduce my problem.  FYI I have set the PII content rule to find only 1 instance and then ask for authorisation.

    I think that the 2007 file format could be the issue because in reality the xlsx file is xml wrapped up in a zip file.

    Another quirk :smileysurprised: when I add an attachment Sophos begins a DLP scan of the 'file attach' dialog box before I have even selected a file to attach!?  So each time I do this now, my blank book1.xlsx is flagged for authorisation as soon as I click File > Attach!

    And on the logging side of things I have enabled a file content rule into the mix and I still see no more granularity than just normal logging.

    Another thing, is there a table of the actual matching rules? i.e. what format for the content rules, credit and debit card for example? Is it just looking for 8 numbers in one sequence?  Can I see this list?  Is it on my server or client PC?

    Support call time methinks.

    Thanks

    :5987
Reply
  • Thanks for the replies.

    After reading the help (which is always a good idea:smileywink:) I realise that it will not scan the email content, but the VMware image of the appliance sounds very interesting, so I will call our rep to arrange a trial when it is out.

    As for the Excel attachment issue, it affects other computer users too, so it is not just an issue on my test PC.  The scenario is if you create a blank excel spreadsheet in 2007 it will be stopped by Sophos as containing credit card numbers etc, but if you save the exact same file as a 2003 spreadsheet it sails through without any warnings.

    Could anybody else out there please try this procedure and see if you can reproduce my problem.  FYI I have set the PII content rule to find only 1 instance and then ask for authorisation.

    I think that the 2007 file format could be the issue because in reality the xlsx file is xml wrapped up in a zip file.

    Another quirk :smileysurprised: when I add an attachment Sophos begins a DLP scan of the 'file attach' dialog box before I have even selected a file to attach!?  So each time I do this now, my blank book1.xlsx is flagged for authorisation as soon as I click File > Attach!

    And on the logging side of things I have enabled a file content rule into the mix and I still see no more granularity than just normal logging.

    Another thing, is there a table of the actual matching rules? i.e. what format for the content rules, credit and debit card for example? Is it just looking for 8 numbers in one sequence?  Can I see this list?  Is it on my server or client PC?

    Support call time methinks.

    Thanks

    :5987
Children
No Data