DLP Content Analysis Configuration Director


This article describes how to configure DLP with Rule type Content Analysis from Director.


DLP works on a hierarchical pattern which makes it easy to understand, it can be broken down into the following  Data Patterns → Data Protection Profiles → DLP Rules → DLP Profile



Prerequisite 


Configuration


Goal of the below config is to block text file upload and download if contains aadhaar, pan card or credit card details for traffic using HTTP/HTTPS.


Step1


Configure the DLP data pattern profile in Services ->Security->Profiles->DLP->Data Protection using the predefined expressions or user defined expressions as shown below, for example we are taking the predefined patterns for aadhaar,pan and credit card.


CLI config for reference

set orgs org-services Tenant1 security profiles dlp data-protection custom-data-profiles pan_cc_aadhaar_data_exp_profile expressions CREDIT_CARD_NUMBER predefined-data-pattern CREDIT_CARD_NUMBER
set orgs org-services Tenant1 security profiles dlp data-protection custom-data-profiles pan_cc_aadhaar_data_exp_profile expressions INDIA_AADHAAR_INDIVIDUAL predefined-data-pattern INDIA_AADHAAR_INDIVIDUAL
set orgs org-services Tenant1 security profiles dlp data-protection custom-data-profiles pan_cc_aadhaar_data_exp_profile expressions INDIA_PAN_INDIVIDUAL predefined-data-pattern INDIA_PAN_INDIVIDUAL
set orgs org-services Tenant1 security profiles dlp data-protection custom-data-profiles pan_cc_aadhaar_data_exp_profile boolean-operation "INDIA_PAN_INDIVIDUAL OR CREDIT_CARD_NUMBER OR INDIA_AADHAAR_INDIVIDUAL



Step 2


Configure the DLP profile in Services ->Security->Profiles->DLP->Data Profile. Make sure the default action is selected as Allow and blocks are done based on the rules.




Step 3


Create the Rules, matching the context protocol and File type, the rule component correlates to the type of DLP being induced in this case content analysis and the User defined data pattern profile we created earlier. Do not select "Header" in the rules unless required.






CLI config for reference

set orgs org-services Tenant1 security profiles dlp dlp-profiles pan_adhaar_cc default-action action allow
set orgs org-services Tenant1 security profiles dlp dlp-profiles pan_adhaar_cc exit-on-first-rule-match disabled
set orgs org-services Tenant1 security profiles dlp dlp-profiles pan_adhaar_cc rules pan_adhaar_cc_dlp_rule activation false
set orgs org-services Tenant1 security profiles dlp dlp-profiles pan_adhaar_cc rules pan_adhaar_cc_dlp_rule match protocol [ HTTP ]
set orgs org-services Tenant1 security profiles dlp dlp-profiles pan_adhaar_cc rules pan_adhaar_cc_dlp_rule match file-type [ txt ]
set orgs org-services Tenant1 security profiles dlp dlp-profiles pan_adhaar_cc rules pan_adhaar_cc_dlp_rule match context [ Attachment Body ]
set orgs org-services Tenant1 security profiles dlp dlp-profiles pan_adhaar_cc rules pan_adhaar_cc_dlp_rule match content-analysis enable true
set orgs org-services Tenant1 security profiles dlp dlp-profiles pan_adhaar_cc rules pan_adhaar_cc_dlp_rule match content-analysis user defined-data-profile pan_cc_aadhaar_data_exp_profile
set orgs org-services Tenant1 security profiles dlp dlp-profiles pan_adhaar_cc rules pan_adhaar_cc_dlp_rule set action block
set orgs org-services Tenant1 security profiles dlp dlp-profiles pan_adhaar_cc rules pan_adhaar_cc_dlp_rule set logging disabled
set orgs org-services Tenant1 security profiles dlp dlp-profiles pan_adhaar_cc reputation lookup disabled
set orgs org-services Tenant1 security profiles dlp dlp-profiles pan_adhaar_cc reputation logging enabled


Step 4


Apply the DLP profile to the security policy in via which you want to do DLP.




Key Points to keep in mind while configuring


[admin@branch1: ~] $ sqlite3 /opt/versa/etc/spack/installed/current/config/predef_dlp.db "SELECT * FROM predef_dlp_data_pattern_list;" | grep -i aadhar

INDIA_AADHAAR_INDIVIDUAL|(aadhar|aadhaar|adhaar|aadhaar|aadhaar|aadhaar card)|\b([2-9]{1}[0-9]{11}|[2-9]{1}[0-9]{3}[\s-][0-9]{4}[\s-][0-9]{4})\b|200|71