McAfee DLP数据防泄密产品资料

2. 系统代理程序
安装在所有的企业终端 中,用于监控和预防数 据丢失
3. 漫游用户
通过全面的强制实施, 即使是移动便携式计算 机上的数据也会受到保护
4. DLP 报告服务器
位于企业网络中,用于 从各代理处收集数据
5. 数据指纹服务器/数据库
会对机密数据进行指纹 加密,然后将指纹发布 给 SIG DLP 设备
您是否已被法规遵从的分析和核查工作弄得焦头烂额?现在,您可以通过 McAfee DLP 全面 的突发事件报告和监控工具,轻松收集重要数据,例如发送人、接收人、时间戳和数据证明。
McAfee DLP 使您完全控制和监视从终端发出的数据,防止数据丢失,同时还避免您的企业 成为负面报道的头条。
借助于 McAfee DLP,您可以:简单快捷地监控实时活动;采用集中管理的安全策略来规范 和限制员工使用和传输敏感性数据的方式;生成详细的取证报告。而这一切都不会影响您的 日常业务活动。McAfee DLP 可以预防通过内部渠道(如电子邮件、IM、CD 刻录、通过 USB 复制以及活动打印)所造成的数据丢失威胁;此外,您还可以避免由木马、蠕虫病毒或 文件共享应用程序导致的数据丢失,它们会在员工不知情的情况下窃取其身份凭据,从而恶 意获取敏感信息。
即使数据被修改、复制、粘贴、压缩或加密,也能防止数据丢失或泄漏,而合法的业务活动 不会受到影响。这款产品可保护 390 多种数据文件。独特的指纹算法和内容标记选项(位置、 应用程序、文件类型、正则表达式、关键字及其他内容)加强了数据保护的广度和深度,真 正确保了企业数据的安全。
如果能够轻松有效地防止数据丢失,您会不会倍感欣慰?如果同时还能让您确保始终遵从业 界和政府法规,这是否更加振奋人心?现在,一切尽在您的掌握之中!

McAfee DLP终端数据防泄密详细介绍_1.2

McAfee终端数据丢失防护解决方案功能介绍版本历史目录一、前言 (3)二、方案介绍 (3)2.1、数据泄漏的渠道广泛 (3)2.2、McAfee的数据防泄漏(DLP)解决方案 (3)三、保护策略介绍 (5)3.1、ePolicy Orchestrator 4.5 控制台中的Host DLP 策略管理器 (5)3.2、定义保护目标 (6)●外接设备控制 (6)●基于位置的保护 (7)●基于应用程序的保护 (8)●基于内容的保护 (8)●基于注册文档指纹的保护 (9)3.3、保护行为定义及举例 (10)●外设控制 (10)●可移动存储保护规则 (11)●WEB发布保护规则 (12)●打印保护规则 (13)●电子邮件发送保护规则 (14)●PDF/图像转换器保护规则 (15)●屏幕捕捉保护规则 (15)●剪贴板保护规则 (16)●文件系统保护规则 (16)●网络通信保护规则 (17)3.4、策略分配 (18)●基于用户分配 (18)●基于计算机分配 (18)3.5、审计报告过滤 (19)一、前言为了让您更好的认识企业数据保护的重要性,以及如何保护企业核心数据,避免数据泄漏事件的发生,本文档将对McAfee终端数据防泄密解决方案进行举例介绍,希望可以借助本文档让您借助McAfee寻找到适合于您企业的数据保护方法。

• Prevent confidential data loss
• Enforce policies anywhere
• Framework for policy authoring and tuning
• Detect content accurately
为什么需要DLP? 什么是DLP? 赛门铁克是怎么做的?
内部员工或合作伙伴带来 合规要求
• 法律法规可能带来的罚款
• 引起了大多数数据泄漏事件
• 名誉损失
• 68% 的事件是由于员工的疏忽大 • HIPAA, PCI, SOX, Gramm-Leach-
McAfee终端加密技术方案CDB 2020

XXXX加密技术解决方案目录1项目概述 (4)1.1项目背景 (4)1.2全硬盘加密建设需求 (4)2McAfee 加密组件介绍 (5)2.1McAfee公司简介 (5)2.2McAfee Drive Encryption产品介绍 (5)3测试环境 (7)3.1系统要求 (7)3.2加密硬件兼容性以及支持硬盘模式 (8)3.3测试拓扑 (8)4测试场景展现 (10)4.2ePO服务器 (10)4.2.1集中管理 (10)4.2.2群集说明 (11)4.3更改登入Logo (11)4.4Windows域用户实现单点登录 (12)4.5Windows非域用户单点登录 (14)4.6取消McAfee认证界面 (14)4.7Mac系统的全盘加密 (15)4.8系统恢复 (17)4.8.1Windows加密系统恢复 (17)4.8.2Mac加密系统恢复 (18)4.9USB存储加密 (19)5McAfee加密系统性能 (22)6代理部署场景 (23)6.1Windows代理部署 (23)6.2Mac OS X代理部署 (23)6.3部署方式对比 (24)7加密流程解析 (25)8项目实施培训 (26)9.1实施人员 (26)9.2实施阶段 (27)9.2服务方案 (28)9.2.1 McAfee服务等级介绍 (28)1 项目概述1.1项目背景XXXX公司目前大部分员工都配有笔记本电脑,出差频繁,存在笔记本电脑丢失的风险。

全硬盘加密(Device Encryption)
对于被授权的用户和应用程序,文件是全 文本格式并且具有完全的可见性
文件被转换成 为扇区格式
McAfee信息安全技术解决方案录1方案概述62安全需求分析82、1存在的安全风险82、1、1系统终端面临的安全威胁82、1、2网络上存在的安全威胁92、1、3现有安全产品的不足92、1、4安全管理问题102、2需求分析102、2、1在系统层面102、2、2 在网络层面112、2、3整体解决方案113McAfee SRM整体解决方案123、1方案设计原则123、2McAfee SRM安全风险管理解决方案123、2、1什么是安全风险123、2、2McAfee SRM安全风险管理133、2、3安全风险管理体系的实现163、3McAfee SRM 的实现 183、3、1 McAfee SRM 部署步骤 183、3、2McAfeeSRM 部署的产品194McAfee TOPS 及MNAC 的部署204. IMeAfee TOPS的部署204、1、lePO的部署204、1、2防病毒客户端VSE8、5i 及Anti-Spyware8、5的部署224、1、3McAfee HIPS7、0的部署234、1、4SiteAdvisor 的部署 244、1、5部署架构图244、2MNAC的部署254、3部署后的维护建议284、3、1制定严格的病毒防治规范294、3、2建立快速、有效的病毒应急体系304、3、3加强计算机安全培训304、3、4建立动态的系统风险评估措施314、3、5建立病毒事故分析制度314、3、6确保恢复,减少损失314、3、7加强技术防范措施315McAfee IntruShield的部署335、1、1 McAfee IntruShield 系统功能 335、1、2方正证券IntruShield部署方案355、1、3IntruShield产品系列376方案优势386、1TOPS产品特点386、k 1TOPS集中管理服务器ePO386、1、2McAfee VirusScan Enterprise8、5i406、1、3主机入侵防护HIPS7、0446、1、4MNAC (McAfee Network Access Control) 476、2IntruShield 产品优势 486、2、1检测及防御功能496、2、1、1网络攻击特征检测496、2、1、2 异常检测506、2、1、3DoS/DDoS 攻击防御506、2、1、4 入侵防护功能516、2、2实时过滤蠕虫病毒和Spyware间谍程序536、2、3 虚拟IPS536、2、4灵活的部署方式546、2、5具备风险识别的入侵防御566、2、6內置Web安全保护576、2、7永远在线的管理平台576、2、8SSL加密攻击检测586、2、9领先的虚拟內部防火墻586、2, lOMcAfee IntruShield所获最新国际奖项597华东地区金融证券典型案例607、1上海交通银行607、2上海浦发银行647、3上海证券交易所667、4最新案例上海银联681方案概述McAfee作为全球最大的专业安全厂商,为全球100多个国家提供业界领先的基于动态安全风险管理的安全整体解决方案,其最大的特点是:以安全风险的控制为基础,实时地了解安全风险变化的原因,并且结合先进的系统防御和网络防御解决方案,帮助客户及时消除各类安全威胁,建设主动的防御体系和完善的风险管理流程。


McAfee HDLP数据防泄漏方案

McAfee ePO 服务器操作系统 • Microsoft Server 2003 SP1、
Microsoft Server 2003 R2
无与伦比的保护 • 控制用户通过网络、应用程序和存储设备发
McAfee DLP Endpoint 只是全面数据保护解决方 案的一部分。McAfee Total Protection™ for Data 将 McAfee DLP Endpoint 和 McAfee Endpoint Encryption 相结合,提供了一套更加全面的数据保 护解决方案。
• 通过监控并防范针对企业最敏感数据的高风险用 户行为,基于主机的防护可以防止数据通过企业 的终端设备泄漏出去
• Microsoft Windows XP • Professional SP1 或更高版本 • Microsoft Windows 2000 SP4 或 更高版本
• 全面监控 - 向审计人员、高级管理 人员和其他利益相关者证明遵从了 内部安全策略和相关法规
0 数以百万计的成本损失。
451 防止数据丢失应做到防患于未然
60 每天都会有与您企业类似的公司因信息被恶意或 借助该解决方案,即使数据被修改、复制、粘贴、
借助于 McAfee DLP Endpoint,您可以:简单快 成为负面新闻报道的主角。

【摘要】赛门铁克公司宣布,计划推出针对平板电脑的全新数据泄露防护解决方案(Symantec Data Loss Preventionfor Tablet),这是业界首个专门用于监控和保护平板电脑中敏感信息的全面数据泄露防护(DLP)解决方案。
一. 数据库防火墙与传统安全防护产品的区别1.1 传统防护模式IDS/IPS的局限IDS和IPS都是基于IP的防护手段。
McAfee Total Protection for Small Business解决方案

McAfee Total Protection for Small Business 解决方案为您的企业提供不间断的、及时更新的单一防护解决方案新的威胁每天层出不穷。
McAfee 为中小型企业提供了业界首次推出的真正的集成系统安全解决方案,这些价格合理的解决方案可由单一控制台进行管理。
McAfee Total Protection for Small Business 和Total Protection for Small Business - Advanced 是作为 McAfee托管的单一解决方案提供的。
成熟的技术借助成熟的技术,McAfee的这两套解决方案可以轻松简化您的安全管理:→通过单一易用、基于Web的管理和报告控制台 - McAfee SecurityCenter 来实现集中管理→除了 Outlook 应用程序提供的基本电子邮件保护功能以外,集成的桌面机和文件服务器病毒防护和反间谍软件功能也可自动保护您的系统免受已知威胁和潜在的恶意程序的侵扰→桌面机防火墙在您的重要数据和恶意入侵之间建立了一道即时的屏障→先进的电子邮件垃圾邮件防护和病毒防护服务可以提供及时的电子邮件防护更新,以提高可用性并确保业务连续性→借助病毒防护和内容过滤功能,先进的电子邮件服务器防护通过一套解决方案实现出色的安全防护Total Protection for Small Business 或Total Protection for Small Business - Advanced是单一的、集成的软件服务。

COPYRIGHT
Copyright©2009McAfee,Inc.All Rights Reserved.No part of this publication may be reproduced,transmitted,transcribed,stored in a retrieval system,or translated into any language in any form or by any means without the written permission of McAfee,Inc.,or its suppliers or affiliate companies.
TRADEMARK ATTRIBUTIONS
AVERT,EPO,EPOLICY ORCHESTRATOR,FLASHBOX,FOUNDSTONE,GROUPSHIELD,HERCULES,INTRUSHIELD,INTRUSION INTELLIGENCE, LINUXSHIELD,MANAGED MAIL PROTECTION,MAX(MCAFEE SECURITYALLIANCE EXCHANGE),MCAFEE,,NETSHIELD, PORTALSHIELD,PREVENTSYS,PROTECTION-IN-DEPTH STRATEGY,PROTECTIONPILOT,SECURE MESSAGING SERVICE,SECURITYALLIANCE, SITEADVISOR,THREATSCAN,TOTAL PROTECTION,VIREX,VIRUSSCAN,WEBSHIELD are registered trademarks or trademarks of McAfee,Inc. and/or its affiliates in the US and/or other countries.McAfee Red in connection with security is distinctive of McAfee brand products.All other registered and unregistered trademarks herein are the sole property of their respective owners.
LICENSE INFORMATION
License Agreement
NOTICE TO ALL USERS:CAREFULLY READ THE APPROPRIATE LEGAL AGREEMENT CORRESPONDING TO THE LICENSE YOU PURCHASED, WHICH SETS FORTH THE GENERAL TERMS AND CONDITIONS FOR THE USE OF THE LICENSED SOFTWARE.IF YOU DO NOT KNOW WHICH TYPE OF LICENSE YOU HAVE ACQUIRED,PLEASE CONSULT THE SALES AND OTHER RELATED LICENSE GRANT OR PURCHASE ORDER DOCUMENTS THAT ACCOMPANIES YOUR SOFTWARE PACKAGING OR THAT YOU HAVE RECEIVED SEPARATELY AS PART OF THE PURCHASE(AS A BOOKLET, A FILE ON THE PRODUCT CD,OR A FILE AVAILABLE ON THE WEB SITE FROM WHICH YOU DOWNLOADED THE SOFTWARE PACKAGE).IF YOU DO NOT AGREE TO ALL OF THE TERMS SET FORTH IN THE AGREEMENT,DO NOT INSTALL THE SOFTWARE.IF APPLICABLE,YOU MAY RETURN THE PRODUCT TO MCAFEE OR THE PLACE OF PURCHASE FOR A FULL REFUND.
License Attributions
Refer to the product Release Notes.

McAfee Host Data Loss Prevention Best Practices:Protecting against data loss from external devices

Contents
Protecting against data loss from removable devices and file systems (4)
Device control (4)
Content protection rules (6)
Examples (8)
Use case:Blocking wireless communication (8)
Use case:Making all USB removable storage read-only except authorized devices (10)
Use case:Blocking files containing personal identity information (11)
Use case:Blocking files created by a GIS application (13)
Use case:Disabling all CD/DVD burners from writing (14) Cons:•The device blocking is based only on the device attributes and does not inspect content.•Can only block or monitor.Cannot make a device read only.Recommended use cases:•Block all Bluetooth adapters and modemsThe enterprise wants to restrict end users from using Bluetooth and modem communication to transfer data.•Block all Wireless communicationThe enterprise wants to restrict end users from using wireless communication while connected to the corporate network.See Use case:Blocking wireless communication.Removable storage device rulesRemovable storage device rules are used for blocking and monitoring removable storage devices such as flash drives,MP3players,and external hard drives.They can block,monitor,or configure the removable storage to read-only.Whenever a new removable storage device is plugged into the computer,McAfee Device Control will match the new device attributes against the device attributes defined in the removable storage device rule.If a match is found McAfee Device Control will perform the action defined by the device rule.Removable storage device rules work on the file system level,and allow for more flexibility than Plug and Play device rules.For example,the removable storage device rule can match a device based on its file system type(NTFS,FAT32)or file system volume label.In addition,they provide more accurate device names.For example an iPod is recognized by the Plug and Play mechanism as USB mass storage device,whereas the removable storage rule recognizes it as Apple iPod, which is more meaningful.(This description fits older iPods.The iPod Touch is recognized as a Windows Image Acquisition device.)McAfee recommends using removable storage device rules,rather than Plug and Play device rules,to control all devices that provide removable storage,such as USB mass storage devices, Flash Drives("Disk on Key"),and CD\DVD.NOTE:Since Plug and Play device rules are applied on the device driver level,they are applied before removable storage device rules.The implication is that if a removable storage device is blocked by both types of rule,the removable storage device rule will not be applied.Pros and cons of removable storage device rulesPros:•Allow read-only mode for removable storage devices.•Allow for greater flexibility for device matching(file system type,volume label).Cons:•The device blocking is based only on the device attributes and does not inspect content. Recommended use cases:•Make all USB removable storage read-only except authorized devices.An enterprise has purchased a specific brand of encrypted flash drive and would like to restrict the use of any other flash drive.See Use case:Making all USB removable storage read-only except authorized devices.•Disable all CD/DVD burners from writing.The enterprise wants to restrict engineering end users from using CD/DVD burners to writeCDs.McAfee Device Control is not able to analyze the content written to CD/DVD thereforeremovable storage device rules should be used.See Use case:Disabling all CD/DVD burnersfrom writing.Content protection rulesUnlike device control functionality that blocks the entire device,content protection rules protectindividual files based on their content.When a file is copied to a network shared folder or aremovable storage device McAfee Host Data Loss Prevention performs deep content analysisto classify the content,and performs one(or more)of the following actions:•Block—Moves the file to the local quarantine folder and deletes its content from the removable storage.This action is not available for network shared folders.•Monitor—Sends an incident event to the Host DLP(in version3.0,the ePolicy Orchestrator) database for monitoring and case management.•Store Evidence—Stores the original file that was copied so it can be viewed in the Host DLP Monitor.•Notify user—Shows a popup to the end-user as notification of the action that was performed.•Encrypt—Encrypts the file using McAfee Endpoint Encryption.This action is available in McAfee Host Data Loss Prevention software version3.0.Removable storage protection rulesRemovable storage protection rules allow for blocking and monitoring of individual files beingwritten to removable devices according to file attributes and their content classification.Whena file is copied to a removable storage device,the Host DLP Agent inspects,analyzes,andclassifies the file content,and if the file classification matches one or more of the removablestorage protection rules,the agent will apply the action defined in the rule.Host DLP provides several content classification techniques,including:•Regular expression matching•Keyword•Application that created or edited the file•Current storage location•Where the file is being copied to.McAfee recommends using removable storage protection rules whenever an enterprise allowsuse of removable storage devices,but wants to restrict(or monitor)the data that is written tothem.Pros and cons of removable storage protection rulesPros:•Allow blocking individual files according to their content and attributes,rather than block the entire device.Cons:•McAfee Host Data Loss Prevention software uses CPU resources to analyze every file copied to removable media.Recommended use cases:•Block copying of files containing personal identity information(PII).There are many forms of PII:Social Security Number(SSN),driver's license number,National Identification Number,and so on.McAfee Host Data Loss Prevention contains pre-defined regular expression patterns(Secured Text Patterns)that can be used to create these rules.See Use case:Blocking files containing personal identity information.NOTE:McAfee Host Data Loss Prevention software version3.0introduces regular expression validators to reduce false positives.•Blocking copying of files created by a Geographic Information System(GIS)application to removable storage.Certain applications create files that contain binary information that cannot be content inspected.McAfee Host Data Loss Prevention software provides a unique technology to classify content based on the application that creates or edits the file.See Use case:Blocking files created by a GIS application.By creating application-based tagging rules the Host DLP Agent can tag any file that is created by a GIS application.This tag can then be used in removable storage protection rules to block or monitor copying of GIS files to removable storage.Network file system protection rulesNetwork file system protection rules are very similar to removable storage protection rules,but they apply to the Windows network file system(shared folders)rather than devices.They support monitoring files copied to a defined Windows share,but it do not support blocking the copy operation.McAfee Host Data Loss Prevention software version3.0introduces the ability to encrypt files that are copied to the network,to enforce compartmentalization policies,using McAfee Endpoint Encryption.Recommended use cases:•Monitor all files containing credit card numbers being copied to public folders on a file server.Many organizations provide public folders for file sharing on the network.Reckless users can copy sensitive files to these ing McAfee Host Data Loss Prevention you can create a network file system protection rule to Monitor,Notify User,and Store Evidence for every file that contains sensitive information,such as credit card numbers,when copied to the public folder on the network.Ideally,such files should also be encrypted.•Compartmentalization(available in McAfee Host Data Loss Prevention software version3.0 using McAfee Endpoint Encryption integration)Assume your organization has an engineering group,a finance group,and a sales group.You can use the McAfee Host Data Loss Prevention software version3.0and McAfee Endpoint Encryption integration to generate three encryption keys—FINANCE_KEY,ENGINEERING_KEY and SALES_KEY.Each key is available only to members of that group to unlock ing these keys in network file system protection rules can ensure that every sensitive file that is copied to a network shared folder will be properly encrypted,and visible only to authorized users.ExamplesThe following examples demonstrate the techniques discussed in the text.ExamplesUse case:Blocking wireless communicationUse case:Making all USB removable storage read-only except authorized devicesUse case:Blocking files containing personal identity informationUse case:Blocking files created by a GIS applicationUse case:Disabling all CD/DVD burners from writingUse case:Blocking wireless communicationAssume an organization wants to restrict end users from using wireless communication whileconnected to the corporate network.With McAfee Device Control it is possible to define a policythat differentiates between users who are online(connected to the corporate network)andthose who are offline.The following example shows how to block wireless adapters while auser is connected to the corporate network.Example1In the Navigation Bar under Device Management,select Device Definitions.2Right-click in the device definitions panel,and click Add New|Plug and Play Device Definition.Type Wireless Network Adapters to rename,and press Enter.3Double-click the device definition to edit it.Select Device Class,then select Network Adapters and click OK.4Select Device Name.The definition parameter edit dialog box appears.5Click Add New and type wireless into the text box.Select the Allow Partial Match option.6Click Add New and type wlan into the text box.Select the Allow Partial Match option.7Click Add New and type802.11into the text box.Select the Allow Partial Match option.Click OK twice to complete the definition.8In the Navigation Bar under Device Management,select Device Rules.9Right-click in the device definitions panel,and click Add New|Plug and Play Device Rule.Type Block wireless network adapters when online to rename,and press Enter.10Double-click to edit the rule.Select Wireless Network Adapters in the Include column.Click Next.11Select Block,Monitor,and Notify User.12For each action,deselect the Offline option.Click Finish .Use case:Making all USB removable storage read-only except authorized devicesAssume an organization that purchased a specific brand of encrypted flash drives and wouldlike to restrict the use of all other flash drives.Example1In the Navigation Bar under Device Management ,select Device Definitions .2Right-click in the device definitions panel,and click Add New |Removable Storage Device Definition .Type USB Removable Storage to rename,and press Enter .3Double-click the device definition to edit it.Select Bus Type ,select USB and click OK .4Right-click in the device definitions panel again,and click Add New |Removable Storage Device Definition .Type McAfee Encrypted USB Devices to rename,and press Enter .5Double-click the device definition to edit it.Select Bus Type ,select USB Vendor ID/Product ID and click Add New .The definition paramete edit dialog box appears.6Click Add New to add each of the following devices:Description Product ID Vendor IDMcAfee Standard Encrypted USB 022A 1A4BMcAfee Standard Driverless Encrypted USB 32201A4BMcAfee Zero-Footprint Bio32001A4BDescriptionVendor IDProduct ID35001A4BMcAfee Zero-Footprint Non-Bio34001A4BMcAfee Encrypted USB Hard Disk TIP:Use the mouse to select the Product ID and Description text boxes.7In the Navigation Bar under Device Management,select Device Rules.8Right-click in the device definitions panel,and click Add New|Removable Storage Device Rule.Type Block all USB except McAfee to rename,and press Enter.9Double-click to edit the rule.Select USB Removable Storage in the Include column, and select McAfee Encrypted USB Devices in the Exclude column.Click Next.10Select Monitor,Notify User and Read Only.Click Finish.Use case:Blocking files containing personal identity informationThe following example shows how to create a content-based tagging rule that will tag any filecontaining a social security number,and how to create a removable storage protection rulethat will prevent copying these files to removable storage.Example1In the Navigation Bar under Rules,select Tagging Rules.Right-click in the tagging rules panel,click Add New|Content Based Tagging Rule,and type SSN Tagging Rule torename the rule.2Double-click the rule to edit it.From the pre-defined list of secured text patterns,check Social Security Number.Click Next.3On the tags page,click Add New,type SSN Tag in the Name text box,click OK,then Finish.4In the Navigation Bar under Rules,select Reaction Rules.Right-click in the panel,click Add New|Removable Storage Protection Rule,and rename it Block PII copied toremovable storage.5Double-click the rule to open the wizard.You can skip all of the steps except the following:a On the tags page,select the SSN tag created in step4.b On the actions page,select Block,Monitor,Notify User,and Store Evidence.Use case:Blocking files created by a GIS application The following example shows how to create an application-based tagging rule that will tag anyfile that is created or edited by a Geographic Information System(GIS)application,and howto create a removable storage protection rule that will prevent copying GIS files to removablestorage.Example1In the Navigation Bar under Applications,select Enterprise Applications List.2Right-click in the application list panel,and click Add.Browse to the GIS application executable,then click Open.Note the exact executable name.You will need it in the nextstep.Click Add,then Close.3In the Navigation Bar under Applications,select Application Groups.Right-click in the panel,and click Add New|Application Group.Type GIS Applications in the Name textbox and press Enter.4Double-click the GIS Applications group.Browse to the name of the vendor and select it.Click the plus sign next to the name to view the details.If there are other products bythe same vendor you don't want to include in the rule,deselect them.5In the Navigation Bar under Rules,select Tagging Rules.Right-click in the tagging rules panel,click Add New|Application Based Tagging Rule,and type GIS Tagging Rule torename the rule.6Double-click the rule,select GIS Applications,then click Next.7(Optional)Click Select from list,select Graphic files,then click Next three times to reach the Tags page.8Click Add New,name the tag GIS Tag,click OK,then Finish.9In the Navigation Bar under Rules,select Reaction Rules.Right-click in the panel,click Add New|Removable Storage Protection Rule,and rename it Block GIS files copiedto removable storage.10Double-click the rule to open the wizard.You can skip all of the steps except the following:a On the tags page,select the GIS Tag created in step6.b On the actions page,select Block,Monitor,Notify User,and Store Evidence.Use case:Disabling all CD/DVD burners from writing Assume an organization wants to restrict engineering end users from using CD/DVD burnersto write CDs.McAfee Host Data Loss Prevention is not able to analyze the content written toCD/DVD,therefore removable storage device rules should be used.Limitation:The following CD/DVD burners are not protected in McAfee Host Data LossPrevention v2.2:•Alcohol120%•Iomega HotburnExample1In the Navigation Bar under Device Management,select Device Definitions.2Right-click in the device definitions panel,and click Add New|Removable Storage Device Definition.Type CD/DVD Devices to rename,and press Enter.3Double-click the device definition to edit it.Select CD/DVD Drives and click OK to close the definition dialog.4In the Navigation Bar under Device Management,select Device Rules.5Right-click in the device definitions panel,and click Add New|Removable Storage Device Rule.Type Block all CD-R burning to rename,and press Enter.6Double-click to edit the rule.Select CD/DVD Devices in the Include column.Click Next. 7Select Notify User and Read Only.Click Finish.。
需要指出的是,本文档所涉及到的文字、图表等,仅限于McAfee 公司和XX内部使用,未经McAfee公司书面许可,请勿扩散到第三方。
目录1方案概述 42中铁信托数据保护需求分析 62.1.1系统终端面临的数据泄露风险 62.1.2不可管理终端的数据泄漏威胁 72.1.3安全管理问题 72.2需求分析 72.2.1数据流失保护 73McAfee 数据保护整体解决方案 83.1McAfee Total Protection for Data解决方案 83.1.1McAfee Total Protection for Data的具体功能 83.2McAfee Total Protection for Data工作流程 94McAfee Total Protection for Data的部署 124.1部署架构及工作流程 121 方案概述中铁信托有限公司和大部分金融企业一样,经营和管理过程中会产生大量的数据,如大量的客户数据、经营交易数据、财务数据和其他重要的管理数据,这些重要数据就像是生命中的“血液”一样重要,是企业生存的基础。
和金融相关的众所周知的比较著名的数据泄漏事件有:1)TJX--攻击者窃取了4570 万个信用卡和借记卡数据,造成的后果是企业形象受损和法律诉讼;2)CardSystems公司--网络罪犯攻击了 4 千万个 Visa/ MC/Amex 用户;后果是CardSyestems 现在已宣告破产;3)ChoicePoint公司--诈骗公司使用购买ChoicePoint 产品的消费者记录;后果是2600万美元的罚款以及股票市值缩水8 亿多美元;4)Wells Fargo--泄露了3300 万个客户的帐户;后果是为了符合州数据泄露法案的要求,仅邮寄的成本就高达 1900 万美元。
无论是黑客攻击、还是内部故意泄露,数据泄漏有以下三个途径造成:1) 物理途径——从桌面计算机、便捷计算机和服务器拷贝数据到USB,CD/DVD和移动硬盘等移动存储介质上;通过打印机打印带出公司或者通过传真机发送。
2) 网络途径——通局域网、无线网络、FTP、HTTP、HTTPS发送数据,这种方式可以是黑客攻击“穿透”计算机后造成,也可能是内部员工从计算机上发送。
3) 应用途径——通过电子邮件、IM即时信息、屏幕拷贝,P2P应用或者“特洛伊木马”窃取信息。
图1.1数据泄漏的三种途径McAfee Data Loss Prevention(以下简称DLP)解决方案可以有效保护企业的重要机密数据,免于数据泄漏的风险。
McAfee DLP Host具有内容感知功能,当数据在网络、物理设备和应用程序等易导致数据丢失的渠道中传输时,根据预先定义的策略,提供全面的保护。
McAfee数据保护解决方案通过基于主机和基于网关的两层保护提供了全面的防护:基于主机的保护(产品名称:McAfee Data Loss PreventionHost)——保护公司和移动中(在家里和在路上)的终端、服务器上的数据;我们建议中铁信托有限公司在网络和终端层面全面部署McAfee Total Protection for Data解决方案,对核心的数据实现全面的安全保护功能,防止数据的非授权泄露。
2 中铁信托数据保护需求分析2.0.1 系统终端面临的数据泄露风险企业的各类机密数据和敏感信息可能通过网络传输、共享文件、移动存储、邮件、应用程序等多种方式进行传播,造成数据的泄漏;内部人员可能通过各类新型的应用程序(如截图工具、内容复制工具等)把文件或数据传输出去;企业员工也可能在无意之间将数据遗留在某些移动存储介质之上,造成泄漏;某些物理打印机及扫描仪的使用,也可能造成企业机密信息的泄漏;数据一旦泄漏,可能给企业带来无法估量的损失;笔记本电脑及各类移动终端的丢失,可能造成的数据遗失;U盘的非法使用带来的机密数据的泄漏;终端层面的数据保护往往面临着难以想象的复杂性,给管理和配置带来一定难度,一定程度上造成数据保护产品的使用效果难以保证。
2.0.2 不可管理终端的数据泄漏威胁企业内部除了可以管理的计算机终端之外,往往还有很多外来接入的计算机,例如外来访问人员、合作伙伴、供应商以及我们的客户,这些计算终端我们往往没有权利安装任何客户端程序,但是他们也很可能造成机密信息的泄漏:(1) 不可管理终端在使用企业数据的过程中无意的泄漏(通过网络访问);(2) 不可管理终端的使用人员有意造成的数据泄漏;(3) 泄漏行为难以审计和记录;2.0.3 安全管理问题部署的数据防泄漏产品,在切实保护数据泄漏并完成数据加密之后;还需要在整体上实现部署、管理和审计,并实现主动的信息安全策略。
2.1 需求分析结合上面的威胁分析,我们可以看到当前网络存在数据泄漏的风险;因此,需要采取相应的措施来消除这些威胁,降低整体安全风险,确保OA和应用网络的数据安全,具体需求可以归纳为以下几个方面:2.1.1 数据流失保护通过部署先进的数据保护类产品,在所有的客户端实现数据保护,并完成统一管理;通过数据保护客户端对用户的网络行为进行检测,阻断数据泄漏行为;通过数据保护客户端对具体应用进行检测,阻断数据泄漏行为;通过客户端程序,有效的审计各类数据调用行为,并记录全部用户行为;数据防护产品必须具有同一的管理平台,且只有一个客户端代理,以最大限度的节省系统资源,提升管理效率;3 McAfee 数据保护整体解决方案3.1 McAfee Total Protection for Data解决方案McAfee基于国际信息安全标准,结合中铁信托的现实,建议客户在考虑信息安全体系建设的过程中,应该首先根据自身情况,结合国际先进的数据保护解决方案,明确数据保护的四个重要方面及控制手段,有计划有步骤的加强整个数据保护体系的建设,才能达到最好的效果。
3.1.1 McAfee Total Protection for Data的具体功能McAfee TOPS for Data的四个组件,分别完成了数据保护流程里边的重要方面,如下所述:(1) 数据流失保护——McAfee DLP Host保护敏感资料不被有意或无意的泄漏全面控制数据的使用和存储使得基础架构和数据本身拥有防护能力详细的记录,事件搜集实时防护和阻挡通知用户和管理员隔离敏感数据(2) 设备控制——McAfee Device Control监控并且只允许授权的设备连接到内网;限制并且阻挡未授权的设备连接,比如外部的MP3,U盘;强制控制可以被复制到授权设备上的数据内容;全面控制数据和设备;仅允许指定的设备;指定什么数据可以被复制;基于用户,组,部门进行策略制定,例如允许CEO连接任何U盘,而其他员工只能使用特定的U盘;详细记录用户和设备的访问信息以符合审计和合规的要求。
综上所述,通过McAfee TOPS for Data,McAfee可以帮助中铁信托建立全面的数据保护体系,从软件系统到硬件的边界防护,从内部人员的有意泄露到外部人员的非授权访问,均能够实现全面的保护。
3.2 McAfee Total Protection for Data工作流程McAfee DLP从物理、网络和应用三个途径进行全面的绝对防护:McAfee DLP具体工作流程图1) 防范数据通过以下渠道丢失:电子邮件、IM、FTP、HTTP、HTTPS、gmail、hotmail、USB、CD、DVD、iPod、打印、复制/粘贴、屏幕抓取、P2P 等2) 保护 390 多种数据文件3) 即使数据被修改、复制、粘贴、压缩或加密,标记功能仍能使防护发挥作用4) 高度准确性:--独特的指纹算法--强大的正则表达式引擎--基于位置和基于环境的分类方法DLP对企业范围数据提供实时和离线的完整监控,保护数据和发现策略违规:1) 及时收集详细的证据和报告--发信人、收信人、时间戳、组、内容等2) 轻松实现全球、组和个人级别的控制--监控(允许)--预防(拦截)--隔离(等待安全小组的授权)--加密(在数据传输之前进行加密)--警告(通知管理员和最终用户)3) 移动保护功能:--无论用户身在何处,均可防范通过便携式计算机转移敏感数据通过使用McAfee DLP数据泄漏保护,可以帮助企业实现:• 保护机密数据、财务数据和知识产权;• 机密用户数据--信用卡号、姓名、地址和个人身份信息等;• 知识产权--专利、源代码、设计、商业秘密和公式;• 支持法规遵从、留住客户、保持竞争优势、保护品牌和客户信任;• 法规遵从/品牌--职员复制/粘贴客户数据并无意中将这些数据通过电子邮件发送出去,DLP将实时拦截数据的发送;• 客户--不如意的销售人员在去竞争对手那里工作之前计划将客户信息打印出来,McAfee DLP将阻止这些信息的打印;• 优势--用户试图通过U 盘窃取公司的源代码,然后带去另一个公司,DLP将阻止这些保护的源码• 避免罚款、法律诉讼和整理等成本• 您会因解决了一个巨大的业务问题而备受重视4 McAfee Total Protection for Data的部署4.1 部署架构及工作流程1) McAfee 数据流失保护全面的控制和基于用户操作的数据保护:• 在日常工作中保护数据避免出现突然泄漏;• 监测数据的操作:— 详细的记录,事件搜集;— 实时防护和阻挡;— 通知用户和管理员;— 隔离敏感数据。
McAfee DLP具有统一的数据管理平台ePO,同时,通过在各个系统终端部署DLP客户端实现对客户端数据的全面保护。