M
M
Mark Rosenthal2016-03-27 22:18:24
Information Security
Mark Rosenthal, 2016-03-27 22:18:24

The best DLP system?

Hey!
The organization (350 people) decided to implement the system. I am in charge of the choice. Leadership decision.
Tasks: catch drawings and block the transfer of certain formats, catch company seals, log data transfer events to removable drives (already blocked everywhere, control is needed for a small group), search for text by mask, split glued documents (jpg from .exe) and block it .
It is desirable to work at the network level without the introduction of additional software on computers, because there are a lot of macos (well, or for it to work on macos).
Yes, I didn’t indicate typical functions, although this is an optional functionality, but if it is, let it be: detection of cards, passports, databases, encrypted files, etc.
What is there on the market, what will they give, what will they not?

Answer the question

In order to leave comments, you need to log in

4 answer(s)
A
alx_int, 2016-04-06
@font

Worked with Mcafee. Seen Symantek, Infowatch, Falcongeys, SolarSecurity Dozor.
Almost all work fine with text. Almost everyone uses the ABBYY OCR module.
Nobody knows how to work with drawings. Catching can be done by digital prints.
Infowatch can search by digital fingerprints with a matching threshold, but each file must be uploaded manually through the console web interface. Infowatch announced the search for the seals of the organization, but it was not possible to see how well it works.
McAfee can tag files (but this mechanism is very easily bypassed by copying to a new file without saving).
Falcongaze, Symantec couldn't find the blueprint piece (only 100% match).
I am now in the process of choosing DLP myself, let's connect by mail, share our experience (alexjob24 dog yandex.ru)

M
mace-ftl, 2016-03-27
@mace-ftl

Look at the comrades from userlock.ru - they make solutions for the client with and without agents, the trick is that it is the functionality that needs to be added, well, integration with ciscos, etc.
For 1000 PCs, the price tag turned out to be around 2 million for a full stuffing, you obviously don’t have a full one and there are fewer computers ...

S
Sergey, 2016-03-28
@edinorog

this issue is much easier to solve. usb are cut off programmatically by any of the hundreds of methods known to me. file exchange only through one computer at the secretary.
raising your mailer solves all problems with filtering incoming (by mask) and outgoing (mask and check before sending) documents.
A logging print server makes it easy to see who printed what. and a file exchanger makes it possible to control its contents through masks.
Do you really want to spend money?
I'm not talking about the ban on most protocols for ordinary jobs. Another thing is smartphones with a camera of 40 megapixels with a boom. this is more difficult for IT people to resolve (also solvable).

M
morgan, 2016-03-28
@morgane

I liked the pilot from these comrades.
Excellent parsing at the network level, image recognition, excellent dictionaries and stability of work with the minimum required server resources.
These gentlemen 's product is technically not bad, the interface is somewhat unfriendly, but it's forgivable that one should not miss it.
This is from industrial and stable, all other products on the market are mostly assembled on their knees in the heat of import substitution at best, at worst, unsuccessful attempts to copy foreign systems with illogical adaptation to the Russian Federation.
From foreign countries, Simantek and McAfee show stable results on pilots, but high price tags and a threshold for the entry of specialists to manage systems +, again, initially foreign detection rules that are not suitable for our realities, do not leave a chance for these systems in Russia.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question