Skip navigation
McAfee Secure sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams
741 Views 5 Replies Latest reply: May 8, 2013 12:02 PM by bruyere RSS
bruyere Newcomer 4 posts since
Apr 22, 2013
Currently Being Moderated

Apr 22, 2013 1:19 PM

Duplicate Device Instance IDs

We are about to roll out Device control making USB Removable Media Read Only.  The devices are blocked and exceptions are working properly so far.  I have asked my colleagues to send me the Device Instance IDs for any CD/DVD burners that need to be excluded and have noticed that some of the Device Instance IDs are identical.

 

Is using the Device Instance ID the proper way to exclude these devices or will this cause security issues with other computers having the same model of burner installed?

 

I have tried finding the device serial numbers in Device manager but they are not listed.  Also in Windows 7 the ID is listed as Device Instance Location.  Is using the Device Instance Location the same as Device Instance ID?

 

Thanks.

  • Tristan Veteran 790 posts since
    Dec 8, 2009
    Currently Being Moderated
    1. Apr 23, 2013 2:19 AM (in response to bruyere)
    Re: Duplicate Device Instance IDs

    I don't believe a device ID is unique like MAC addresses.

     

    What reason have you decided to use device ID instead of using the built in device classes in DLP?

     

    The easiest way to excluded a subset of burners is probably to create a security group of users and add them as an exclusion to the blocking policy.

  • tonyw McAfee Employee 159 posts since
    May 9, 2011
    Currently Being Moderated
    3. May 7, 2013 9:49 PM (in response to bruyere)
    Re: Duplicate Device Instance IDs

    You might want to try using just a blanket monitor rule for the devices to have DLP collect the device parameters for you.  Once collected, you can then right click on the event and export the device parameters.  When you create your device definition, if the criteria exists for the device (such as serial number), you can import from the exported csv file automatically.

More Like This

  • Retrieving data ...

Bookmarked By (0)

Legend

  • Correct Answers - 5 points
  • Helpful Answers - 3 points