Skip navigation
McAfee Secure sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams
543 Views 2 Replies Latest reply: Jun 19, 2013 4:16 AM by kubaros RSS
virgona Newcomer 27 posts since
Apr 14, 2013
Currently Being Moderated

Apr 30, 2013 1:10 PM

False-positive detection and notification by HDLP

Hi All,

 

What "false-positive" I talk about here is not real false-positive, it looks more like a bug for notification. I don't know what is the exactly suited word in English because of my poor English, let me give you an example. Sometimes after DLP detects a event defined in a rule, if I don't close the process related, when I open a file which is not in defination and should not be detected using the same program and it shares the same process with first detected file, there is a notification for detection new opening (I defined notification in rule actions page.), but the file name (if existing) is not the filename which is not in defination. And normally I will not find the event in DLP Monitor. For Clipboard Protection Rule, if a definded file triggers the rule, I will not be able to copy content from all files opned by same process. After clsoe the process, all non-defined files are back to uncontrolled mode.

 

It is hard for me to do a test, for it is not always working in way.

 

Is this by design? or a bug? or I did something wrong on rule defination?

More Like This

  • Retrieving data ...

Bookmarked By (0)

Legend

  • Correct Answers - 5 points
  • Helpful Answers - 3 points