Professional Documents
Culture Documents
Conference of
Informatics
University of
Piraeus
Sokratis K. Katsikas
Outline
1.
2.
3.
Implementation.
Data Loss
Prevention
Firewalls and
Data Loss
IDSs
Prevention
Extrusion
Prevention
Information Loss Prevention
Data Loss
DLP
Prevention
Content Monitoring and
Filtering
Data Loss
Protection
Types of DLP
3 Primary
Data
Data
in
at
in
Motion
Use
states of
Rest
Information
DLP
Network DLP
Central Management
Console
DLPs Basic
Characteristic
Content
Content
What
and
Discovery
Awareness
Where?
OpenDLP
Windows filesystem
Free
,
Open
Source,
Only
deals
with
Components:
Encryption
Regular
Windows Network
agent
and
agentless
the
Endpoint
Share
Web
expressions
defeats
this
tool
based
DLP
software
UNIX Filesystem
application
tool
found
in
Microsoft SQL
Agents
OpenDLP
More information:
1. OpenDLP, Available online:
https://code.google.com/p/opendl
p/
.
2. OpenDLP:
prevention
online:
Data
tool,
loss
Available
MyDLP
Data in motion
Free
DLP
Agent
based
Windows
OS
Data at tool
rest .
software
Data in use
MyDLP
Enterprise Edition
Community
Edition
MyDLP
More information:
1. R.
K,
Open
Application:
Source
DLP
MyDLP,
Data
Leak/Loss
Available
Prevention
Online:
http://www.excitingip.com/3950/open-source-dlp-data-leaklos
s-prevention-application-mydlp/
.
2. MyDLP, Available Online: http://www.mydlp.com/why-mydlp/.
3. MyDLP Administration Guide, Version 2.0, MyDLP, 2012.
4. MyDLP Endpoint Installation Guide, Version 2.0, MyDLP,
2013.
5. MyDLP Installation Guide, Version 2.0, MyDLP, 2013.
Main Goal
DLP solution based exclusively on free
software tools.
MyDLP and OpenDLP.
Combination and colaboration.
MyDLP
OpenDLP
Data in Motion
Data at Rest
Data in Use
Data at Rest
and where.
n
o
i
t
c
Se
?
?
?
Tit
l
e?
?
Benefits:
1. Limit
resources
consumption
2. Increase
speed
detection
Policies
2.
3.
Event
OpenDLP.TO REPLACE
NOT
scheduling
OpenDLPs
scan results
THE WEB
comparison.
mechanism
PLATFORMS
OpenDLP Automation
Selenium
Export
and
HTML
elements
Start
scan
Webdriver
save results
Existing
Data
If
filename
EXISTS,
Md5
ifif filename
AND
md5
values
filename
AND
md5
value
Current
Previous
Scan
Scan
XML
Document
File
File
unchanged
Modified
Deleted
value
NOT
in
current
scans
NOT
in
current
scans
results
EXIST
in
current
scans
Modification
Results
Results
results
results
Results Comparison
New
If
Data
filename
Entries
New
data
entries
New
If filename
File Detected
NOT inor
New
Data
detection
EXISTS,
Detected
but
files
detected
sent to
previous scans
pattern
NOT
in
administrator
via
eresults
previous
mailscans
MyDLP Automation
Flash
app
Use
of Selenium
Limitation
disassembling
not
Webdriver NOT
reliable
possible
Sikuli
Create
rules
based
on
Parse
OpenDLPs
detected
Custom
user
object
Image
Recognition
customdata
user object
Technology
Conclusion
Solid DLP services at no
cost!
Combination of tools
counterbalances
weaknesses.
Automation increases
systems capabilities.
References
References
Questions ??
?