Skip to main content
McAfee MVISION Cloud

Use Keywords in DLP Policies

In DLP policies, keywords allow you to specify search terms or expressions that are compared to words in files.

For information about using custom keywords with Data Identifiers, see DLP Policy Rules and Rule Groups

Keyword-based Search

To use keyword-based searches, you can enter keywords in a DLP policy. MVISION Cloud then matches documents that contain the keywords. You can set a policy to search on just a word, or on a phrase. (Make sure to put a phrase within "quotation marks".) 

You can also set a proximity match, which allows you to define how many words can separate keywords and still trigger a match. If two keywords are found within the number of words (set with ~n where n is the number of words), it's a match. 

When the Keyword box is activated, the rule also looks for one of the keywords within 200 characters (about 30 words) before and after the identified data as another validation to reduce false positives. 

As of the MVISION Cloud 3.9 release, the keyword proximity is variable and can be between 1 and 10000 characters. You can specify this value through the custom Proximity Distance value when keyword validation is enabled.  Existing policies are fixed at 200 characters; but, when you create a policy as of release 3.9, you can specify a variable proximity value between 1 and 10000. 

Keyword 2 is used as a secondary set of keywords as an AND condition, where keywords from both lists must be present. 

For example, say a document contains the following sentence:

This company confidential document was written in San Francisco and contains secret details.

The following table includes examples of how keyword-based searches in a DLP policy would work on the example sentence. 

Query Result Notes
Secret Match Keyword-based searches are case insensitive.
cisco No Match "cisco" is not seen as an exact match to "San Francisco".
secret info Match The query tells MVISION Cloud to find documents that contain either "secret" or "info," and because the document contains "secret", it is a match.
"secret details" Match This is an exact phrase match. To define a phrase query, put the terms inside quotation marks to match exactly, including the quotes. For example, "secret details" matches "secret details" including quotes, but not secret details without quotes. 
"document secret”~10 Match The proximity defined at ~10 means the policy matches if the words in the phrase are found within 10 words of each other. Because it is a phrase, both words must be found.
"company secret"~3 No match The proximity, defined as ~3, means that there are too many words between "company" and "secret" for this to be identified as a match. 

Create a Keyword DLP Policy

To add a keyword to a DLP policy:

  1. Choose Policy > DLP Policies.
  2. Click Actions > Create New Policy to create a policy. (See Create a DLP Policy from a Template for information about templates.)
  3. Enter a descriptive name to identify the policy from the policy selection screen in later steps.
  4. For Type, choose an integration method. Some user actions and response actions depend on the Type you choose.
  5. For User Groups, add groups to include or Exclude.
  6. For Rules, click Add Rule and choose Keyword.
  7. Click edit (pencil icon) to the right of the Keyword text box.
  8. In the Edit Keywords dialog box, choose an option
    • Match Criteria
      • Match Any (which is the default) creates a match when any keyword is found in a file.
      • Match All means a match is created only when all keywords are found in a file.
    • Match Count. Specify the number of unique matches and perform additional keyword validation.
    • Case Sensitive: Select No or Yes to consider case sensitivity. 
    • Match Special Characters. When this option is set to Yes, then the keywords in the dictionary are matched exactly, as is. If keywords are enclosed in quotes, a match occurs only if the document includes that keyword enclosed in quotes too. We recommend that you don't enclose keywords in quotes when this option is selected, unless you are trying to match exactly (quotes included).
      • If Yes is selected, only the exact special characters trigger a match, including quotation marks.
      • If No is selected, any special character triggers a match.
      • For Example, when matching "M&A":
        • Yes. Only "M&A" (including quotes) triggers a match.
        • No. M&A, M-A, and M#A all trigger a match.

dlp_policy_edit_keywords_4.0.png

  1. If you have a dictionary file, select Use a predefined dictionary, and then choose it from the Select Dictionary list.
  2. If you would like to use new keywords in this DLP policy, enter them in the text box. You can enter keywords as:
    • Single keywords.
    • Phrases. Enclosed in "quotation marks". 
    • Proximity-based phrases. The phrase is enclosed in "quotation marks" followed by ~n, where n is the maximum number of words that can separate the keywords. For example, "aba routing"~3 is a match in a document where the words aba and routing are separated by up to three words, but no more.
  3. Click Save.
  4. Location. Specify if the match should be located in:
    • Email Subject, Body, Attachments, and File Content
    • Email Subject and File Metadata
    • All
  5. Choose any other options, then click Save.
  • Was this article helpful?