Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Working With Web DLP
Working With Web DLP
 
Help | Content Gateway | Version 8.1.x
Related topics:
 
When Websense Content Gateway is deployed with the Web DLP module, the TRITON AP-WEB solution is extended to include:
*
*
When Content Gateway is deployed without the Web DLP module, your deployment still benefits from some data theft forensic data on the Threats dashboard.
TRITON AP-WEB with the Web DLP module
When TRITON AP-WEB is deployed with the Web DLP module, capabilities include forensics data in the Threats dashboard and data loss prevention (DLP) over Web channels such as HTTP, HTTPS, FTP, and FTP over HTTP. (A full TRITON AP-DATA deployment can extend data loss prevention to include channels such as mobile devices, removable media, and printers. For a complete description of TRITON AP-DATA, visit the Products page at www.websense.com.)
Web DLP, as well as extended data protection configurations, require separate installation of TRITON AP-DATA. Before configuring Content Gateway to work with TRITON AP-DATA, see the deployment and installation information hosted in the Websense Technical Library.
Content Gateway supports 2 methods of working with TRITON AP-DATA:
*
*
Only one method can be used at a time.
How Web DLP works
In addition to the Web DLP data flow described below, enabling a special analytic engine called the Policy Engine, causes outbound traffic to be analyzed for data theft. In the Web module of the TRITON Manager, see the Outbound security options on Scanning > Scanning Options.
Web DLP data flow works as follows:
1.
2.
*
*
*
3.
a.
b.
 
Note 
Transactions over HTTP, HTTPS, FTP, and FTP over HTTP can be examined.
Transaction details are logged by TRITON AP-DATA, per its configuration.
TRITON AP-DATA components on-box with Content Gateway
When Content Gateway is installed, a small number of TRITON AP-DATA components are installed on the same box. Content Gateway registers with TRITON AP-DATA components when it's first configured and then checks the registration status whenever it's restarted, automatically re-registering if necessary. For more information about TRITON AP-DATA registration, see Registering and configuring TRITON AP-DATA.
After policies have been created and deployed in the DATA module of TRITON Manager, Content Gateway sends content, such as postings and uploads, to TRITON AP-DATA for analysis and policy enforcement.
Content Gateway collects and displays Web DLP transaction statistics, such as:
*
*
*
*
*
These statistics can be viewed in the Content Gateway manager by navigating to Monitor > Security > Web DLP. For a complete list of statistics, see Web DLP.
TRITON AP-DATA over ICAP
When the Web DLP policy engine is located on a separate host, Content Gateway can communicate with TRITON AP-DATA over ICAP v1.0. For configuration details, see Configuring the ICAP client. Note that integration with on-box components is the preferred deployment.

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Working With Web DLP
Copyright 2016 Forcepoint LLC. All rights reserved.