Skip Links

Network World

RE: Data-leakage prevention tools catch errors, not theft

Of course this is the case. Data leakage prevention tools are Leak, not theft, prevention. The problem from a compliance standpoint, is there is no dfference between an inadvertant and an intentional disclosure. You can stop the stupid, but you cannot stop the evil. The best think you can do to address the "evil" (by evil I mean those who are intent and determined to do something wrong)is have good data forensics, that way when it becomes apparent that data has been leaked (say IP to a competitor) is have tools in place to determine who, what, where and when, that way you can have evidence take action, be it a personnel action, or a leagal one, or both.

Click to read the article this is in response to.

of course they don't stop intentional leak/theft

0

A very simple way to bypass them is to encrypt the data :)

I wrote about these tools here:
http://securetheworld.blogspot.com/2007/03/methods-for-network-based-devices.html

A snippet:
An approach that combines pattern matching for known and/or structured data and fingerprinting for unstructured data works well in detecting unintended accidental data leaks in information passing through a company's network. A report says that 60% of the leaks reported so far are of this nature. So it is a useful approach

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

Post new comment

The content of this field is kept private and will not be shown publicly.
  • You can use BBCode tags in the text.
  • Lines and paragraphs break automatically.
  • Allowed HTML tags: <p> <strong> <i> <br /> <br> <ul> <ol> <li> <dl> <dt> <dd> <blockquote>

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Welcome, visitor. Register Log in