by Vasu Murthy

Protecting your network from USB

Opinion
Apr 16, 20073 mins

My company provides employees with laptops and handheld devices to promote an efficient work environment. I’ve also seen employees listening to iPods or carrying keychain USB memory sticks around the office. With so many ways for data to escape the network, how can I ensure that all points are protected from users literally walking out the door with data that doesn’t belong to them?

Laptops and mobile devices are designed to connect – be it at hotspots or at home. They are good at getting the user connected to the rest of the world. Unfortunately this also means there is more opportunity for data loss from these devices. The most common conduits of data loss from endpoints fall into two categories: endpoint ports that include USB, Bluetooth, IR, CD/DVDRW, printing, and so on, and mobile network channels that include public webmail, personal email, blogs, chat, and more.

Organizations have tried various approaches to prevent data leaks from endpoint, including some that focus on disabling endpoint ports completely or disabling non-corporate network connectivity. However, such binary lockdown could have a negative impact on efficiency and productivity – not to mention the impact on employee morale. Think of a sales people not being able to load a presentation onto a customer’s projection system because USB ports have been disabled!

A good endpoint solution should cover both endpoint ports and the mobile network channel in a “content-aware” manner. Content awareness is the intelligence that lets an agent distinguish between sensitive data and non-sensitive data. For example, a content-aware agent could let a sales person copy a customer presentation to a USB drive but not the customer list.

Most endpoint agents collect logs of what data is leaving the endpoint. While this data can generate awareness of the extent of the problem, creating a massive laundry list of incidents for administrators does not address the root of the problem – user education. The agent at a minimum must provide “educate” and “block” actions. An educate action lets the user know that the data transfer is potentially risky and gives an option to reconsider the data transfer. It also provides an audit trail and proof of deliberation. In cases where the data transferred is extremely sensitive, the agent must be able to block the transfer altogether. For example, it is quite justified to block webmail that includes a 60 percent match to information about a company’s upcoming product.

A good endpoint solution should be able to integrate with the network-based data loss prevention technologies and provide the enterprise with a single point of policy definition, incident management, and administration.

A “capture” action, which stores a copy of the violating document for a finite determined by the enterprise, is a useful feature that can support data leak investigations.

With an endpoint data protection solution, employees can continue to use iPods and keychain USB drives freely without creating undue worries about data loss. Choosing a good endpoint solution can provide automatic user education and data loss prevention for lasting improvement in enterprise risk.

Vasu Murthy is the senior product manager at Reconnex,, makers of the Reconnex iGuard appliance, which provides enterprises with data loss prevention capabilities that address data in motion, data at rest and data in use at endpoints.