McAfee MAP-3300-SWG Product Guide - Page 133

Rule Creation Wizard

Page 133 highlights

Overview of Email features Email Policies Task - Edit the threshold associated with an existing rule This task assumes that your rule includes a dictionary which triggers the action based on a threshold, such as the Compensation and Benefits dictionary. See Dictionaries to get information about the score associated with a specific term. 1 Go to Email | Email Policies | Scanning Policies and select Compliance. 2 Expand the rule that you want to edit, then select the Edit icon next to the dictionary whose score you want to change. 3 In dictionary threshold, type the score on which you want the rule to trigger, and click OK. Task - Restrict the score contribution of a dictionary term This task assumes that your rule includes a dictionary which triggers the action based on a threshold score, such as the Compensation and Benefits dictionary. For such dictionaries, you can restrict how many times a term can contribute to the overall score. See Dictionaries to get information about the score associated with a specific term. For example, if 'testterm' within a dictionary has a score of 10 and is seen 5 times within an email, it will add 50 to the overall score. Alternatively you can restrict this, for example to contribute only twice by setting 'Maximum term count' to 2. 1 Go to Email | Email Policies | Scanning Policies and select Compliance. 2 Expand the rule that you want to edit, then click the Edit icon next to the dictionary whose score you want to change. 3 In Maximum term count, type the maximum number of times that you want a term to contribute to the score. Rule Creation Wizard Use the wizard to create a new compliancy rule. Email | Email Policies | Scanning Policies Introduction to the Rule Creation Wizard Set the dictionaries that you want the rule to use, and the actions that you want the appliance to take when the rule triggers. Table 108 Option definitions Option Customize the name for this rule Rule name Dictionaries to include Search Name Threshold Max Term Count Definition The first page of the wizard Type the name of the rule that you want to create. The second page of the wizard. Search the list of dictionaries for the ones that you want to include in the rule. Displays the dictionary name as it appears in the Email Compliance Dictionaries list (Email | Email Policies | Dictionaries). Displays the threshold that will trigger a score-based dictionary. To enable score-based detection for a dictionary, go to Email | Email Policies | Dictionaries. Displays the maximum number of times that terms in that dictionary can contribute towards a threshold score. McAfee Email and Web Security Appliances 5.6.0 Product Guide 133

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

Task — Edit the threshold associated with an existing rule
This task assumes that your rule includes a dictionary which triggers the action based on a threshold,
such as the
Compensation and Benefits
dictionary. See
Dictionaries
to get information about the score
associated with a specific term.
1
Go to
Email
|
Email Policies
|
Scanning Policies
and select
Compliance
.
2
Expand the rule that you want to edit, then select the
Edit
icon next to the dictionary whose score
you want to change.
3
In dictionary threshold, type the score on which you want the rule to trigger, and click
OK.
Task — Restrict the score contribution of a dictionary term
This task assumes that your rule includes a dictionary which triggers the action based on a threshold
score, such as the
Compensation and Benefits
dictionary. For such dictionaries, you can restrict how many
times a term can contribute to the overall score. See
Dictionaries
to get information about the score
associated with a specific term. For example, if ’testterm’ within a dictionary has a score of 10 and is
seen 5 times within an email, it will add 50 to the overall score. Alternatively you can restrict this, for
example to contribute only twice by setting ‘Maximum term count’ to 2.
1
Go to
Email
|
Email Policies
|
Scanning Policies
and select
Compliance
.
2
Expand the rule that you want to edit, then click the
Edit
icon next to the dictionary whose score
you want to change.
3
In
Maximum term count
, type the maximum number of times that you want a term to contribute to the
score.
Rule Creation Wizard
Use the wizard to create a new compliancy rule.
Email
|
Email Policies
|
Scanning Policies
Introduction to the Rule Creation Wizard
Set the dictionaries that you want the rule to use, and the actions that you want the appliance to take
when the rule triggers.
Table 108
Option definitions
Option
Definition
Customize the name for
this rule
The first page of the wizard
Rule name
Type the name of the rule that you want to create.
Dictionaries to include
The second page of the wizard.
Search
Search the list of dictionaries for the ones that you want to include in the rule.
Name
Displays the dictionary name as it appears in the
Email Compliance Dictionaries
list
(
Email
|
Email Policies
|
Dictionaries
).
Threshold
Displays the threshold that will trigger a score-based dictionary. To enable
score-based detection for a dictionary, go to
Email
|
Email Policies
|
Dictionaries
.
Max Term Count
Displays the maximum number of times that terms in that dictionary can
contribute towards a threshold score.
Overview of Email features
Email Policies
McAfee Email and Web Security Appliances 5.6.0 Product Guide
133