Views:

To resolve the issue, you may create a DLP Identifier to block these kinds of letters. Select the expression you would like to block.

Create a DLP Data Identifier

  1. Navigate to Policy > Policy Objects > DLP Data Identifiers > Select Expression tab and click Add

    DLP Data Identifiers

    Click the image to enlarge.

  2. Provide a name and copy the string “([一-鿿]+)” without quotes, to the Expression field. Click Save. As an option, you may provide some description in the Description field, and you may also verify the expression by copying a Chinese subject line to the Test data field and clicking Test.

    Test

    Click the image to enlarge.

    If the test result is not correct, remove the pasted expression and create a new one with the following steps.

  3. (Optional) Access this Unicode Lookup site, and copy the character to the Keyword box in IMSVA Web UI.

    Unicode Lockup 1

    Click the image to enlarge.

  4. Access this other Unicode Lookup site, and copy the character to the Keyword box as well.

    Unicode Lockup 2

    Click the image to enlarge.

    Refer to the screenshot in Step 2, add “(“,“[“, “-“, “]”,”+” and “)” accordingly to compose the expression.

Create a DLP Compliance Template

  1. Navigate to Policy > Policy Objects > DLP Compliance Templates and click Add.

    DLP Compliance Templates

    Click the image to enlarge.

  2. Provide a name, select the DLP Data Identifier you just created, click Add and then Save.

    DLP Compliance Templates 2

    Click the image to enlarge.

Add a new policy rule

  1. Navigate to Policy > Policy List, click Add and select Other.

    Policy Rule-Other

    Click the image to enlarge.

  2. Configure Senders and Recipients as needed.

    Policy List

    Click the image to enlarge.

    Policy List 2

    Click the image to enlarge.

  3. In case some users need to receive Chinese mails from specific senders, configure the Exception.

    Policy List-Exception

    Click the image to enlarge.

  4. Configure the scanning criteria to use the DLP Compliance Template just created.
    1. Check the checkbox next to DLP Compliance Templates and then click DLP Compliance Templates.

      DLP Compliance Templates 3

      Click the image to enlarge.

    2. Select the DLP Compliance Template you just created and click “>>” button to add it to “Selected” field, then click Save.

      DLP Compliance Templates 4

      Click the image to enlarge.

    3. Click Next.

      DLP Compliance Templates 5

      Click the image to enlarge.

  5. Configure the policy Action.

    Policy LIst-Quarantine

    Click the image to enlarge.

  6. Name the rule and set its Order Number (priority). You may put it right under the antivirus rule and spam rule.

    Policy LIst-Quarantine 2

    Click the image to enlarge.

  7. Save the changes. The final result will be the following:

    Policy List-Quarantine 3

    Click the image to enlarge.

Below is a sample spam email containing unicode characters in Greek, Latin, and IPA Extension, which is why the policy to detect profanity keyword fails to work.

Spam Mail

Click the image to enlarge.

To resolve the issue, create a DLP Identifier to block these accented letters. Please note that there are many other unicode types.

greek-and-coptic

Click the image to enlarge.

On the product side, you may opt to block emails that contains any of these characters and you may expand it depending on how spammers combine these characters. The following procedure will use the sample mentioned above.

  1. Go to Policy > Policy Objects > DLP Data Identifiers.
  2. Select the Expression tab and click Add.
  3. Provide a name and copy the string "([Ͱ-Ͽ]+)" without quotes to the Expression field, then click Save.
     
    The string came from the ([<first letter>-<last letter>] +) from the Greek and Coptic Unicodes.

    String

    Click the image to enlarge.

  4. Repeat Step 3 and copy the string "([ɐ-ʯ]+)" without quotes, to the Expression field, then click Save.

    IPA-Extension

    Click the image to enlarge.

  5. Create a DLP Compliance Template.
    1. Navigate to Policy > Policy Objects > DLP Compliance Templates and click Add.
    2. Provide a name, select the DLP Data Identifier you just created, click Add and then Save.

    Below is an example wherein both DLP Compliance Templates are added into the policy.

    Compliance-Template

    Click the image to enlarge.

    Here is a sample policy:

    Sample-Policy

    Click the image to enlarge.

  6. Test the policy to verify that the email with Greek or Latin character is quarantined.

    Test

    Click the image to enlarge.

    • Profanity detection

      Profanity-Detection

      Click the image to enlarge.

    • Compliance detection

      Compliance Detection

      Click the image to enlarge.