SmartID’s, or Smart Identifier Patterns are regular expressions created with qualifiers when appropriate. These SmartID’s are used during Data Loss Prevention (DLP) processing to look for and act on specific violations.
In some cases, SmartID’s are very generic due to the nature of the search item and must be combined with dictionaries and proximity searches in order to reduce the number of false positives.
For example, a rule that is looking for Social Security Numbers (SSN) will trigger if the format of nine digits (nnn-nn-nnnn) is matched, but could also trigger on any nine digit number. To reduce the number of false positive results on unformatted SSN, we look for numbers that are nine digits and do not whole group zeros (e.g. 000-11-2222, or 111-00-2222). We also check that the number is near an indicative word in one of our dictionaries (e.g. SSN or Soc Sec No).
Alaska or Alabama driver’s license numbers are unformatted numbers of lengths between five and seven or seven and eight digits respectively. In these cases we would expect a higher number of false positives since these license numbers are indistinguishable from each other if the length is equal to seven.
We attempt to reduce the number of false positives for driver’s licenses by using the SmartID’s in conjunction with the USDL (United States Drivers License) dictionary.
Smart Identifier Formats
The following is a description of the most commonly used SmartIDs and the search pattern that is being used for Social Security Numbers, Credit Cards and Drivers Licenses. In the case of most Credit Cards, a valid must also work with the Luhn Algorithm, so the SmartID contains the logic to verify the number against this checksum formula.
Social Security Number Smart Identifier
Formatted – matches nnn-nn-nnnn
Unformatted – matches – nnnnnnnnn
Credit Card Smart Identifier
American Express (0000-000000-00000):
– 15 digit number that starts with 34 or 37 + Luhn.
Diners Club / Carte Blanche (0000-000000-0000:
– 14 digit numbers that start 3000-3059/3600-3699/3800-3899 followed by 6 digits followed by 4 digits.
Discover Card (0000-0000-0000-0000):
– 16 digit numbers that start with 6011 + Luhn.
Master Card (0000-0000-0000-0000):
– 16 digit numbers that start with 5100-5599 + Luhn.
Union Pay-China (0000-0000-0000-0000):
– 16 digit numbers that start with 62 + Luhn.
– 13 or 16 digit numbers that start with 4 + Luhn.
Banking Smart Identifier
ABA Routing Number:
ABA Routing Number and Bank Account Number:
Banking Account Terms and Bank Account Number:
Driver’s License Smart Identifiers
Canadian Drivers Licenses
Prince Edward Island:
State Identification Numbers
Spambrella rescued us and our customers from uncertain times with Postini/Google and now McAfee. As an MSP we have relied upon Spambrella and their support for just over 2 years. Our experience has been positive and we have overcome obstacles using their support team for anything email related (sometimes out of their scope). We recommend Spambrella to all of our customers. Thanks!
Having moved away from McAfee, we quickly realised our customers had not settled. We decided to set up an open webinar with all customers and Spambrella. Over 80% of our customers opted to move and a positive decision it was!
The Spambrella team have been excellent. I highly recommend their services and technical expertise.
With over 4k end user email users it was top priority that our migration was stable and quick. Spambrella proved to be the perfect choice with hands on technical assistance. We worked late nights migrating our customers from another email security vendor that increased their pricing without prior warning. We are very happy with Spambrella and will continue to recommend this service.
Our experience with Spambrella has been great.
Support is very responsive and provide a high level of value.
Monotype is one of the world’s best-known providers of type-related products, technologies and expertise.
Spambrella has been a valued service addition to RCS London. Our clients are very happy with the security features Spambrella provides and the user interaction with the service has been simple and welcomed by all. RCS is a fast growth MSP in London UK and the business requires valuable additions like Spambrella. We recommend Spambrella to other MSP’s looking for a monthly subscription email security service.
As an MSP Kingdom provides best of breed packaged services to its clients. Spambrella was brought in to replace both our premium and SMB email security/filter options. Spambrella is quick and simple to set up and administer. The Proofpoint connection is valuable and enables us to quickly deploy policy based encryption which is becoming popular. Overall we cannot fault Spambrella as a service or as a team.
You’ve made the big decision to migrate to Microsoft Office 365. Its array of cloud collaboration makes this a great decision. Yet at the same…
Organizations using Office 365 are choosing Spambrella for the following reasons: Spambrella is more effective than Office 365 security in blocking spam, viruses and malicious…
Problem Statement Today’s email attacks (ransomware, business email compromise, and sandbox evasion) have evolved, and are outpacing the tools developed to combat them. While they…
Business Email Attack Losses Now Top $12 Billion The U.S. Government’s Federal Bureau of Investigation (FBI) released an open administration declaration this week cautioning that…