SSN Detection Behavior in DDC Exchange Reports


Issue:

A test email containing a 9-digit number was not detected under the Social Security Number (SSN) report in Lepide DDC Exchange scanning.


Cause:

The default SSN detection pattern in Lepide uses two validation checks:

  • Matching the SSN regular expression pattern

  • Matching one or more keywords defined under Supporting Evidence

  • Lepide does not classify content as sensitive based only on a 9-digit number. The content must also contain associated supporting keywords configured within the SSN pattern definition.

Findings:

  • The test email contained only the 9-digit number

  • The email did not contain any supporting SSN-related keywords

  • Due to missing supporting evidence, the email was not detected under the SSN report

Purpose of Supporting Evidence:

The Supporting Evidence mechanism is intentionally used to:

  • Improve detection accuracy

  • Reduce false positives

  • Prevent random numeric values from being classified as SSN data

Recommendation:

Additional supporting keywords/evidence can be added to the SSN pattern configuration to improve detection coverage based on environment requirements.

Conclusion:

The observed behaviour is expected and aligns with the default SSN detection logic implemented in Lepide DDC Exchange scanning.