Issue:
A test email containing a 9-digit number was not detected under the Social Security Number (SSN) report in Lepide DDC Exchange scanning.
Cause:
The default SSN detection pattern in Lepide uses two validation checks:
Matching the SSN regular expression pattern
Matching one or more keywords defined under Supporting Evidence
Lepide does not classify content as sensitive based only on a 9-digit number. The content must also contain associated supporting keywords configured within the SSN pattern definition.
Findings:
The test email contained only the 9-digit number
The email did not contain any supporting SSN-related keywords
Due to missing supporting evidence, the email was not detected under the SSN report
Purpose of Supporting Evidence:
The Supporting Evidence mechanism is intentionally used to:
Improve detection accuracy
Reduce false positives
Prevent random numeric values from being classified as SSN data
Recommendation:
Additional supporting keywords/evidence can be added to the SSN pattern configuration to improve detection coverage based on environment requirements.
Conclusion:
The observed behaviour is expected and aligns with the default SSN detection logic implemented in Lepide DDC Exchange scanning.