About Facebook File Control?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

About Facebook File Control?

L1 Bithead

Dear Sir,

 

In facebook, There are many way to transfer file.

Like In chat windows , Or In posting windows.

 

In Paloalto App-ID

 

facebook-file-sharing 

Facebook file sharing is a feature offered on Facebook Groups that lets users share presentations, schedules, documents and many other file types with a group. You can post a file to a group by clicking on Upload File.

 

I want to known.

Is this signature can identifcation all file transfer action, or just facebook group???

 

If I deny this App-ID, Can block all file transfer in facebook?

 

Or

I need enable Decryption Policy and use file blocking profile in facebook-base , facebook-posting.

 

Best Regards,

Roy Wang.

 

2 REPLIES 2

Cyber Elite
Cyber Elite

Hi Roy

 

facebook-file-sharing will allow you to share any type of file (including executables) with a group so this application will only apply to the group sharing in facebook. If you block facebook-file-sharing you will only block sharing files with a group but not through other means

 

however:

 

facebook-chat functionality in facebook only allows you to share text based files or pictures (facebook enforces this restriction)

facebook-post also only allows you to upload videos or photos (enforced by facebook also)

If you want to block files in facebook-chat or facebook-post you'd need a fileblocking/data filtering security profile to block pictures, videos or pdf. executables and other types of files will not be permitted through these means.

 

for any facebook sub-application you will need ssl decryption to be able to positively identify them

 

hope this helps

Tom

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Cyber Elite
Cyber Elite

Hello,

Since we whitelist apps, we just allowed facebook-base and since none of the other apps are allowed, they are blocked. If you are the opposite, i.e. blacklist, you could write a security policy that blocks the other facebook apps:

 

source: trust destination:untrust applications: (facebook apps that are not the 'base') deny

 

Hope this helps.

  • 2139 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!