Data filter - Blocking suspicious downloads

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Data filter - Blocking suspicious downloads

L1 Bithead

For data filtering we set a rule to alert for certain downloads (such as .bat, .exe, etc).  In the monitor log, all alerts are listed as LOW severity.  I have noticed a pattern where a workstation shows a suspicious download such as game.exe or abyzdew.exe (random letters in name) and then starts showing outbound spyware or virus messages.  My deduction is the download was some type of malware.

Is there a way to have the files being downloaded scanned for malware and alerted in the data filter tab?  What is the purpose of the severity column in the data filtering tab as it relates to the "FILE" type of data filter and why does it always show as low.

Thanks.

Crill

1 REPLY 1

L0 Member

>For data filtering we set a rule to alert for certain downloads (such as .bat, .exe, etc).  In the monitor log, all alerts are listed as LOW >severity.  I have noticed a pattern where a workstation shows a suspicious download such as game.exe or abyzdew.exe (random letters >in name) and then starts showing outbound spyware or virus messages.  My deduction is the download was some type of malware.

>Is there a way to have the files being downloaded scanned for malware and alerted in the data filter tab?  What is the purpose of the

Downloaded files will be scanned for malware through antivirus profile (Objects->Security Profiles -> Antivirus). Corresponding logs are generated in 'Threat' Log. If you click on the log, it will also show corresponding logs for the 'same' session from different log databases e.g, if a file blocking profile also got triggered on the file, you will see that log when you click on the virus log in the threat log.

>severity column in the data filtering tab as it relates to the "FILE" type of data filter and why does it always show as low.

Currently, all file blocking logs show up as 'low' severity. Let me know if you have some suggestions on how you would like to see this in a future release (Also, please work through your Sales Engineer/Reseller to have them open a feature request for better tracking).

Let me know if you have any further questions,

Thanks,
Sandeep

>Thanks.

>Crill

  • 2146 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!