Click-Time Protection

Check Point's virtual inline technology provides phishing protection for emails after they have been scanned by Microsoft servers, but before they reach the user's mailbox.

New attacks became more sophisticated and are able to generate phishing campaigns such that the phishing website they link to does not have any known bad reputation, sometimes for hours and days after the emails are sent.

Click-Time Protection replaces links in the email's body and attachments. The replaced links point to the Check Point inspection services, so that every time a user clicks on a link, the website behind the link is inspected to ensure it is not a phishing website.

Click-Time Protection uses these security engines for inspection.

  • URL Reputation - Checks if the URL is known to be malicious or holds any malicious references.

  • URL Emulation - Emulates the website to detect zero-day phishing websites.

Benefits

  • Most Up-to-Date Intelligence - Inspecting links when the user clicks on the URL allows Check Point to inspect the URL based on the latest inspection intelligence and software capabilities.

  • Protection against zero-day phishing websites - Inspecting links when the user clicks on the URL allows Check Point to follow the user into the website. Click-Time Protection then emulates the website to expose hidden Phishing indicators. So the Phishing websites that are not known to be malicious are also flagged.

  • Pointing out the users that clicked the malicious URL - Click-Time Protection forensics allows administrators to detect the users that require further education and training to avoid clicking on malicious links.

Note:

Click-Time Protection is available only for Office 365 Mail and Gmail.

Interaction with Microsoft ATP

Email Security supports link rewriting even when Microsoft Safe Links is enabled.

When both Check Point Click-Time Protection and Microsoft Safe Links are active, the Check Point rewritten link is embedded within the Microsoft rewritten link.

The format of the rewritten link is as follows:

Safe Links rewritten URL prefix> < Check Point rewritten URL prefix> <Original URL> < rewritten URL suffix> <Microsoft Safe Links suffix>

This integration provides the protection of both Check Point and Microsoft without you requiring to disable either one:

  • Both Check Point and Microsoft inspects the original link upon email receipt.

  • When a user clicks the URL, both Check Point and Microsoft inspects the website or file linked and can block access if it is identified as malicious.

When clicking on re-written links, the end user experiences the following:

Microsoft Verdict Check Point Verdict User Experience
Clean Clean Redirects to the original URL.
Malicious Malicious or Clean Microsoft block page.
Clean Malicious Check Point block page. See Click-Time Protection - End-User Experience.