Solution Architecture

Component Description
1 Mobile Security Protect app
  • The Mobile Security Protect app is a lightweight app for iOS(R) and AndroidTM that protects the device and helps analyze threats to devices in the Enterprise environment. It monitors operating systems device configurations, apps behavior and network connections and provides data to the solution which it uses to identify suspicious or malicious behavior.

  • To protect user privacy, the App examines critical risk indicators found in the anonymized data it collects.

  • The App performs some analysis on the device while resource-intensive analysis is performed in the cloud. This approach minimizes impact on device performance and battery life without changing the end-user experience.

2 UEM
  • Unified Endpoint Management (generalized term replacing MDM/EMM).

  • Device Management and Policy Enforcement System.

  • The UEM option enables you to integrate Mobile Security to a generic unsupported UEM, or to any of these supported UEMs:

    • Workspace ONE (Formerly AirWatch UEM)

    • Microsoft Intune

    • MobileIron Core

    • IBM MaaS360

    • Citrix Endpoint Management (Formerly XenMobile)

    • MobileIron Cloud

    • BlackBerry UEM On-Premises

    • Jamf Pro

    • Google Cloud

    • Samsung Knox Manage / Samsung SDS EMM

    • SOTI MobiControl

    • Applivery

For more information on how to integrate the Mobile Security solution with different UEMs, see Mobile Security UEM Integration Guide.

3 Mobile Security Gateway
  • The cloud-based Check Point Mobile Security Gateway is a multi-tenant architecture to which mobile devices are registered.

  • The Gateway handles all Solution communications with enrolled mobile devices and with the customer's (organization's) Dashboard instance.

  • No Personal Information is processed by or stored in the Gateway.

4 Mobile Security Management Dashboard
  • The cloud-based web-UI Mobile Security Management Dashboard is hosted in the Check Point Portal and is configured as a per-customer instance.

  • It enables administration, provisioning, and monitoring of devices, security policies, events, alerts and mobile forensics

  • The Dashboard can be integrated with an existing Unified Endpoint Management (UEM) solution for automated policy enforcement on devices at risk.

5 Behavioral Risk Engine
  • The cloud-based Mobile Security Behavioral Risk Engine (BRE) uses data it receives from the App about network, configuration, and operating system integrity data, and information about installed apps to perform in-depth mobile threat analysis.

  • The Engine uses this data to detect and analyze suspicious activity, and produces a risk score based on the threat type and severity.

  • The risk score determines if and what automatic mitigation action is needed to keep a device and its data protected.

  • No Personal Information is processed by or stored in the Engine.

6 ThreatCloud
  • Check Point's ThreatCloud is the world largest Indicators of Compromise (IoC) database that incorporates real-time threat intelligence from hundreds of thousand Check Point gateways and from millions of endpoints across the globe.

  • ThreatCloud powers the Anti-Phishing, Safe Browsing, URL Filtering and Anti-bot technologies for Mobile Security on-device Network Protection.

  • ThreatCloud exchanges threat intelligence with the Behavioral Risk Engine for app analysis.