Threat Prevention Policy Insights

Threat Prevention Policy Insights simplifies the management of the Threat Prevention policy and profiles by providing administrators with actionable, environment-specific insights.

Check Point's Infinity Cloud calculates the insights and they are displayed per Policy LayerClosed Layer (set of rules) in a Security Policy..

Key benefits

  • Reduces administrator effort with fast, one-click remediation actions.

  • Provides customized insights based on analysis of traffic passing through the Security Gateways.

  • Optimizes security and performance by

    • Detecting misconfigurations and configuration gaps

    • Identifying high CPU-consuming protections

    • Highlighting unoptimized Threat Prevention settings.

Supported Environments

Limitations

  • Threat Prevention Policy Insights is not supported for Smart-1 Cloud environments.

  • Autonomous Threat Prevention is not supported.

Prerequisites

Activating Threat Prevention Policy Insights

Note - Threat Prevention Policy Insights does not rely on Log Sharing or Configuration Sharing. Instead, it uploads Threat Prevention logs, profiles, rules, and objects to the Check Point Portal for analysis.

Procedure

  1. In SmartConsoleInfinity Services view > locate the Policy Insights card:

    1. Toggle the switch to On.

    2. Accept the Terms and Conditions.

    The card status changes from Inactive to Initializing.

  2. Make sure the Insights button appears in the top-left corner of the Threat Prevention Rule BaseClosed All rules configured in a given Security Policy. Synonym: Rulebase..

Notes:

  • After the activation process, the log analysis may take several hours (up to 48 hours in large environments). Therefore, suggestions do not appear immediately. Some insights can appear within a few days, while others require a longer period of time to appear.

  • The insight calculation process runs every two weeks.

Types of Insights

Click here for detailed information regarding each insight.

Managing Threat Prevention Policy Insights

To view insights for a Policy Layer

  1. In SmartConsole, go to the Security Policies view > Threat Prevention.

  2. Click the Insights button at the top-left corner.

Each category in the Threat Prevention Policy Insights window shows:

  • The latest date on which the presented information is based.

  • The number of suggestions in that category.

Confidence Level

Each insight is assigned a confidence level that reflects its reliability and accuracy.

For example: Longer observation periods provide more comprehensive data, increasing the reliability of the insight.

Severity

Each insight is assigned a severity level that reflects how critical it is to address the issue for maintaining the security of your environment.

Available Actions

For each insight, you can select one of these options:

  • Apply - Accept the insight. Threat Prevention Policy Insights implements the change automatically.

    Note - For certain suggestions, automatic remediation is not available. In these cases, you must follow the provided instructions to perform manual remediation.

    Publish your session for the changes to take affect.

  • Decline - Reject the insight. The insight moves to the Declined suggestions section.

    To return a declined suggestion to the Suggestions section, select the suggestion and click Undo decline.

  • Decide later - Move the suggestion to the Decide later section. This is useful for insights that require additional consideration.

    In the Decide later, these are the available actions:

    • Apply - Accept the change.

    • Decline - Reject the change.

    • Move back - Move the suggestion back to the Suggestions section.

Filtering Insights

You can filter the suggestions based on these categories:

  • Recommended (the default option) - Suggestions with the highest calculated security impact and confidence.

  • All - Valuable suggestions.

Watch the Video