Web & Files Protection

This category includes URL Filtering, Download (web) Emulation & Extraction, Credential Protection and Files Protection.

URL Filtering rules

URL Filtering rules define which sites can be accessed from within your organization. You select these sites in the Categories and Blacklisting sections, and define the mode in which the rule operates.

When you select a category of sites, the URL Filtering rule applies to all sites in the selected category.

In Blacklisting, you enter the names of specific domains, IP addresses or sites.

Note:
  • You can add the domain names manually or upload a CSV file with the domain names you want to include in the blacklist.

  • You can use * and ? as wildcards for blacklisting.

    • * is supported with any string. For example: A* can be ADomain or AB or AAAA.

    • ? is supported with another character. For example, A? can be AA or AB or Ab.

  • You can export your blacklist.

There are 3 configuration modes for the URL Filtering protection:

  • Prevent - Currently supported only in Hold mode. The request to enter a site is suspended until a verdict regarding the site is received.

    • Unclassified URLs - URLs that the service has no verdict about. Unclassified URLs are allowed by default. To change this configuration to Block, contact Check Point Support.

    • Ask - This option is selected by default. This lets you access a site determined as malicious, if you think that the verdict is wrong.

  • Detect - Allows an access if a site is determined as malicious, but logs the traffic.

  • Off

Note:

SmartEndpoint does not support the new capability. It is only supported for web users.

You can define specific URLs or domains as blacklisted. These URLs/domains will be blocked automatically, while other traffic will be inspected by the URL Filtering rules. You can add the URLs/domain names manually or upload a CSV file with the URLs/domain names you want to include in the blacklist.

Add a URL to the blacklist

  1. Go to Advanced Settings > URL Filtering > Blacklist > Edit.
  2. In the URLs pane, for each required URL, enter the URL and click the + sign
  3. Click OK.
Note:

You can use * and ? as wildcards for blacklisting.

  • * is supported with any string. For example: A* can be ADomain or AB or AAAA.

  • ? is supported with another character. For example, A? can be AA or AB or Ab.

To search for a URL

  1. Go to Advanced Settings > URL Filtering > Blacklist > Edit.

  2. In the search box, enter the required URL.

    The search results appear in the URLs pane.

    You can edit or delete the URL.

To import URLs from an external source

  1. Go to Advanced Settings > URL Filtering > Blacklist > Edit.

  2. Next to the search box, click the sign (import domains list from a 'csv' file).

  3. Find the required file and click Open.

  4. Click OK.

Export a list of URLs

  1. Go to Advanced Settings > URL Filtering > Blacklist > Edit.

  2. Next to the search box, click the sign (export domains list to a 'csv' file).

  3. Click OK.

Malicious Script Protection

Malicious Script Protection scans Uncategorized websites for embedded malicious JavaScripts. If the domain that hosts the script belongs to any one of these categories, then the page is blocked and the event is logged.

  • Anonymizer

  • Botnets

  • Critical Risk

  • High Risk

  • Medium Risk

  • Phishing

  • Spam

  • Spyware

  • Malicious Sites

  • Suspicious Content

Note:

Ensure that you set URL Filtering Mode to either Prevent or Detect.If it is set to Prevent, the page is blocked and the event is logged. If it is set to Detect, the page is not blocked and the event is logged.

To specify malicious script protection:

  1. To enable malicious script protection, select Block websites where Malicious Scripts are found embedded in the HTML.

  2. To allow users to dismiss the malicious script security alert and access the website, select Allow user to dismiss the Malicious Scripts alert and access the website.

Download (Web) Emulation & Extraction

Endpoint Security browser protects against malicious files that you download to your device. The Endpoint Security Browser extension is supported on Google Chrome. Threat Emulation detects zero-day and unknown attacks. Files on the Endpoint device are sent to a sandbox for emulation to detect evasive zero-day attacks. Threat Extraction proactively protects users from malicious content. It quickly delivers safe files while the original files are inspected for potential threats.

There are three configuration options for this protection:

  • Detect - Emulate original file without suspending access to the file and log the incident.

  • Off - Allow file

Credential Protection

This protection includes two components:

  • Zero Phishing - Phishing prevention checks different characteristics of a website to make sure that a site does not pretend to be a different site and use personal information maliciously.

    There are three configuration options for this protection: Prevent, Detect and Off.

  • Password reuse protection alerts users not to use their corporate password in non-corporate domains.

    There are three configuration options for this protection: Detect & Alert, Detect and Off.

Files Protection

This protection includes two components:

  • Anti-Malware - Protection of your network from all kinds of malware threats, ranging from worms and Trojans to adware and keystroke loggers. Use Anti-Malware to manage the detection and treatment of malware on your endpoint computers.

    There are three configuration options for this protection:

    • Prevent - Prevents your files from malware threats.

    • Detect - Provides detection of the threats, so they appear in the logs, although the virus or malware are still executable. Administrators must use this mode with caution.

    • Off - No protection from malware.

    Note:

    Starting from E83.20 Endpoint Security client, Check Point has certified the E2 client version (the Anti-Malware engine is based on Sophos as opposed to Kaspersky) for Cloud deployments.

  • Files Threat Emulation - Emulation on files on the system.