Zero Phishing

Introduction

Zero Phishing is a new technology and a Threat Prevention protection introduced in R81.20.

Zero Phishing prevents unknown zero-day and known phishing attacks on websites in real-time, by utilizing industry leading Machine-Learning algorithms and patented inspection technologies.

Phishing attacks continue to play a dominant role in the digital threat landscape, which is becoming more mature and sophisticated. Most cyber-attacks start with a phishing attempt.

The Check Point Zero Phishing protection scans the web traffic on the Security Gateway and sends it to the Check Point Cloud for scanning. This way, the Zero Phishing protection prevents access to the most sophisticated phishing websites, both known and completely unknown (zero-day phishing websites).

Because the protection is initiated on the network Security Gateway, the protection is browser-agnostic and platform-agnostic and it does not depend on an email security solution.

Protections usually provided by endpoint or email solutions are now available through the Security Gateway, with no need to install and maintain clients on any device.

The Zero Phishing protection uses two main engines:

  1. Real-time phishing prevention based on URLs

    The engine prevents both known and unknown zero-day phishing attacks, by analyzing various features on the URL in real-time. The engine sends the URL information to the URL-reputation cloud service to perform the analysis. For example: brand similarity, non-ASCII characters and time of registration.

    Using Machine-Learning, the risk is calculated and URLs are classified as phishing and blocked.

  1. In-browser Zero Phishing

    The Security Gateway performs patented Java Script injection to scan HTML forms when they are loaded on the browser (including dynamic forms).

    When the end-user clicks the input fields in the form, all HTML components are scanned in real-time, and the information is sent to the Check Point Zero Phishing cloud service for AI-based analysis.

    The risk is calculated and the phishing site is blocked accordingly.

Discussion Points

  • The enhanced solution is available through the Security Gateway network flow, introducing dynamic security components that run within the browser with no need to install any client.

  • Delivered as part of your existing SandBlast (SNBT) license.

  • Works out of the box for Security Gateways with Autonomous Threat Prevention enabled.

Goal

Demonstrate the capability of Zero Phishing protection.

Instructions

Important - Zero Phishing sites on this demo are not really a phishing sites and it exists for demo purposes only.

For that reason other products like Anti-Virus & Anti-Bot may block it as well.

In order to demonstrate Zero Phishing capabilities , you may need to add an exception for these blades under global exceptions: Security Policies > Threat Prevention > Exceptions > Global Exceptions.

Example: