Advanced File Analysis
Steps
- Check the box next to Enable Advanced File Analysis.
- Open the Advanced File Analysis platform drop-down.
-
If you have purchased Forcepoint Advanced Malware Detection for Web, you can select Cloud Service.
- Control the types of files sent to the cloud-based service. Check the box next to the general file types listed to keep those file types from being sent to the file
sandbox. By default, none of the boxes are checked; all suspicious files are sent.
Note that analysis is performed to determine a file’s true type.
When a file type is selected for “Do not submit”, both the true file type and the file extension are used to determine that the file will not be sent to the cloud.
Caution: Electing not to send file types to the service may expose the network to unknown risk. Select the file types based on proper risk assessment.
Balance the privacy risks involved in sending files to the service against the security risks involved in not sending them.
- To not send files having a specific extension, check Files with the following extensions, enter file extensions in the input box provided, and click
Add. Multiple file extensions can be added in a comma separated list.
To remove an entry from the list, highlight a file extension and click Delete.
Note: With the Hybrid Module, the File Sandboxing option available with Forcepoint Web Security Cloud is enabled if Advanced File Analysis is enabled and Cloud Service is selected.
- Control the types of files sent to the cloud-based service. Check the box next to the general file types listed to keep those file types from being sent to the file
sandbox. By default, none of the boxes are checked; all suspicious files are sent.
-
If you have purchased Forcepoint Advanced Malware Detection, you can select On Premises from the drop-down.
By default, images and txt files are not sent to the appliance.
- Enter the IP address of the Controller (prod1 [P] interface) in the Controller IP address entry field.
- Click Check Status to confirm that the appliance is installed at that IP address. This check does not ensure connection to Content Gateway.
- When you are done configuring advance file analysis options, click OK to cache your changes. Changes are not implemented until you click Save and Deploy.