The URL Dynamic Analysis feature allows the Email Security - Server appliance to analyze and dynamically scan URLs within an email message body that point to objects such as ZIP, EXE, PDF, DOC, and DOCX file types. The URL is compared against a set of heuristic rules to determine whether the URL is suspicious. Based on its internal security rules, the Email Security - Server appliance downloads the object from the referenced URL and submits it to the MVX (Multi-Vector Virtual Execution) engine for further analysis. If the object is detected as malicious, the Email Security - Server appliance immediately blocks the email from being delivered to you and marks the malicious email for quarantine. If the URL is the only object within the message body and is detected as nonmalicious, the Email Security - Server appliance does not block the email from being delivered to you.
When URL Dynamic Analysis is enabled, the Email Security - Server appliance can also identify malicious shortened URLs (for example, j.mp, tinyurl.com, or bit.ly) that are embedded in an email message body. You can prevent access to these shortened URLs, which may point to sites that contain malware.
You can exclude URLs from analysis by adding their domains to a custom domain whitelist.
Note
URL Dynamic Analysis is sometimes referred to as DUA or Dynamic URL Analysis in Trellix documentation.
Note
URL Dynamic Analysis is disabled by default.
Note
If an appliance is deployed behind a Network Security appliance, Trellix recommends you whitelist the IP address of the appliance. This will prevent the Network Security appliance from alerting the that it is downloading malicious content. For more information about whitelisting, see the Network Security User Guide.
Note
Network configuration parameters can be modified to support an interface on a subnet different from the management interface.
Task list for managing URL dynamic analysis
Complete the tasks for managing URL Dynamic Analysis in the following order:
Log in to the Email Security - Server Web UI or CLI.
If the live ether2 data interface is required, verify that the ether2 interface is cabled for connectivity to the Internet. This connection allows the appliance to retrieve objects referenced by suspicious URLs for further analysis.
Determine the external IP address, default gateway IP address, name server IP address, and (if used) the proxy server IP address of your network configuration. (In a NAT environment, use the IP address assigned to the interface, not the external-facing NAT IP address.)
Specify the settings for the live ether1 or ether2 interface. For details about how to specify the network connectivity settings, see Configuring URL dynamic analysis.
If a proxy server is required to access the Internet, specify the proxy server settings. For details about how to specify the proxy server settings, see Configuring a proxy server for URL dynamic analysis using the Web UI.
Verify and test the connection between the live ether1 or ether2 interface and the Internet. For details about how to verify and test the connection between the live (ether1 or ether2) interface and the Internet, see Configuring URL dynamic analysis.
If a proxy server is configured, verify and test the connection between the proxy server and the Internet. For details about how to verify and test the connection between the proxy server and the Internet, see Configuring a proxy server for URL dynamic analysis using the Web UI.
Enable URL Dynamic Analysis. For details about how to enable URL Dynamic Analysis, see Enabling or disabling URL dynamic analysis.
Track the malicious URLs that are related to URL Dynamic Analysis by using the What's Happening panel of the Dashboard.
Determine the domains that you want to add to a custom whitelist. For details about how to add custom domains to a whitelist, see Adding or deleting a custom domain whitelist for URL dynamic analysis using the CLI.
Verify the total number of suspicious URLs that have been dynamically analyzed. For details about how to verify the total number of suspicious URLs, see Viewing the statistics for URLs analyzed using the CLI.