Custom whitelists, blacklists, passwords, and duplicates

Prev Next

The Email Security - Server appliance supports three custom analysis lists—whitelist, blacklist, and password. The lists allow you to control the types of rules to perform and their contents. A whitelist is equivalent to an allowed list. A blacklist is equivalent to a blocked list. A password blacklist is equivalent to a common password-guessing list that is tried in a dictionary attack.

The Email Security - Server appliance also supports configuring the time interval for analyzing duplicate files or URLs both malicious as well as non-malicious.

Whitelist

A whitelist allows you to control which messages containing an attachment can be bypassed based on the matched known rule entries. No further analysis is performed. The Email Security - Server appliance will not analyze an attachment within an email message for malicious content if it contains the signature ID, SHA-256 hash file, REGEX URL, or URL that you defined and added to the appliance database. Whitelisting allows you to eliminate false positives and to suppress rules based on your defined rules.

Blacklist

A blacklist allows you to control which messages containing an attachment must be considered malicious based on the matched known rule entries. The Email Security - Server appliance immediately marks the attachment within an email message for quarantine if it includes the SHA-256 hash file, REGEX URL, URL or file extension that you defined and added to the appliance database. No further analysis is performed.

Password Blacklist

A password blacklist allows you to prohibit passwords based on the matched password entries that you defined and added to the appliance database. A password blacklist contains a list of common passwords that are not allowed because they are frequently used or easily guessed.

Duplicates

Duplicate detection allows the Email Security - Server appliance to skip analysis of files or URLs that are duplicates and it has already analyzed. After a file or URL is analyzed, an identical file or URL that is submitted within a specified time interval will be marked duplicate and will not be analyzed. When the interval expires, an identical file or URL that is submitted will be analyzed as if it had not been seen before. This feature reduces the processing load and allows the appliance to analyze traffic more efficiently. Duplicate detection can be configured separately with different time intervals for malicious files, non-malicious files, malicious URLs, and non-malicious URLs.

Task list for managing custom whitelists, blacklists, and passwords

Complete the steps for managing custom whitelists, blacklists, and passwords in the following order:

  1. Log in to the CLI to configure the custom analysis actions.

  2. Add rules to a custom whitelist. See Adding or deleting a custom whitelist rule using the CLI.

  3. Add rules to a custom blacklist. See Adding or deleting a custom blacklist rule using the CLI.

  4. Add passwords to a custom password blacklist. See Adding or deleting a custom password using the CLI.

  5. View custom blacklists and whitelists using the CLI. SeeViewing custom whitelists and blacklists.

  6. Track the non-malicious and malicious emails that contain attachments based on the matched custom whitelist or blacklist rules that have been processed by using the Search Emails > Processed Mails page. For details about how to view the status of emails with custom whitelist or blacklist rules, see Viewing the status of an email with custom whitelist or blacklist rules on .