analysis riskware policy rule <rule-id> enable

Prev Next

Enables or disables a specific riskware detection custom policy rule on the EX Series appliance.

Riskware detection policy rules help you to identify objects by suspicious file types and mark them as riskware. The appliance receives a list of updated riskware policy rules when the system checks for new security content from the DTI Cloud. Both the rule ID and rule name are unique. Analysis is performed against all matched rules. When you enable at least one matched policy rule on the appliance, the appliance generates a riskware alert on a nonmalicious submission. No further analysis is performed. The submission status for a riskware alert of a custom policy rule is marked as Custom Riskware in the output of the show submission id command.

When you enable a particular custom policy rule based on riskware detection on the appliance, traffic matching the submission is marked as custom riskware and it will be excluded from further analysis. When you disable a particular custom policy rule based on riskware detection, traffic matching the submission is not marked as custom riskware. After you have configured the appliance to detect a riskware custom policy rule, you can view the analysis results on the Riskware page in the Web UI.

Riskware detection custom policy rule configuration is disabled by default.

Syntax

[no] analysis riskware policy rule <rule_ID> enable

Parameters

no

Use the no form of this command to disable a particular custom policy rule ID.

<rule_ID>

A particular custom policy rule ID.

Example

The following example enables a custom policy rule ID for riskware detection on the appliance:

hostname (config) # analysis riskware policy rule 65008 enable

The following example disables a custom policy rule ID for riskware detection on the appliance:

hostname (config) # no analysis riskware policy rule 65016 enable

User role

Admin or Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Release 8.0

  • Network Security: Release 8.0