Consider a scenario where a Sensor is between the endpoints on your network and the Web. The Sensor is integrated with a Intelligent Sandbox cluster consisting of 3 Intelligent Sandbox Appliances.
![]() |
Number | Description |
|---|---|
1 | The endpoints attempt to download files from the Web. The inline monitoring ports detect this activity. |
2 | For a given file, the Sensor withholds the last packet from being forwarded to the endpoint and simultaneously streams the file packets to the primary Intelligent Sandbox for analysis. For this purpose, the Sensor and the primary Intelligent Sandbox use their management ports. |
3 | After the entire file is with the primary Intelligent Sandbox, it distributes this file to one of the appliances in the cluster. For all communication, the members in the cluster use their management ports. |
4 | The corresponding secondary Intelligent Sandbox responds with a job ID to the primary and begins to analyze the file based on the user profile. If the file is detected by static analysis, the secondary Intelligent Sandbox sends the malware result (severity) to the primary Intelligent Sandbox. |
5 |
|
6 | The Sensor forwards the job ID to the Manager. The Manager queries the primary Intelligent Sandbox Appliance management port for the analysis reports. The primary Intelligent Sandbox pulls the reports from the corresponding Intelligent Sandbox Appliance based on the job ID. Then it forwards the reports to the Manager for display. Also, if the file is found to be malicious based on dynamic analysis, the alert in the Real-time Threat Analyzer is updated accordingly. |
7 | Backup Intelligent Sandbox assumes Primary Intelligent Sandbox role if Primary Intelligent Sandbox goes down for some reason. |
