
Welcome to the third article in the series about the new cloud management console for personal computer protection — Check Point SandBlast Agent Management Platform. As a reminder, in we got acquainted with the Infinity Portal and created the cloud management service for agents Endpoint Management Service. In we explored the web console management interface and installed the agent with the default policy on a user machine. Today, we will examine the contents of the standard Threat Prevention security policy and test its effectiveness against popular attacks.
Standard Threat Prevention Policy: Description
The figure above presents the standard rule of the Threat Prevention policy, which by default applies to the entire organization (all installed agents) and includes three logical groups of protection components: Web & Files Protection, Behavioral Protection, and Analysis & Remediation. Let’s take a closer look at each of the groups.
Web & Files Protection
URL Filtering
URL Filtering allows control over user access to web resources using five pre-installed categories of websites. Each of the five categories contains several more specific subcategories, allowing for setup such as blocking access to the Games subcategory while allowing access to the Instant Messaging subcategory, both of which fall under the Productivity Loss category. URLs related to specific subcategories are defined by the company Check Point. You can check the category of a specific URL or request a category override on a special resource .
As an action, you can set Prevent, Detect, or Off. Also, when selecting the Detect action, a setting is automatically added that allows users to bypass the URL Filtering alert and proceed to the desired resource. If the Prevent action is chosen, this setting can be removed, and the user will be unable to access the blocked site. Additionally, a convenient way to manage blocked resources is by setting up a Block List, where you can specify domains, IP addresses, or upload a .csv file with a list of domains to be blocked.
The standard policy for URL Filtering is set to action Detect and one category — Security has been selected for event detection. This category includes various anonymizers, websites with a Critical/High/Medium risk level, phishing sites, spam, and much more. However, users will still be able to access the resource thanks to the setting 'Allow user to dismiss the URL Filtering alert and access the website.'
Download (web) Protection
Emulation & Extraction allows for the emulation of uploaded files in the Check Point cloud sandbox and the cleaning of documents 'on the fly,' removing potentially malicious content or converting the document to PDF. There are three operating modes:
- Prevent — allows obtaining a copy of the cleaned document before a final emulation verdict, or waiting for the emulation to complete and downloading the original file immediately;
- Detect — performs emulation in the background, not preventing the user from obtaining the original file regardless of the verdict;
- Off — any files are allowed to be downloaded without undergoing emulation and cleaning of potentially malicious components.
There is also an option to choose an action for files that are not supported by Check Point's emulation and cleaning tools — you can allow or prohibit the downloading of all unsupported files.
The standard policy for Download Protection is set to action Prevent with the option to obtain a copy of the original document cleaned of potentially malicious content, as well as allowing the download of files that are not supported by emulation and cleaning tools.
Credential Protection
The Credential Protection component safeguards user credentials and includes two components: Zero Phishing and Password Protection. Zero Phishing protects users from accessing phishing resources, while Password Protection notifies the user about the inadmissibility of using corporate credentials outside the protected domain. Zero Phishing can be set to Prevent, Detect, or Off. When Prevent is set, users can either be allowed to bypass the warning about a potential phishing resource and access the resource, or the option can be disabled and access will always be blocked. With Detect, users always have the option to bypass the warning and access the resource. Password Protection allows for selecting protected domains for which password compliance checks will be carried out, and one of three actions: Detect & Alert (notifying the user), Detect, or Off.
The standard policy for Credential Protection provides for Prevent for any phishing resources, preventing users from accessing potentially malicious sites. It also includes protection against the use of corporate passwords; however, this function will not work without specified domains.
Files Protection
Files Protection is responsible for protecting files stored on the user machine and includes two components: Anti-Malware and Files Threat Emulation. Anti-Malware is a tool that regularly scans all user and system files using signature analysis. The settings of this component can be configured for regular scanning or random scanning times, the signature update period, and the option for users to cancel the scheduled scan. Files Threat Emulation allows for emulating files stored on the user machine in the Check Point cloud sandbox; however, this security feature only works in Detect mode.
The standard policy for Files Protection includes protection through Anti-Malware and detection of malicious files using Files Threat Emulation. Regular scans are performed every month, and signatures on the user machine are updated every 4 hours. Users are allowed to cancel the scheduled scan, but no later than 30 days after the last successful scan.
Behavioral Protection
Anti-Bot, Behavioral Guard & Anti-Ransomware, Anti-Exploit
The Behavioral Protection component group includes three elements: Anti-Bot, Behavioral Guard & Anti-Ransomware, and Anti-Exploit. Anti-Bot allows tracking and blocking C&C connections using Check Point ThreatCloud's constantly updated database. Behavioral Guard & Anti-Ransomware continuously monitors activity (files, processes, network interactions) on the user's machine and can prevent ransomware attacks in their early stages. Additionally, this protection element allows you to recover files that have already been encrypted by malware. Files are restored to their original directories, or a specific path can be specified for storage of all recovered files. Anti-Exploit detects zero-day attacks. All components of Behavioral Protection support three operating modes: Prevent, Detect, and Off.
The standard policy for Behavioral Protection provides Prevent mode for the Anti-Bot and Behavioral Guard & Anti-Ransomware components, with the recovery of encrypted files in their original directories. The Anti-Exploit component is disabled and not in use.
Analysis & Remediation
Automated Attack Analysis (Forensics), Remediation & Response
Two security components are available for analysis and investigation of security incidents: Automated Attack Analysis (Forensics) and Remediation & Response. Automated Attack Analysis (Forensics) generates reports based on the results of attack reflections with detailed descriptions—including a breakdown of the malware execution process on the user’s machine. There is also the option to use the Threat Hunting feature, which enables proactive searching for anomalies and potentially malicious behavior using pre-set or custom filters. Remediation & Response allows configuring recovery and quarantine parameters for files after an attack: controls the interaction of users with quarantined files, and there is an option to store files in quarantine in a directory specified by the administrator.
The standard policy for Analysis & Remediation includes protection that involves automatic actions for recovery (terminating processes, restoring files, etc.), and the option to send files to quarantine is active, allowing users to only delete files from quarantine.
Standard Threat Prevention policy: testing
Check Point CheckMe Endpoint
The fastest and simplest way to check the security of a user machine against the most common types of attacks is to conduct a test using the resource , which performs a series of standard attacks of various categories and allows you to obtain a report based on the testing results. In this case, the Endpoint testing option was used, where an executable file is downloaded and launched on the computer, and then the verification process begins.
During the security check of the workstation, the SandBlast Agent signals identified and mitigated attacks on the user's computer. For example, the Anti-Bot blade reports detection of an infection, the Anti-Malware blade identified and removed the malicious file CP_AM.exe, and the Threat Emulation blade established based on the emulation results that the file CP_ZD.exe is malicious.
The results of the testing conducted with CheckMe Endpoint show the following outcome: out of 6 categories of attacks, the standard Threat Prevention policy only failed against one category — Browser Exploit. This is explained by the fact that the standard Threat Prevention policy does not include the Anti-Exploit blade. It should be noted that without the installed SandBlast Agent, the user's computer passed the check only for the Ransomware category.
KnowBe4 RanSim
To test the functionality of the Anti-Ransomware blade, a free solution can be used , which runs a series of tests on the user machine: 18 ransomware infection scenarios and 1 cryptocurrency miner infection scenario. It should be noted that the presence of many blades (Threat Emulation, Anti-Malware, Behavioral Guard) in the standard policy with Prevent action does not allow this test to be launched correctly. However, even with a reduced security level (Threat Emulation in Off mode), the Anti-Ransomware blade test shows high results: 18 out of 19 tests were successfully passed (1 did not start).
Malicious files and documents
A telling example is the testing of the performance of different blades in the standard Threat Prevention policy using malicious files in popular formats downloaded to the user machine. This test involved 66 files in PDF, DOC, DOCX, EXE, XLS, XLSX, CAB, and RTF formats. The results showed that the SandBlast Agent was able to block 64 out of 66 malicious files. Infected files were either removed after downloading or cleansed of malicious content using Threat Extraction and delivered to the user.
Recommendations for Improving the Threat Prevention Policy
1. URL Filtering
The first thing to correct in the standard policy to enhance the security of the client machine is to switch the URL Filtering blade to Prevent and specify the corresponding categories for blocking. In our case, all categories were chosen except for General Use, as they include most resources that should be restricted for user access in the workplace. It is also advisable to remove the option for users to skip the warning window by unchecking the parameter 'Allow user to dismiss the URL Filtering alert and access the website.'
2. Download Protection
The second parameter to pay attention to is the ability of users to download files that are not supported by Check Point emulation. Since this section discusses enhancements to the standard Threat Prevention policy from a security standpoint, the best option would be to prohibit the downloading of unsupported files.
3. Files Protection
It is also necessary to pay attention to the settings for file protection—specifically the options for periodic scanning and allowing the user to postpone mandatory scans. In this case, the user's working hours must be considered, and a good option from a security and performance perspective is setting mandatory scans to occur daily, with the time chosen randomly (between 00:00 and 8:00), and the user can postpone the scan for a maximum of one week.
4. Anti-Exploit
A significant drawback of the standard Threat Prevention policy is the disabled Anti-Exploit blade. It is recommended to enable this blade with the Prevent action to protect the workstation from attacks using exploits. With this fix, the CheckMe retest successfully completes without detecting vulnerabilities on the user's workstation.
Conclusion
In summary: in this article, we introduced the components of the standard Threat Prevention policy, tested this policy using various methods and tools, and outlined recommendations for improving the settings of the standard policy to enhance the security level of the user's machine. In the next article of the series, we will move on to studying the Data Protection policy and review the Global Policy Settings.
. To not miss the next publications on the SandBlast Agent Management Platform — follow our updates on social media (, , , , ).
Source: habr.com
