{"id":90854,"date":"2020-08-07T01:42:11","date_gmt":"2020-08-06T23:42:11","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/3-check-point-sandblast-agent-management-platform-politika-threat-prevention"},"modified":"2020-08-07T01:42:11","modified_gmt":"2020-08-06T23:42:11","slug":"3-check-point-sandblast-agent-management-platform-politika-threat-prevention","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/3-check-point-sandblast-agent-management-platform-politika-threat-prevention","title":{"rendered":"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.\" src=\"\/wp-content\/uploads\/2020\/08\/47e6b1a7815bb76935e1a31f0cb83772.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nWelcome to the third article in the series about the new cloud management console for personal computer protection \u2014 Check Point SandBlast Agent Management Platform. As a reminder, in <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/511768\/\">first article)<\/a><\/noindex> we got acquainted with the Infinity Portal and created the cloud management service for agents Endpoint Management Service. In <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/512614\/\">second article<\/a><\/noindex> we explored the web console management interface and installed the agent with the default policy on a user machine. Today, we will examine the contents of the standard Threat Prevention security policy and test its effectiveness against popular attacks.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2>Standard Threat Prevention Policy: Description<\/h2>\n<p>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/nz\/u6\/8g\/nzu68gxim5rr7iibz1wyquwrede.png\"><img decoding=\"async\" alt=\"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.\" src=\"\/wp-content\/uploads\/2020\/08\/ef02bf7e83c46edc063e71d5f3c0e7e1.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>The figure above presents the standard rule of the Threat Prevention policy, which by default applies to the entire organization (all installed agents) and includes three logical groups of protection components: Web &amp; Files Protection, Behavioral Protection, and Analysis &amp; Remediation. Let\u2019s take a closer look at each of the groups.<\/p>\n<h3>Web &amp; Files Protection<\/h3>\n<p><\/p>\n<p>                        <b class=\"spoiler_title\">URL Filtering<\/b><br \/>\n                        URL Filtering allows control over user access to web resources using five pre-installed categories of websites. Each of the five categories contains several more specific subcategories, allowing for setup such as blocking access to the Games subcategory while allowing access to the Instant Messaging subcategory, both of which fall under the Productivity Loss category. URLs related to specific subcategories are defined by the company Check Point. You can check the category of a specific URL or request a category override on a special resource <noindex><a rel=\"nofollow\" href=\"https:\/\/urlcat.checkpoint.com\/urlcat\/main.htm\">URL Categorization<\/a><\/noindex>.<br \/>\nAs an action, you can set Prevent, Detect, or Off. Also, when selecting the Detect action, a setting is automatically added that allows users to bypass the URL Filtering alert and proceed to the desired resource. If the Prevent action is chosen, this setting can be removed, and the user will be unable to access the blocked site. Additionally, a convenient way to manage blocked resources is by setting up a Block List, where you can specify domains, IP addresses, or upload a .csv file with a list of domains to be blocked.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/kg\/lu\/lo\/kglulo9f-hiyxv7ydcj4zdxxjxy.png\"><img decoding=\"async\" alt=\"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.\" src=\"\/wp-content\/uploads\/2020\/08\/098f6e80aaa9ac5ddab0db2e4fe5e256.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>The standard policy for URL Filtering is set to action Detect and one category \u2014 Security has been selected for event detection. This category includes various anonymizers, websites with a Critical\/High\/Medium risk level, phishing sites, spam, and much more. However, users will still be able to access the resource thanks to the setting 'Allow user to dismiss the URL Filtering alert and access the website.'<\/p>\n<p>                        <b class=\"spoiler_title\">Download (web) Protection<\/b><br \/>\n                        Emulation &amp; Extraction allows for the emulation of uploaded files in the Check Point cloud sandbox and the cleaning of documents 'on the fly,' removing potentially malicious content or converting the document to PDF. There are three operating modes:<\/p>\n<ul>\n<li><i>Prevent<\/i> \u2014 allows obtaining a copy of the cleaned document before a final emulation verdict, or waiting for the emulation to complete and downloading the original file immediately;<\/li>\n<\/ul>\n<p><\/p>\n<ul>\n<li><i>Detect<\/i> \u2014 performs emulation in the background, not preventing the user from obtaining the original file regardless of the verdict;<\/li>\n<\/ul>\n<p><\/p>\n<ul>\n<li><i>Off<\/i> \u2014 any files are allowed to be downloaded without undergoing emulation and cleaning of potentially malicious components.<\/li>\n<\/ul>\n<p>\nThere is also an option to choose an action for files that are not supported by Check Point's emulation and cleaning tools \u2014 you can allow or prohibit the downloading of all unsupported files.<\/p>\n<p>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/hu\/m0\/a4\/hum0a4qxlidupf5fhldhtbjnqro.png\"><img decoding=\"async\" alt=\"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.\" src=\"\/wp-content\/uploads\/2020\/08\/5333f91625d3230651025309a7a4182d.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>The standard policy for Download Protection is set to action Prevent with the option to obtain a copy of the original document cleaned of potentially malicious content, as well as allowing the download of files that are not supported by emulation and cleaning tools.<\/p>\n<p>                        <b class=\"spoiler_title\">Credential Protection<\/b><br \/>\n                        The Credential Protection component safeguards user credentials and includes two components: Zero Phishing and Password Protection. <i>Zero Phishing<\/i> protects users from accessing phishing resources, while <i>Password Protection<\/i> notifies the user about the inadmissibility of using corporate credentials outside the protected domain. Zero Phishing can be set to Prevent, Detect, or Off. When Prevent is set, users can either be allowed to bypass the warning about a potential phishing resource and access the resource, or the option can be disabled and access will always be blocked. With Detect, users always have the option to bypass the warning and access the resource. Password Protection allows for selecting protected domains for which password compliance checks will be carried out, and one of three actions: Detect &amp; Alert (notifying the user), Detect, or Off.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/7c\/xn\/lv\/7cxnlvruw7jmk6g71emd-zi3qag.png\"><img decoding=\"async\" alt=\"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.\" src=\"\/wp-content\/uploads\/2020\/08\/068e4ca4d7a89ff74d48a71c6079025a.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>The standard policy for Credential Protection provides for Prevent for any phishing resources, preventing users from accessing potentially malicious sites. It also includes protection against the use of corporate passwords; however, this function will not work without specified domains.<\/p>\n<p>                        <b class=\"spoiler_title\">Files Protection<\/b><br \/>\n                        Files Protection is responsible for protecting files stored on the user machine and includes two components: Anti-Malware and Files Threat Emulation. <i>Anti-Malware<\/i> is a tool that regularly scans all user and system files using signature analysis. The settings of this component can be configured for regular scanning or random scanning times, the signature update period, and the option for users to cancel the scheduled scan. <i>Files Threat Emulation<\/i> allows for emulating files stored on the user machine in the Check Point cloud sandbox; however, this security feature only works in Detect mode.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/yv\/5-\/ns\/yv5-nsf5xe8vjjjoaslhu8aaofo.png\"><img decoding=\"async\" alt=\"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.\" src=\"\/wp-content\/uploads\/2020\/08\/b347fd5a4a3e3732dec20efa5d7a766a.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>The standard policy for Files Protection includes protection through Anti-Malware and detection of malicious files using Files Threat Emulation. Regular scans are performed every month, and signatures on the user machine are updated every 4 hours. Users are allowed to cancel the scheduled scan, but no later than 30 days after the last successful scan.<\/p>\n<h3>Behavioral Protection<\/h3>\n<p><\/p>\n<p>                        <b class=\"spoiler_title\">Anti-Bot, Behavioral Guard &amp; Anti-Ransomware, Anti-Exploit<\/b><br \/>\n                        The Behavioral Protection component group includes three elements: Anti-Bot, Behavioral Guard &amp; Anti-Ransomware, and Anti-Exploit. <i>Anti-Bot<\/i> allows tracking and blocking C&amp;C connections using Check Point ThreatCloud's constantly updated database. <i>Behavioral Guard &amp; Anti-Ransomware<\/i> continuously monitors activity (files, processes, network interactions) on the user's machine and can prevent ransomware attacks in their early stages. Additionally, this protection element allows you to recover files that have already been encrypted by malware. Files are restored to their original directories, or a specific path can be specified for storage of all recovered files. <i>Anti-Exploit<\/i> detects zero-day attacks. All components of Behavioral Protection support three operating modes: Prevent, Detect, and Off.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/cj\/we\/hw\/cjwehwnasdhxnxtjrcaed-6x0mc.png\"><img decoding=\"async\" alt=\"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.\" src=\"\/wp-content\/uploads\/2020\/08\/e46e6617b6930a9b74ffb5dd752d27e4.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>The standard policy for Behavioral Protection provides Prevent mode for the Anti-Bot and Behavioral Guard &amp; Anti-Ransomware components, with the recovery of encrypted files in their original directories. The Anti-Exploit component is disabled and not in use.<\/p>\n<h3>Analysis &amp; Remediation<\/h3>\n<p><\/p>\n<p>                        <b class=\"spoiler_title\">Automated Attack Analysis (Forensics), Remediation &amp; Response<\/b><br \/>\n                        Two security components are available for analysis and investigation of security incidents: Automated Attack Analysis (Forensics) and Remediation &amp; Response. <i>Automated Attack Analysis (Forensics)<\/i> generates reports based on the results of attack reflections with detailed descriptions\u2014including a breakdown of the malware execution process on the user\u2019s machine. There is also the option to use the Threat Hunting feature, which enables proactive searching for anomalies and potentially malicious behavior using pre-set or custom filters. <i>Remediation &amp; Response<\/i> allows configuring recovery and quarantine parameters for files after an attack: controls the interaction of users with quarantined files, and there is an option to store files in quarantine in a directory specified by the administrator.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/yv\/g6\/_5\/yvg6_5q9htpuow09drvc9twvin0.png\"><img decoding=\"async\" alt=\"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.\" src=\"\/wp-content\/uploads\/2020\/08\/054dd15ef97b9f018c09dac6168363a2.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>The standard policy for Analysis &amp; Remediation includes protection that involves automatic actions for recovery (terminating processes, restoring files, etc.), and the option to send files to quarantine is active, allowing users to only delete files from quarantine.<\/p>\n<h2>Standard Threat Prevention policy: testing<\/h2>\n<p><\/p>\n<h4>Check Point CheckMe Endpoint<\/h4>\n<p>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/zv\/cy\/xm\/zvcyxmbkz7okn3e93d2skndecvk.png\"><img decoding=\"async\" alt=\"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.\" src=\"\/wp-content\/uploads\/2020\/08\/edeedd847643ab7ac6cb374287601a7f.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>The fastest and simplest way to check the security of a user machine against the most common types of attacks is to conduct a test using the resource <noindex><a rel=\"nofollow\" href=\"https:\/\/pages.checkpoint.com\/checkme-instant-security-check.html\">Check Point CheckMe<\/a><\/noindex>, which performs a series of standard attacks of various categories and allows you to obtain a report based on the testing results. In this case, the Endpoint testing option was used, where an executable file is downloaded and launched on the computer, and then the verification process begins.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/zr\/rl\/9y\/zrrl9yjxowxgkrywqwipy8ac0dq.png\"><img decoding=\"async\" alt=\"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.\" src=\"\/wp-content\/uploads\/2020\/08\/698d916e730a65d937abd49929545a64.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>During the security check of the workstation, the SandBlast Agent signals identified and mitigated attacks on the user's computer. For example, the Anti-Bot blade reports detection of an infection, the Anti-Malware blade identified and removed the malicious file CP_AM.exe, and the Threat Emulation blade established based on the emulation results that the file CP_ZD.exe is malicious.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/dh\/xi\/3-\/dhxi3-jlwqijhtxwwbxac-zrtj4.gif\"><img decoding=\"async\" alt=\"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.\" src=\"\/wp-content\/uploads\/2020\/08\/1a4af1b0066af56d4163d3e6b2ca8441.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>The results of the testing conducted with CheckMe Endpoint show the following outcome: out of 6 categories of attacks, the standard Threat Prevention policy only failed against one category \u2014 Browser Exploit. This is explained by the fact that the standard Threat Prevention policy does not include the Anti-Exploit blade. It should be noted that without the installed SandBlast Agent, the user's computer passed the check only for the Ransomware category.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/h3\/76\/zc\/h376zclkuvjxwxc2unwvcnejwem.png\"><img decoding=\"async\" alt=\"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.\" src=\"\/wp-content\/uploads\/2020\/08\/66a08b2b436df273344a00aafabb1f50.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<h4>KnowBe4 RanSim<\/h4>\n<p>\nTo test the functionality of the Anti-Ransomware blade, a free solution can be used <noindex><a rel=\"nofollow\" href=\"https:\/\/www.knowbe4.com\/ransomware-simulator\">KnowBe4 RanSim<\/a><\/noindex>, which runs a series of tests on the user machine: 18 ransomware infection scenarios and 1 cryptocurrency miner infection scenario. It should be noted that the presence of many blades (Threat Emulation, Anti-Malware, Behavioral Guard) in the standard policy with Prevent action does not allow this test to be launched correctly. However, even with a reduced security level (Threat Emulation in Off mode), the Anti-Ransomware blade test shows high results: 18 out of 19 tests were successfully passed (1 did not start).<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/7y\/l_\/nq\/7yl_nqjgbol5kav2pgyu4ta-fr4.png\"><img decoding=\"async\" alt=\"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.\" src=\"\/wp-content\/uploads\/2020\/08\/99622aa0c54d086efeaac3c2661a028e.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<h4>Malicious files and documents<\/h4>\n<p>\nA telling example is the testing of the performance of different blades in the standard Threat Prevention policy using malicious files in popular formats downloaded to the user machine. This test involved 66 files in PDF, DOC, DOCX, EXE, XLS, XLSX, CAB, and RTF formats. The results showed that the SandBlast Agent was able to block 64 out of 66 malicious files. Infected files were either removed after downloading or cleansed of malicious content using Threat Extraction and delivered to the user.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/dx\/g_\/az\/dxg_az4i9fvox2mbgdhhpoqzuae.png\"><img decoding=\"async\" alt=\"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.\" src=\"\/wp-content\/uploads\/2020\/08\/751ea1224ee20e1a98c53ae747b98b65.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<h3>Recommendations for Improving the Threat Prevention Policy<\/h3>\n<p><\/p>\n<h4>1. URL Filtering<\/h4>\n<p>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/ff\/03\/w2\/ff03w26_9avqezjhb-fflbmmdca.png\"><img decoding=\"async\" alt=\"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.\" src=\"\/wp-content\/uploads\/2020\/08\/9cd69ad2a8a1c034693960b567ea0a46.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>The first thing to correct in the standard policy to enhance the security of the client machine is to switch the URL Filtering blade to Prevent and specify the corresponding categories for blocking. In our case, all categories were chosen except for General Use, as they include most resources that should be restricted for user access in the workplace. It is also advisable to remove the option for users to skip the warning window by unchecking the parameter 'Allow user to dismiss the URL Filtering alert and access the website.'<\/p>\n<h4>2. Download Protection<\/h4>\n<p>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/pj\/kt\/cz\/pjktczvmqy02s3oxr4vjhpvzvvk.png\"><img decoding=\"async\" alt=\"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.\" src=\"\/wp-content\/uploads\/2020\/08\/7aab7f03a4bb2422e79cdb46b163df09.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>The second parameter to pay attention to is the ability of users to download files that are not supported by Check Point emulation. Since this section discusses enhancements to the standard Threat Prevention policy from a security standpoint, the best option would be to prohibit the downloading of unsupported files.<\/p>\n<h4>3. Files Protection<\/h4>\n<p>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/it\/ci\/4y\/itci4yn2eoqkfvkdhw8muzwf68m.png\"><img decoding=\"async\" alt=\"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.\" src=\"\/wp-content\/uploads\/2020\/08\/99cb509f48ff618a6f853f37e56cb8e2.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>It is also necessary to pay attention to the settings for file protection\u2014specifically the options for periodic scanning and allowing the user to postpone mandatory scans. In this case, the user's working hours must be considered, and a good option from a security and performance perspective is setting mandatory scans to occur daily, with the time chosen randomly (between 00:00 and 8:00), and the user can postpone the scan for a maximum of one week.<\/p>\n<h4>4. Anti-Exploit<\/h4>\n<p>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/6e\/mx\/kv\/6emxkv4yzkzkqu546ep-iratzr8.png\"><img decoding=\"async\" alt=\"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.\" src=\"\/wp-content\/uploads\/2020\/08\/b4ba3964fcc5572d479eefe50abf0e31.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>A significant drawback of the standard Threat Prevention policy is the disabled Anti-Exploit blade. It is recommended to enable this blade with the Prevent action to protect the workstation from attacks using exploits. With this fix, the CheckMe retest successfully completes without detecting vulnerabilities on the user's workstation.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/cq\/ys\/ri\/cqysrifvsbfda0sowlprohzzxpg.png\"><img decoding=\"async\" alt=\"3. Check Point SandBlast Agent Management Platform. Threat Prevention Policy.\" src=\"\/wp-content\/uploads\/2020\/08\/521e2edcd642977369f92eded813c435.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<h3>Conclusion<\/h3>\n<p>\nIn summary: in this article, we introduced the components of the standard Threat Prevention policy, tested this policy using various methods and tools, and outlined recommendations for improving the settings of the standard policy to enhance the security level of the user's machine. In the next article of the series, we will move on to studying the Data Protection policy and review the Global Policy Settings.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/358508\/\">A large collection of materials on Check Point from TS Solution<\/a><\/noindex>. To not miss the next publications on the SandBlast Agent Management Platform \u2014 follow our updates on social media (<noindex><a rel=\"nofollow\" href=\"https:\/\/t.me\/tssolution\">Telegram<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.facebook.com\/groups\/tssolution.info\/\">Facebook<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/vk.com\/ts_solution\">VK<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/tssolution.ru\/blog\">TS Solution Blog<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/zen.yandex.ru\/id\/5c7d2162fa818600ae386a52\">Yandex.Zen<\/a><\/noindex>).<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/513254\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0414\u043e\u0431\u0440\u043e \u043f\u043e\u0436\u0430\u043b\u043e\u0432\u0430\u0442\u044c \u043d\u0430 \u0442\u0440\u0435\u0442\u044c\u044e \u0441\u0442\u0430\u0442\u044c\u044e \u0446\u0438\u043a\u043b\u0430 \u043e \u043d\u043e\u0432\u043e\u0439 \u043e\u0431\u043b\u0430\u0447\u043d\u043e\u0439 \u043a\u043e\u043d\u0441\u043e\u043b\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043f\u0435\u0440\u0441\u043e\u043d\u0430\u043b\u044c\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u043e\u0432 \u2014 Check Point SandBlast Agent Management Platform. \u041d\u0430\u043f\u043e\u043c\u043d\u044e, \u0447\u0442\u043e \u0432 \u043f\u0435\u0440\u0432\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u043f\u043e\u0437\u043d\u0430\u043a\u043e\u043c\u0438\u043b\u0438\u0441\u044c \u0441 \u043f\u043e\u0440\u0442\u0430\u043b\u043e\u043c Infinity Portal \u0438 \u0441\u043e\u0437\u0434\u0430\u043b\u0438 \u043e\u0431\u043b\u0430\u0447\u043d\u044b\u0439 \u0441\u0435\u0440\u0432\u0438\u0441 \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0430\u0433\u0435\u043d\u0442\u0430\u043c\u0438 Endpoint Management Service. \u0412\u043e \u0432\u0442\u043e\u0440\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u0438\u0437\u0443\u0447\u0438\u043b\u0438 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441 \u0432\u0435\u0431-\u043a\u043e\u043d\u0441\u043e\u043b\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0438 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u043b\u0438 \u0430\u0433\u0435\u043d\u0442\u0430 \u0441\u043e \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u043e\u0439 \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u043e\u0439 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":90855,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-90854","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/3-check-point-sandblast-agent-management-platform-politika-threat-prevention\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd473. Check Point SandBlast Agent Management Platform. \u041f\u043e\u043b\u0438\u0442\u0438\u043a\u0430 Threat Prevention | ProHoster\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/3-check-point-sandblast-agent-management-platform-politika-threat-prevention\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-08-06T23:42:11+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-08-06T23:42:11+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd473. Check Point SandBlast Agent Management Platform. Threat Prevention Policy | ProHoster","description":"","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/3-check-point-sandblast-agent-management-platform-politika-threat-prevention","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd473. Check Point SandBlast Agent Management Platform. \u041f\u043e\u043b\u0438\u0442\u0438\u043a\u0430 Threat Prevention | ProHoster","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/3-check-point-sandblast-agent-management-platform-politika-threat-prevention","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-08-06T23:42:11+00:00","article:modified_time":"2020-08-06T23:42:11+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"90854","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:40:04","updated":"2022-10-01 09:33:59","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/90854","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=90854"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/90854\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/90855"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=90854"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=90854"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=90854"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}