Please enable JavaScript to view this site.

SecurityGateway for Email Servers v12.5

Navigation: Security > Filtering

Attachment Disguise Protection

Scroll Prev Top Next More

Attachment Disguise Protection uses the heuristic file type detection of the IKARUS Anti-Virus engine to compare each attachment's actual, detected file type against its file extension. This lets SecurityGateway catch malware that has been renamed to look harmless – for example, an executable disguised with a .pdf or .docx extension – even when that file type would not otherwise be blocked by Attachment Filtering. Restrictions can be defined both globally and per domain (see File Type Extensions and Exceptions below).

Configuration

Enable disguised file type detection

When enabled, messages with any attachment that is found to be in one of the file type categories selected below but whose file extension doesn't match its file type, will be subject to the action selected in the "If a disguised file type is detected" option below. This option is disabled by default.

…also flag files whose extension matches a monitored type but whose content does not

In addition to flagging attachments whose content does not match their extension, this option also checks the reverse case – a file whose extension belongs to one of the monitored categories (such as .pdf or .docx) but whose actual, detected content type does not match what that extension normally contains. This can catch corrupted or unusual files being used to disguise malicious content. It is enabled by default.

Because some legitimate files are stored in unusual or non-standard formats, this reverse check can occasionally flag files that are not actually malicious. If you find it produces too many false positives, clear this checkbox to fall back to the standard content-vs-extension check only.

If a disguised file type is detected:

Use this option to designate the action SecurityGateway takes when a disguised file type is found.

…refuse the message

When this option is selected, messages containing a disguised file type are refused during the SMTP session. This is the default option.

…quarantine the message

Choose this option to place messages containing a disguised file type in the administrative quarantine rather than refuse them.

…accept the message

Choose this option to accept the message despite the disguised attachment. You can still tag the subject or add to the message's spam score, below, so the message can be flagged, filtered, or reviewed further downstream.

-

…tag subject with

Check this box and enter text in the field provided if you want the message's subject line to be tagged when a disguised file type is detected. The default tag is "*** DISGUISED ***". This option is unavailable if you have selected the "refuse the message" option above, since refused messages are never delivered.

…add [xx] points to message score

Check this box and enter a value if you want SecurityGateway to add the specified number of points to the message's spam score when a disguised file type is detected. As with the "tag subject with" option, this option is unavailable if the message is being refused. The default value is 5.0.

File Types to Monitor

Select the file type categories you want Attachment Disguise Protection to monitor. Only attachments whose detected content type falls into a selected category (or whose extension falls into a selected category, when the "also flag files whose extension matches" option above is enabled) are checked for a mismatch; unselected categories are ignored. By default, Executables, Scripts, VBA Macros, Archives, System Files, and Disk Images are selected, but you can also choose to monitor Documents, Images, Audio, Video, and Databases.

Category list

The file type categories are arranged as a two-level tree. Click the arrow to the left of a category name to expand or collapse its sub-categories. Top-level categories (such as Executables or Scripts) group related sub-categories, such as Windows Executables, DOS Executables, PowerShell, or Windows Batch. Checking a top-level category selects all of its sub-categories. Checking only some of its sub-categories changes the parent checkbox to an indeterminate state, to give a visual indicator that not all sub-categories are selected. All file extensions associated with a file type are listed after the file type's name.

Edit extensions (pencil icon)

File type categories and sub-categories that have file extensions associated with them display those extensions next to their name, followed by a pencil icon. Click the extensions text or the pencil icon to open the File Type Extensions dialog, described below, where you can review or customize which file extensions belong to that category.

Select All / Deselect All

Use these buttons to quickly select or clear every category and sub-category in the list.

search for a file type

Type in this box to filter the category list down to categories and sub-categories whose names or extensions match your search text. Click the X icon to clear the search and show the full list again.

File Type Extensions File Type Extensions

Exclusions

Exclude messages from allowlisted senders

Check this box if you wish to exclude messages from Attachment Disguise Protection when they are from an address, host, or IP on an Allowlist.

Exclude messages from authenticated sessions

Use this option if you wish to exclude a message from Attachment Disguise Protection when it is arriving over an authenticated session.

Exclude messages from domain mail servers

Use this option to exclude messages from Attachment Disguise Protection when they are coming from one of your domain mail servers.

Exclude messages sent to email addresses listed below

Check this box and add any recipient addresses that you wish to exclude from Attachment Disguise Protection. Email address masks are allowed. Example: *@company.mail, user*@company.mail, admin@*.mail.

Exceptions - Domains

If you wish to customize this page's settings for specific domains:

1.Select a domain in the "For Domain:" drop-down list at the top of the page.

2.Click Use the custom settings defined below for this domain.

3.Choose the desired settings.

4.Click Save.

When any customized domains exist and "-- Global --" is selected above, the customized domains will be listed here at the bottom of the page. Click the View/Edit link for the corresponding domain to review or edit its settings, or click Reset to reset the domain's settings to the default Global values.

Copy Domain Settings

If you have customized a domain's settings and wish to copy those settings to one or more other domains:

1.Select a domain in the "For Domain:" drop-down list at the top of the page.

2.At the bottom of the page, click "Click here to copy these custom settings to one or more domains."

3.On the Copy Custom Domain Settings page, use the arrows to move any desired domains from Available Domains to Selected Domains.

4.Click Save and Close.