18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

About the Keyword<br />

Search tab<br />

Chapter 6: Configuring Application Defenses<br />

Creating Mail (Sendmail) Application Defenses<br />

The Keyword Search tab allows you to configure the <strong>Sidewinder</strong> <strong>G2</strong> to perform<br />

a search for specified character set(s), or key words, within an e-mail<br />

message. The search scans the message’s header and body sections. If the<br />

mail body contains mime encoded attachments, the encoded attachments are<br />

scanned. If the filter finds a specific number <strong>of</strong> key word matches, the message<br />

is rejected. If the filter does not match a specific number <strong>of</strong> key words, it passes<br />

the message onto the next filter or to the intended recipient.<br />

Select your key words carefully. For best results:<br />

• Use spaces before and after each defined phrase.<br />

• Create a comprehensive list <strong>of</strong> phrases instead <strong>of</strong> relying on wildcard-like<br />

searching.<br />

• Note that key word searching is most reliable on MIME attachments with<br />

ASCII content-types. If dealing with non-ASCII types <strong>of</strong> attachments, false<br />

positives are likely if the length <strong>of</strong> the key words are short and the<br />

attachments are long.<br />

Following these guidelines can decrease the chance <strong>of</strong> mistakenly rejecting a<br />

legitimate message.<br />

To configure character sets to search for, follow the steps below.<br />

1 Verify that kmvfilter server is enabled in the appropriate burbs (Services<br />

Configuration > Servers).<br />

2 In the Minimum Number <strong>of</strong> Phrase Matches Required for Rejection <strong>of</strong><br />

Message field, specify the number <strong>of</strong> key word matches that must be found<br />

in a message before it is rejected.<br />

3 In the Total Number <strong>of</strong> Phrase Matches to Verify Before Rejection field,<br />

specify whether the filter will search the entire message for key words, or<br />

whether it will stop searching for key words if the minimum number <strong>of</strong><br />

matches is met:<br />

• Minimum—Select this option if you want the filter to stop searching and<br />

fail the message if the minimum number <strong>of</strong> key word matches is met.<br />

This is based on the number that you enter in the previous step. The<br />

filter will reject a mail message once the minimum number <strong>of</strong> key words<br />

are matched.<br />

• All—Select this option if you want the filter to continue searching the<br />

message for key words after the minimum number <strong>of</strong> key word matches<br />

is met, for auditing purposes. After searching the entire message for key<br />

word matches, the message is rejected.<br />

4 The Phrase List table provides the list <strong>of</strong> phrases that will be filtered for this<br />

Application Defense. The table contains three columns:<br />

• Before—This column indicates whether a space is required immediately<br />

before the specified phrase to match the filter. An asterisk (*) indicates<br />

that the phrase will not match unless there is a space immediately in<br />

front <strong>of</strong> the phrase.<br />

175

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!