01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

6<br />

<strong>Web</strong> filtering<br />

Media type filtering<br />

Media type filtering<br />

The appliance filters media according to their types, based on rules that use appropriate filter lists, so<br />

particular text, audio, image, streaming, and other media can be blocked. This section explains media<br />

type filtering and tells you how to modify the rules and lists that are involved in the filtering.<br />

Rules for media type filtering<br />

Rules for media type filtering block and whitelist media types. This section explains how these rules<br />

work and how you can modify them. It also describes a media type filtering rule set from the library.<br />

A media type filtering rule set typically includes nested rule sets for controlling media upload and<br />

download. In each rule set, there is at least one rule that blocks media if their types are on a blocking<br />

list.<br />

There can be whitelisting rules that let media skip the blocking rule. There can also be several blocking<br />

rules to handle different media types or media types in different contexts, for example, media types<br />

embedded in archives. A special rule calls an opener module to open media.<br />

Note: Media type filtering rules can also be included in rule sets that are not media type filtering rule sets in<br />

the first place, for example, in virus and malware filtering rule sets.<br />

Media type filtering rule<br />

The following is an example of a rule for blocking media types.<br />

Note: The rule is shown here in a notation similar to the one used on the user interface.<br />

Name<br />

Block types from list Download Media Type Blocklist<br />

Criteria Action<br />

MediaType.EnsuredTypes at least one in list Download Media Type –> Block<br />

Blocklist<br />

<br />

In plain text, this rule can be rephrased as follows:<br />

If media belongs to a type that is on a particular blocking list, block access to it.<br />

The rule criteria checks the MediaType.EnsuredTypes property. Media have this property if it can be<br />

ensured with a probability of more than 50% that they are of a particular type. This is the case if a<br />

signature from an internal list on the appliance can be found in the object code of the media.<br />

For media that have their types ensured in this sense, the rule looks up the specified blocking list to see<br />

whether they are on it. It they are, the criteria is matched and the rule applies. If media belong to<br />

multiple types, already one of them on the list is sufficient to let the criteria match.<br />

The rule then executes the Block action. Processing of all rules stops and the media is not passed on to<br />

the user who requested it. This way, access to it is blocked.<br />

The settings of the Block action specify a message that is sent to a user who is affected by the action.<br />

The message mentions media type as the blocking reason.<br />

200 <strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!