This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

What's the simplest way to block a Top-Level-Domain (*.ru/* for example )in web protection?

What is the simplest way to block all users from visiting a TLD? This seems like a basic functionality but I haven't found a good answer.



This thread was automatically locked due to age.
Parents Reply Children
  • These points are understood. We simply don't do any legit business requiring access to many TLDs. There are many phishing and Emotet download attempts using 3rd-world country domains, for example.

  • In our business users have no need to be on sites outside Australia, Japan, NZ, Singapore etc so for them to be going to China, Russia, etc is really a no no.

    That said we all understand not all these locations host bad content.

    An interesting fact from a recent Webroot report:

    Russia only hosts 3% of the bad URLs and China 5%

    The really worrying thing is:

    A massive 40% of malicious URLs
    were found on good domains.
     
    So we try and manually block traffic etc but we will still be under attack from a known good domain anyways.
     
    Slightly off topic but have a read of the report here:
     
  • Clearly the problem is the northern hemisphere.  In fact, given that 63% are hosted in the US, just block that country.  :)

  • LOL yeah that will fix it.

    It's bad enough using Office 365 and with the "Load Balancing" we get our data hitting servers in HK and China (I am in Melbourne)

    Then there is TeamViewer with servers all over Europe

    A few exceptions need to be created to my world of blocking everything LOL

  • Seriously though, as a completely separate thing from website categorization there is a large effort within Sophos Labs to block malware URLs and domains.  To this end, everyone should make sure they are always blocking the "Criminal Activities" User Activity (or the categories within it).

    https://www.sophos.com/en-us/labs.aspx

  • As examples, regardless of geography, I don't know where a ".online" or ".loan" domain might be physically hosted but I know my users don't have any business going there.

    krebsonsecurity.com/.../

  • Is there a KB article better describing what the categories contain such as "Criminal Activities"? That's a bit open to interpretation. I'd put all Wall Street banks in there, for example.

  • There are a hundred categories.  Managing a rule for each separately is complex.  Therefore the categories are grouped together, along with filetypes into "User Activities".

    You can go into Web \ User Activities to see the categories in each.

    You can go into Web \ Categories and click into a category to get a description.  I think there must be a list somewhere in help or a KB of all the descriptions.  But there is another place to get them.  This site, used for some internal testing, contains a list of categories and descriptions.  Please note that this site has different lists for different products, the list of categories for CWG and XG are the same.

    http://www.sophostest.com/cwg/

  • This definition of "Criminal Activities" doesn't seem to like-up with the advice of using this category for malware domains, etc:

     

    Criminal Activity

    Includes sites for advocating, instructing, or giving advice on performing illegal acts; tips on evading law enforcement; and lock-picking and burglary techniques.

  • The User Activity called Criminal Activity contains 7 categories.

    One of the categories is also called Criminal Activity.  The description may not be ideal - I know that child porn and other illegal to browse to things are categorized as Criminal Activity.

    The other most important category is Spyware and Malware.  This is where a lot of the bad computer security stuff is.

    Blocking the entire User Activity is what I recommend.

     

    I will not comment on the decision of naming a User Activity the same as a Category.  :)