The Network Security appliance supports three custom analysis lists—whitelist, blacklist, and password. The lists allow you to control the types of rules to perform and their contents. A whitelist is equivalent to an allowed list. A blacklist is equivalent to a blocked list. A password blacklist is equivalent to a common password-guessing list that is tried in a dictionary attack.
Note
The whitelisted or blacklisted URLs identified based on matched known rule entries are from only PDFs or documents files, and not URLs from packet captures or URLs available over the network.
The custom blacklist does not block the mentioned URL/SHA as it is embedded inside a PDF or a document. A notification alert is generated to indicate that a detection has occurred.
Whitelist
A whitelist allows you to control which messages containing an attachment can be bypassed based on the matched known rule entries. No further analysis is performed. The Network Security appliance will not analyze an attachment within an email message for malicious content if it contains the signature ID, MD5 or SHA-256 hash file, REGEX URL or URL that you defined and added to the appliance database. Whitelisting allows you to eliminate false positives and to suppress rules based on your defined rules.
Blacklist
A blacklist allows you to control which messages containing an attachment must be considered malicious based on the matched known rule entries. The Network Security appliance immediately marks the attachment within an email message for quarantine if it includes the MD5 or SHA-256 hash file, REGEX URL, URL or file extension that you defined and added to the appliance database. No further analysis is performed.
Password Blacklist
A password blacklist allows you to prohibit passwords based on the matched password entries that you defined and added to the appliance database. A password blacklist contains a list of common passwords that are not allowed because they are frequently used or easily guessed.
Task list for managing custom whitelists, blacklists, and passwords
Complete the steps for managing custom whitelists, blacklists, and passwords in the following order:
Log in to the CLI to configure the custom analysis actions.
Add rules to a custom whitelist. See Adding or deleting a custom whitelist rule using the CLI.
Add rules to a custom blacklist. See Adding or deleting a custom blacklist rule using the CLI.
Add passwords to a custom password blacklist. See Adding or deleting a custom password using the CLI.
View custom whitelists and blacklists. See Viewing custom whitelists and blacklists.