Sandbox; Chapter 19 Sandbox; Overview; What You Need To Know - ZyXEL Communications USG FLEX H Series User Manual

Table of Contents

Advertisement

19.1 Overview

Zyxel sandbox is a security mechanism which provides a safe environment to separate running
programs from your network and host devices. Files with unknown or untrusted programs and codes are
uploaded to the cloud. These files are executed within an isolated virtual machine (VM) to monitor and
analyze the zero-day malware and advanced persistent threats (APTs). The zero-day malware refers to
malware that is unknown to any software vendor or developer. It is dangerous because there is no
available defenses against it at the time of discovery.
The zero-day malware and APTs may evade the Zyxel Device's detection, such as anti-malware. Results
of cloud sandbox are sent from the server to the Zyxel Device.
After checking the received files against its local cache, the Zyxel Device sandbox uploads a copy of
the files for inspection if the files are not recorded in the local cache. The scan result from the cloud is
added to the Zyxel Device cache and used for future inspection. When a file with malicious or suspicious
code is detected, the Zyxel Device takes specific actions on the threats.
By default, the Zyxel Device sandbox forwards all files that have not been checked before to the clients
behind the Zyxel Device.
Note: The scan results will be removed from the Zyxel Device cache after the Zyxel Device
restarts. When the scan results stored reach the limit, new scan results automatically
overwrite existing scan results, starting with the oldest scan result first.
Figure 186 Zyxel Sandbox Inspection

19.1.1 What You Need to Know

The Zyxel Device forwards files that are not recorded in the local cache to the client behind the Zyxel
Device before sandbox has completed checking. The scan result will display in Log & Report > Log/
Events. We suggest you to inform your client not to open the file until sandbox has completed checking.
If the client already opened it, then please urge the client to run an up-to-date anti-malware scanner.
C
USG FLEX H Series User's Guide
299
H A P T E R

Sandbox

19

Advertisement

Table of Contents
loading

Table of Contents