file security.md

File Security

Overview

In addition to the Contextual Machine-Learning based engine, CloudGuard WAF provides file security, aimed at preventing malicious files from being uploaded to the organization's servers.

The file security engine scans the HTTP traffic coming into the organization, analyzes any files uploaded, and consults Check Point's Threat Cloud regarding the file's reputation.

In addition to reputation checks via ThreatCloud, File Security validates the actual file type using magic byte (file signature) inspection by default — regardless of the file extension or declared Content-Type. This protects against disguised or mislabeled malicious files (e.g., an executable renamed with a .txt or .jpg extension) and cannot be disabled.

How to setup File Security

Please note that enabling File Security may introduce additional latency.
We recommend configuring longer timeouts and applying File Security only to the relevant assets. If needed, you can create a new asset with a specific URI to limit the scope of this protection.

When defining a new Web Application / API, file security is inactive by default.
However - a security administrator may choose to activate the mode of the file security engine.

Step 1: Browse to Policy->Assets and edit the Web Application / API asset

Once the asset edit window opens, select the Web Attacks tab and scroll to the File Security sub-practice.

Step 2: Make sure the Mode of File Security sub-practice is as desired

Setting the Mode to As Top Level means inheriting the primary mode of the practice.

Otherwise you can override it only for this specific sub-practice to Detect/Prevent/Disable.

Step 3: Edit the settings of the File Security sub-practice

The settings allow:

The following file types are considered archives in file security:

Files that require more than a few seconds to be analyzed by the Threat Emulation engine may be delivered to users before a final verdict is reached to provide better connectivity.

When making the first change to the default Web Application/API Best Practice's configuration such as making changes to the default configuration of the File Security engine settings, you will be prompted to change the name of the Practice to your own custom practice name.

Step 5: Enforce Policy

Click Enforce on the top banner of the Infinity Portal.