wreppo

Web Reputation Policies

Web reputation policies dictate whether OfficeScan will block or allow access to a website.

You can configure policies for internal and external clients. OfficeScan administrators typically configure a stricter policy for external clients.

Policies are granular settings in the OfficeScan client tree. You can enforce specific policies to client groups or individual clients. You can also enforce a single policy to all clients.

After you deploy the policies, clients use the location criteria you have set in the Computer Location screen (see Computer Location) to determine their location and the policy to apply. Clients switch policies each time the location changes.

  1. Select the targets in the client tree.

  2. Click Settings > Web Reputation Settings.

  3. Click the External Clients tab to configure a policy for external clients or the Internal Clients tab to configure a policy for internal clients.

  4. Select Enable Web reputation policy on the following operating systems. The operating systems listed in the screen depends on the targets you selected in step 1.

  5. When a web reputation policy is enabled:

  6. Select Enable assessment.

  7. When in assessment mode, clients will allow access to all websites but will log access to websites that are supposed to be blocked if assessment was disabled. Trend Micro provides assessment mode to allow you to evaluate websites and then take appropriate action based on your evaluation. For example, websites that you consider safe can be added to the approved list.

  8. Select Check HTTPS URLs.

  9. HTTPS communication uses certificates to identify web servers. It encrypts data to prevent theft and eavesdropping. Although more secure, accessing websites using HTTPS still has risks. Compromised sites, even those with valid certificates, can host malware and steal personal information. In addition, certificates are relatively easy to obtain, making it easy to set up malicious web servers that use HTTPS.

    Enable checking of HTTPS URLs to reduce exposure to compromised and malicious sites that use HTTPS. OfficeScan can monitor HTTPS traffic on the following browsers:

    Supported Browsers for HTTPS Traffic

    Browser

    Version

    Microsoft Internet Explorer

    • 6 with SP2 or higher

    • 7.x

    • 8.x

    Mozilla Firefox

    3.5 to 5.0

  10. Select Send queries to Smart Protection Servers if you want internal clients to send web reputation queries to Smart Protection Servers.

  11. Select from the available web reputation security levels: High, Medium, or Low

  12. The security levels determine whether OfficeScan will allow or block access to a URL. For example, if you set the security level to Low, OfficeScan only blocks URLs that are known to be web threats. As you set the security level higher, the web threat detection rate improves but the possibility of false positives also increases.

  13. If you disabled the Send queries to Smart Protection Servers option in step 7, you can select Block pages that have not been tested by Trend Micro.

  14. While Trend Micro actively tests web pages for safety, users may encounter untested pages when visiting new or less popular websites. Blocking access to untested pages can improve safety but can also prevent access to safe pages.

  15. Configure the approved and blocked lists.

    1. Select Enable approved/blocked list.

    2. Type a URL.

    3. You can add a wildcard character (*) anywhere on the URL.

      For example:

      You can type URLs containing IP addresses. If a URL contains an IPv6 address, enclose the address in parentheses.

    4. Click Add to Approved List or Add to Blocked List.

    5. To export the list to a .dat file, click Export and then click Save.

    6. If you have exported a list from another server and want to import it to this screen, click Import and locate the .dat file. The list loads on the screen.

  16. To submit web reputation feedback, click the URL provided under Reassess URL. The Trend Micro Web Reputation Query system opens in a browser window.

  17. Select whether to allow the OfficeScan client to send web reputation logs to the server. Allow clients to send logs if you want to analyze URLs being blocked by OfficeScan and take the appropriate action on URLs you think are safe to access.

  18. If you selected domain(s) or client(s) in the client tree, click Save. If you clicked the root domain icon, choose from the following options:

See also: