Dec 1, 2017 — ETP updates
-
An SIA administrator can now enable Safe Search in a policy configuration. This feature allows you to block or prohibit adult and explicit content in search results that are completed by end users on Google or Bing search engines.
-
An SIA administrator can now report a domain is a potential threat and include supporting information for our analysts to review.
-
If an end user attempts to access a domain or IP address that is included in the Deny List, the end user is directed to an error page that indicates access to the domain is prohibited.
-
Protect laptops that are off-network with the Enterprise Client Connector, a DNS proxy application that you download from the SIA portal and configure for installation on enterprise users’ laptops. The Client Connector allows you to apply an SIA policy to DNS requests that are made outside the corporate network. With the Client Connector, you can detect an end user’s network conditions, send off-network DNS requests to SIA, log Client Connector activity, and identify the machine name.
-
Identify the IP address of devices with the Enterprise Security Connector, a virtual machine that you deploy in your network to collect suspicious or malicious traffic, identify machines or laptops that are infected with malware or are making requests to malicious domains. This information is directed to the Security Connector based on the policy configuration. SIA reports on this data and allows administrators to correlate this data with threat event information.
Sep 1, 2017 — ETP updates
-
SIA administrators can now schedule a daily or weekly report that generates with alerts or all event data for the selected time period. Reports are generated and emailed to users who an administrator configures to receive scheduled report notifications.
-
From the Communication tab on the Utilities page, SIA administrators can now easily provide email addresses for alert notifications. In future releases, the improved design of the Communication tab will allow administrators to configure notification emails for specific SIA features.
-
From the Sinkhole tab on the Utilities page, SIA administrators complete a new process to create a custom sinkhole. SIA administrators can also now modify a sinkhole policy assignment.
-
In an upcoming release, SIA administrators will be able to download an OVA file to create a virtual machine that is configured as a sinkhole in your network. The SIA sinkhole receives suspicious or malicious traffic and identifies machines that are infected with malware. To participate in the beta of the SIA sinkhole feature, contact your account representative.
-
New reporting criteria or dimensions, including additional reporting dimensions for DNS activity. On the DNS Activity page, users can now view DNS activity data based on threat category and Autonomous System (AS) Name.
Jul 1, 2017 — ETP 1.3 updates
-
The ability to create a PDF of the Dashboard or the DNS Activity page. Each PDF contains an image of the entire page, including the data, graphs, and applied filters.
-
SIA administrators can now manage sinkholes from the Utilities page. A new Sinkhole tab is available.
-
New options are available to upload text files that contain known or suspected domains or IP addresses for a custom list configuration.
-
SIA administrators can now report a domain they believe is misclassified in a security list or incorrectly categorized in the Acceptable Use Policy.
-
The “Drop” list action in a policy configuration is no longer available. If a list was previously assigned the “Drop” action, the lists are instead assigned the “Deny” action.
-
The “Warning” action for a security or custom list in a policy is now called “Blockpage”. The behavior of the action has not changed.
-
To share domain search results, an SIA user can now provide the URL of the Indicator Search results page to other SIA users.
-
If a malicious or harmful domain is found with the Indicator Search, the search results now list known bad URLs within those domains.
-
Event reports now generate data at near realtime.
-
The SIA user documentation is updated, including the online help, User Guide, and Quick Start Guide.