<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Zero-Day Malicious File get Block but hash put on benign cache in TE in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Zero-Day-Malicious-File-get-Block-but-hash-put-on-benign-cache/m-p/51882#M13525</link>
    <description>&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;Hello CheckMates!&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;I would like your opinion with the following behavior&lt;/SPAN&gt;&lt;/SPAN&gt; of Threat Emulation:&lt;/P&gt;&lt;P&gt;One of our customer with local TE250X Appliance experienced a serious issue on a malware campaing where the first malicious file who arrived to the appliance (via MTA) was prevented by TE as it should. However, the following files with &lt;U&gt;&lt;STRONG&gt;same hash&lt;/STRONG&gt;&lt;/U&gt; were allowed (thus, received on mailboxes)!!!!&lt;/P&gt;&lt;P&gt;I have understood if a file is detected as malicious should be put on malicious cache, so we had a big surprise when we found all this hash on benign cache instead of malicious. The same happened for more files who arrived that day:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image_2019_04_25T22_14_06_329Z.png" style="width: 771px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/985iCCB228BC78733130/image-dimensions/771x467?v=v2" width="771" height="467" role="button" title="image_2019_04_25T22_14_06_329Z.png" alt="image_2019_04_25T22_14_06_329Z.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As you can see on photo, all files had one thing in common: Severity High and Confidence N/A. Optimized Profile is in use (Engine version at that time was 58.990000492)&lt;/P&gt;&lt;P&gt;We tried debug with same files later on that day, but confidence level changed to HIGH and the files were putted on malicious cache correctly.&lt;/P&gt;&lt;P&gt;So now we have the following concerns:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Is expected behavior (put on benign cache) when the file's confidence can not be determined even if the severity already has a level (high in this case)???&lt;/LI&gt;&lt;LI&gt;How Check Point determine the confidence level for security events?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Currently we have a case opened with TAC but despite we already sent a lot of information, &lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;they could not explain this behavior&lt;/SPAN&gt;&lt;/SPAN&gt; yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;Has someone experienced the same? &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;I will appreciate your comments&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jul 2019 23:51:09 GMT</pubDate>
    <dc:creator>MikeB</dc:creator>
    <dc:date>2019-07-12T23:51:09Z</dc:date>
    <item>
      <title>Zero-Day Malicious File get Block but hash put on benign cache in TE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Zero-Day-Malicious-File-get-Block-but-hash-put-on-benign-cache/m-p/51882#M13525</link>
      <description>&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;Hello CheckMates!&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;I would like your opinion with the following behavior&lt;/SPAN&gt;&lt;/SPAN&gt; of Threat Emulation:&lt;/P&gt;&lt;P&gt;One of our customer with local TE250X Appliance experienced a serious issue on a malware campaing where the first malicious file who arrived to the appliance (via MTA) was prevented by TE as it should. However, the following files with &lt;U&gt;&lt;STRONG&gt;same hash&lt;/STRONG&gt;&lt;/U&gt; were allowed (thus, received on mailboxes)!!!!&lt;/P&gt;&lt;P&gt;I have understood if a file is detected as malicious should be put on malicious cache, so we had a big surprise when we found all this hash on benign cache instead of malicious. The same happened for more files who arrived that day:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image_2019_04_25T22_14_06_329Z.png" style="width: 771px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/985iCCB228BC78733130/image-dimensions/771x467?v=v2" width="771" height="467" role="button" title="image_2019_04_25T22_14_06_329Z.png" alt="image_2019_04_25T22_14_06_329Z.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As you can see on photo, all files had one thing in common: Severity High and Confidence N/A. Optimized Profile is in use (Engine version at that time was 58.990000492)&lt;/P&gt;&lt;P&gt;We tried debug with same files later on that day, but confidence level changed to HIGH and the files were putted on malicious cache correctly.&lt;/P&gt;&lt;P&gt;So now we have the following concerns:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Is expected behavior (put on benign cache) when the file's confidence can not be determined even if the severity already has a level (high in this case)???&lt;/LI&gt;&lt;LI&gt;How Check Point determine the confidence level for security events?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Currently we have a case opened with TAC but despite we already sent a lot of information, &lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;they could not explain this behavior&lt;/SPAN&gt;&lt;/SPAN&gt; yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;Has someone experienced the same? &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;I will appreciate your comments&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2019 23:51:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Zero-Day-Malicious-File-get-Block-but-hash-put-on-benign-cache/m-p/51882#M13525</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2019-07-12T23:51:09Z</dc:date>
    </item>
    <item>
      <title>Re: Zer-Day Malicious File get Block but hash put on benign cache in TE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Zero-Day-Malicious-File-get-Block-but-hash-put-on-benign-cache/m-p/51908#M13526</link>
      <description>Perhaps it's a bug in the TE engine that we need to investigate.&lt;BR /&gt;Can you tell me in a PM what the TAC SR is for this case?</description>
      <pubDate>Fri, 26 Apr 2019 00:10:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Zero-Day-Malicious-File-get-Block-but-hash-put-on-benign-cache/m-p/51908#M13526</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-26T00:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: Zer-Day Malicious File get Block but hash put on benign cache in TE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Zero-Day-Malicious-File-get-Block-but-hash-put-on-benign-cache/m-p/52075#M13527</link>
      <description>TAC SR shared in a PM, thank you for your answer and Help!</description>
      <pubDate>Mon, 29 Apr 2019 01:25:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Zero-Day-Malicious-File-get-Block-but-hash-put-on-benign-cache/m-p/52075#M13527</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2019-04-29T01:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: Zer-Day Malicious File get Block but hash put on benign cache in TE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Zero-Day-Malicious-File-get-Block-but-hash-put-on-benign-cache/m-p/54278#M13528</link>
      <description>&lt;P&gt;Today we experience the same issue with identical behavor:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN class="uiOutputText"&gt;The &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="uiOutputText"&gt;zero-day file&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class="uiOutputText"&gt; (arrived via email - MTA) is prevented but there is &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="uiOutputText"&gt;NO &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class="uiOutputText"&gt;emulation report.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="uiOutputText"&gt;File has &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="uiOutputText"&gt;HIGH &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class="uiOutputText"&gt;severity but confidence level &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="uiOutputText"&gt;N/A&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="uiOutputText"&gt;The file hash is placed in the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="uiOutputText"&gt;benign &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class="uiOutputText"&gt;cache without any apparent explanation&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="benign_cache-230519.jpg" style="width: 848px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1314i9B82F3D39A9B00E8/image-size/large?v=v2&amp;amp;px=999" role="button" title="benign_cache-230519.jpg" alt="benign_cache-230519.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN&gt;Has anyone experienced something similar?&lt;/SPAN&gt;?? &lt;SPAN class=""&gt;definitely this is not an expected behavior.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;On the other hand, someone has an idea of how Check Point determines a Confidence level N/A???&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2019 20:50:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Zero-Day-Malicious-File-get-Block-but-hash-put-on-benign-cache/m-p/54278#M13528</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2019-05-23T20:50:03Z</dc:date>
    </item>
  </channel>
</rss>

