- CheckMates
- :
- Products
- :
- Harmony
- :
- Endpoint
- :
- Speed up sandbox download
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Speed up sandbox download
Good morning, greetings from Argentina!
Emulating downloads in the Checkpoint sandbox (Chrome extension) takes forever. A 1MB file takes about 3 minutes. It's an eternity.
I have v88.61 installed on the endpoints, and the configuration I apply is as follows:
I'd like to know if the sandboxing process can be sped up.
Thank you very much, best regards!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is partly the use case for why Threat Extraction or CDR exists.
End users receive sanitised documents whilst emulation occurs in the background.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for your response.
The download is suspended until emulation is complete. The user receives the download after emulation, not before.
The problem is that this emulation takes a long time. What parameters can be configured to speed up the emulation process?
Regards!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Beyond the file itself, there are no parameters that influence the speed of the emulation process.
Three minutes is pretty typical for that.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello, greetings from Argentina again!
The problem is that .xlsx, .docx, .pdf, and .jpg files are taking forever, and my organization's users are losing patience. I can't understand how a 3MB file takes around 4 minutes; it's an eternity in the age of IT.
Considering that the premise of my cybersecurity department is: "absolutely every download goes through sandboxing," what is recommended to speed up the emulation process?
I'll run the configuration again:
Best regards!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I assume, given what we do with Threat Emulation, the emulation is as quick as is practical.
This includes acting on the document in the same ways an end user might.
We provide the "Get extracted copy before emulation completes" (i.e. Threat Extraction) option, which gives the end user a safe file immediately that does not include potentially unsafe/malicious elements (e.g. scripts in MS Office docs).
Once the file is emulated, if the end user needs the original, and we have not found any threats via emulation, the end user can get it.
In practice, I've only had to get the original file a handful of times over the past ~10 years.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Again talking generally, sandbox location local/remote/cloud and connectivity to it obviously can be a factor.
See also - https://support.checkpoint.com/results/sk/sk109833
Out of interest is there a reason you prefer to not leverage extraction here?
