310
Controlling traffic at the security gateway
Blocking inappropriate content with content filtering
When a user requests a URL (if the URL is not previously denied based on other criteria), the URL is
first matched against the Content Categories list of URLs. If the URL is not found in any content
category, the Web content, including the headers and the contents of the page, is processed using DDR,
in real time as it is retrieved from the Internet to determine its suitability.
Note:
When you enable DDR, if large files that could cause the transfer to timeout are encountered,
data comforting is enabled.
See
“Avoiding potential session time-out errors”
Scoring Web content using DDR
To determine whether to block or allow access to a site based on DDR, the security gateway compares
the text on the requested site with predefined DDR dictionaries. Each occurrence of a word that is
contained in an active dictionary receives a numerical score, and the security gateway keeps a total
score for a given amount of text. If the total score exceeds the configured numerical threshold, then
access to the site is blocked. An Access Denied message is returned to the requesting Web browser.
Each of the predefined content categories has an associated DDR dictionary with related trigger words
that has been populated by Symantec. When you select the content categories to deny, the security
gateway assumes that the type of content associated with that list is not acceptable. The dictionary
that is associated with that content category is activated for DDR scanning. However, you can choose
whether to activate DDR for a content profile.
How DDR evaluates Web content
In addition to vulgar words, the security gateway also looks for words that can be conditionally
inappropriate. The software reviews each word on a page and examines the surrounding words to
determine the context of these potentially inappropriate terms. For example, in a standard filtering
configuration, the following two phrases are rated differently by DDR.
The context review performed by DDR is based on extensive rules that are supplied with the security
gateway package. These rules, along with the content categories, are routinely updated and refined.
The security gateway automatically downloads updated lists and rules if you subscribe to the list
updates.
Related information
For further information related to this topic, see the following:
■
“Configuring and running LiveUpdate”
Adjusting the sensitivity of DDR
The security gateway lets you change the sensitivity of DDR. You can change the sensitivity for both
incoming and outgoing HTTP requests. You can adjust DDR to be more or less sensitive by selecting
from a range of 1 to 10, where 10 is the most sensitive. Each number in the range is associated with a
numerical score. Any Web page that receives a score that is greater than or equal to this score is
blocked.
Prerequisites
None.
Table 8-3
Filtering by DDR
Phrase
Action
Hot sexual pictures
DDR rates this string of words with a positive score.
Sexual harassment
DDR rates this string of words with a score of zero (no effect).
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...