Skip to main content

Security Rules on Zenconsole

Published on:
.
4 min read

Security Rules in Zenconsole allow you to define how Zenarmor detects and blocks malicious, deceptive, suspicious, and potentially dangerous internet destinations.

Security settings are configured separately for each Internet Security Policy. The configured rules apply to gateways, endpoints, users, groups, and traffic that match the policy criteria.

When a device covered by a policy attempts to access an internet destination, Zenarmor evaluates the request by using its cloud-based threat intelligence and categorization services. The destination is then allowed or blocked according to the selected security profile and category settings.

Zenarmor provides two layers of security protection:

  • Essential Security: Provides core protection against common threats and risky destinations.
  • Advanced Security: Provides additional protection against emerging threats, compromised infrastructure, botnet activity, and suspicious domain behavior.
note

The availability of Advanced Security features may depend on your Zenarmor subscription.

To access the security settings of an Internet Security Policy, follow the steps below:

  1. Sign in to Zenconsole.
  2. Select the organization you want to manage.
  3. Navigate to Policies > Internet Security Policies.
  4. Select the policy you want to configure.
  5. Navigate to the Security tab.

The Security tab displays the Essential Security and Advanced Security sections.

Figure 1. Security Rules on Zenconsole

Understanding Security Profiles

Essential Security and Advanced Security provide the following profiles:

ProfileDescription
PermissiveAllows all categories in the applicable security section.
Moderate ControlBlocks the categories considered most likely to present an immediate security risk while allowing categories that may require stricter organizational judgment.
High ControlBlocks all categories in the applicable security section.
CustomAllows you to configure each category independently.

To create a custom configuration, enable the toggle next to a category to block it or disable the toggle to allow it. Zenconsole automatically switches the active profile to Custom when you change any category setting.

The Status column displays the current action for each category:

  • Blocked: Access to destinations in the category is blocked.

  • Allowed: Access to destinations in the category is allowed.

    Figure 2. Security Profiles on Zenconsole

Essential Security

Essential Security provides the core layer of protection against common malicious, deceptive, and risky internet activity.

To configure Essential Security, follow the steps below:

  1. Open the Security tab of the policy.
  2. Locate the Essential Security section.
  3. Select one of the following profiles:
    • Permissive
    • Moderate Control
    • High Control
    • Custom
  4. If you select Custom, use the toggle next to each category to set it to Blocked or Allowed.

The Essential Security profiles apply the following general behavior:

  • Permissive: Allows all Essential Security categories.

  • Moderate Control: Blocks Malware/Virus, Phishing, Hacking, Spam sites, and Potentially Dangerous destinations.

  • High Control: Blocks all Essential Security categories.

  • Custom: Uses the individual category settings selected by the administrator.

    Figure 3. Configuring Essential Security Rules

The following Essential Security categories are available.

Malware/Virus

The Malware/Virus category includes destinations known to host or distribute malware, viruses, or other malicious software.

Blocking this category helps prevent users and devices from accessing content that could compromise systems, expose sensitive information, or provide unauthorized access to the network.

Phishing

The Phishing category includes destinations associated with phishing campaigns, deceptive websites, and infrastructure used to steal credentials or other sensitive information.

Blocking this category prevents users from accessing known phishing destinations and reduces the risk of account compromise, identity theft, and unauthorized access.

Hacking

The Hacking category includes destinations associated with hacking tools, unauthorized access methods, and content that may facilitate malicious activity.

Blocking this category reduces exposure to resources that could be used to compromise devices, accounts, or network infrastructure.

Spam Sites

The Spam sites category includes destinations associated with unsolicited, misleading, or potentially harmful content distributed through spam campaigns.

Blocking this category reduces exposure to fraudulent promotions, phishing attempts, malware distribution, and other security risks commonly associated with spam.

Potentially Dangerous

The Potentially Dangerous category includes destinations that demonstrate suspicious characteristics or behavior but have not been conclusively identified as malicious.

Blocking this category provides proactive protection against destinations that resemble known threats or display an elevated security risk.

Parked Domains

The Parked Domains category includes registered domains that do not currently host a developed website. These domains are commonly used for advertising, traffic monetization, or domain resale.

Although some parked domains are legitimate, others may display misleading advertisements, deliver malvertising, redirect users to harmful destinations, or distribute malicious content.

Blocking this category helps prevent users from interacting with potentially unsafe advertising and suspicious parked-domain landing pages.

Firstly Seen Sites

The Firstly Seen Sites category includes websites that the Zenarmor Web Categorization engine has not previously encountered.

Because these destinations have not yet been fully classified, they may present a higher level of uncertainty. Blocking this category provides proactive protection against newly created or previously unknown malicious websites. However, it may also restrict legitimate new websites and should therefore be configured according to the organization’s security requirements.

When Zenarmor encounters a Firstly Seen Site, the destination is added to the AI-based classification queue. The classification system analyzes the website and attempts to assign an appropriate category.

If classification succeeds, the website category is updated and the new information is propagated through the Cloud Web Categorization and Threat Intelligence system. If the website cannot be classified, it is marked as Unknown or Uncategorized and may be queued for further analysis.

Advanced Security

Advanced Security extends Essential Security by providing additional protection against emerging threats, compromised infrastructure, evasive activity, and suspicious domain behavior.

Threat actors frequently use recently registered domains, compromised websites, dynamic DNS services, and recently reactivated domains to distribute malware, conduct phishing campaigns, or avoid reputation-based security systems. Advanced Security categories allow Zenarmor to block these destinations before they can affect users and devices.

The Advanced Security profiles apply the following general behavior:

  • Permissive: Allows all Advanced Security categories.
  • Moderate Control: Blocks Recent Malware/Phishing/Virus Outbreaks, Botnet C&C, Compromised Website, Spyware and Adware, and Keyloggers and Monitoring. Dynamic DNS Sites, Newly Registered Sites, and Newly Recovered Sites remain allowed.
  • High Control: Blocks all Advanced Security categories.
  • Custom: Uses the individual category settings selected by the administrator.

To configure Advanced Security, follow these steps:

  1. Open the Security tab of the policy.

  2. Scroll to the Advanced Security section.

  3. Select Permissive, Moderate Control, or High Control to apply a predefined profile.

  4. To create a custom configuration, enable or disable any individual category toggle. Zenconsole automatically changes the selected profile to Custom.

  5. Verify the resulting action for each category in the Status column.

    Figure 4. Configuring Advanced Security Rules

The following Advanced Security categories are available.

Recent Malware/Phishing/Virus Outbreaks

The Recent Malware/Phishing/Virus Outbreaks category includes recently identified malware, phishing, and virus campaigns.

New threats may spread rapidly before they are widely represented in conventional signature and reputation databases. Blocking this category provides additional protection against recently observed campaigns and emerging threats.

This category includes malware, phishing, and virus campaigns identified within a recent period, typically during the first zero to two weeks of their activity.

Botnet C&C

The Botnet C&C category includes destinations identified as command-and-control infrastructure used to manage compromised devices.

Botnets rely on command-and-control servers to send instructions to infected devices and receive stolen information. These instructions may be used to launch distributed denial-of-service attacks, distribute malware, send spam, perform automated attacks, or conduct other malicious activity.

Blocking this category prevents compromised devices from communicating with known botnet command-and-control infrastructure.

Compromised Website

The Compromised Website category includes legitimate websites that have been infiltrated, altered, or abused by malicious actors.

Compromised websites may distribute malware, host phishing content, redirect users to harmful destinations, or expose visitors to security vulnerabilities. Blocking this category helps protect users from threats delivered through otherwise legitimate websites.

Spyware and Adware

The Spyware and Adware category includes destinations associated with software that monitors user activity, collects information without authorization, or displays intrusive advertising.

Spyware may collect sensitive information without the user’s knowledge, while adware may deliver unwanted advertisements or redirect users to unsafe content. Blocking this category protects user privacy and reduces exposure to unwanted or potentially malicious software.

Keyloggers and Monitoring

The Keyloggers and Monitoring category includes destinations associated with software designed to record keystrokes or monitor user and device activity without authorization.

These tools may be used to collect credentials, private communications, browsing activity, and other sensitive information. Blocking this category helps protect users from credential theft, unauthorized surveillance, and privacy violations.

Dynamic DNS Sites

The Dynamic DNS Sites category includes destinations that use dynamic DNS services to associate changing IP addresses with domain names.

Dynamic DNS has legitimate uses, including remote access and hosting services on changing IP addresses. However, threat actors can also use these services to conceal malicious infrastructure, frequently change attack destinations, and make malicious systems more difficult to track.

Organizations should evaluate their legitimate use of dynamic DNS services before blocking this category.

Newly Registered Sites

The Newly Registered Sites category includes domains that were registered recently.

Threat actors frequently use newly registered domains for phishing, malware distribution, fraud, and other short-lived malicious campaigns. Because these domains are new, reputation systems may not yet have collected enough information to classify them conclusively.

Blocking this category provides proactive protection but may also affect legitimate newly launched websites.

Newly Recovered Sites

The Newly Recovered Sites category includes domains that have recently become active again after an extended period of inactivity.

Threat actors may acquire or reactivate dormant domains to take advantage of their previous reputation and avoid security systems that treat established domains as trusted. These domains may then be used for phishing, malware distribution, or other malicious campaigns.

Blocking this category reduces exposure to recently reactivated domains that may have been repurposed for malicious activity.