• +90 212 510 58 68
  • This email address is being protected from spambots. You need JavaScript enabled to view it.
  • Pazartesi - Cuma 09:00 - 18:00

UTM Destek

FORTI SANDBOX

Forttisandbox gelişmiş tehdit koruması sağlayan fortinet ürünleri ile entegre çalışan,tehditlere karşı hızlı çözümler sağlayan bir üründür.Zararlı yazılımlara ve tehditlere karşı koruma sağlar.
fortinet sandbox

Atak Yüzeyinde Geniş Kapsama alanı

Genişleyebilen mimarilerde bile gerçek zamanlı tehditlere karşı tam koruma sağlar.Networku son nokta cihazları ve uygulama katmanında korur.

Sıfır Gün Koruması

Fortinet 3.parti üreticiler ile yaptığı ortaklıklar sonucunda API’ler ile sıfır gün koruması sağlar

Sandbox Malware Analizi

Biilinen sandbox koruması iki adımlıdır.Tehditler ve riskli dosyalar Fortinet’in anrivitüs veritabanına analiz edilir, ikinci adımda ise analiz biter ve koruma sağlanır.

Ek olarak FortiGate, FortiMail, FortiWeb, ve FortiClient üçüncü parti üreticilerin API setleriyle entegredir.

FEATURES SUMMARY

FORTISANDBOX 1000D

ADMINISTRATION

 

Supports WebUI and CLI configurations

Multiple administrator account creation

Configuration file backup and restore

Notification email when malicious file is detected

Weekly report to global email list and FortiGate administrators

Centralized search page which allows administrators to build customized search conditions

Frequent signature auto-updates

Automatic check and download new VM images

VM status monitoring

Radius Authentication for administrators

 

NETWORKING / DEPLOYMENT

 

Static Routing Support

File Input: Offline/sniffer mode, On-demand file upload, file submission from integrated device(s)

Option to create simulated network for scanned file to access in a closed network environment

High-Availability Clustering support

Port monitoring for fail-over in a cluster

 

SYSTEM INTEGRATION

 

File Submission input: FortiGate, FortiClient (ATP agent), FortiMail, FortiWeb

File Status Feedback and Report: FortiGate, FortiClient, FortiMail, FortiWeb

Dynamic Threat DB update: FortiGate, FortiClient, FortiMail
– Periodically push dynamic DB to registered entities
– File checksum and malicious URL DB

Update Database proxy: FortiManager

Remote Logging: FortiAnalyzer, syslog server

JSON API to automate the process of uploading samples and downloading actionable malware indicators
toremediate

Certified third-party integration: CarbonBlack, Ziften

Inter-sharing of IOCs between FortiSandboxes

 

ADVANCED THREAT PROTECTION

 

Virtual OS Sandbox:
– Concurrent instances
– OS type supported: Windows XP*, Windows 7, Windows 8.1, Windows 10, macOS, and Android
– Anti-evasion techniques: sleep calls, process, and registry queries
– Callback Detection: malicious URL visit, botnet C&C communication, and attacker traffic from activated

malware
– Download Capture packets, Original File, Tracer log, and Screenshot

Supported in a custom VM File type support: .7z, .ace, .apk, .arj, .bat, .bz2, .cab, .cmd, .dll, .doc, .docm, .docx, .dot, .dotm, .dotx, .exe,
.gz, .htm, html, .jar, .js, .kgb, .lnk, .lzh, Mach-O, .msi, .pdf, .pot, .potm, .potx, .ppam, .pps, .ppsm, .ppsx, .ppt,
.pptm, .pptx, .ps1, .rar, .rtf, .sldm, .sldx, .swf, .tar, .tgz, .upx, url, .vbs, WEBLink, .wsf, .xlam, .xls, .xlsb, .xlsm,
.xlsx, .xlt, .xltm, .xltx, .xz, .z, .zip

Protocols/applications supported:
– Sniffer mode: HTTP, FTP, POP3, IMAP, SMTP, SMB
– Integrated mode with FortiGate: HTTP, SMTP, POP3, IMAP, MAPI, FTP, IM and their equivalent
SSL-encrypted versions
– Integrated mode with FortiMail: SMTP, POP3, IMAP
– Integrated mode with FortiWeb: HTTP
– Integrated mode with ICAP Client: HTTP

Customize VMs for supporting various file types

Isolate VM image traffic from system traffic

Network threat detection in Sniffer Mode: Identify Botnet activities and network attacks, malicious URL visit

Scan SMB/NFS network share and quarantine suspicious files. Scan can be scheduled

Scan embedded URLs inside document files

Integrate option for third-party Yara rules

Option to auto-submit suspicious files to cloud service for manual analysis and signature creation

Option to forward files to a network share for further third-party scanning

Files checksum whitelist and blacklist option

URLs submission for scan and query from emails and files

 

MONITORING AND REPORT

 

FORTISANDBOX 1000D

Hardware

 
   

Form Factor

2 RU

Total Network Interfaces

6x GE RJ45 ports,
2x GE SFP slots

Storage

2x 2 TB

Power Supplies

2x Redundant PSU

   

SYSTEM PERFORMANCE

 
   

VM Sandboxing (Files/Hour)

160

AV Scanning (Files/Hour)

6,000

Number of VMs

8

Sniffer Througput

1 Gbps

   

Dimensions

 
   

Height x Width x Length (inches)

3.5 x 17.2 x 14.5

Height x Width x Length (cm)

89 x 437 x 368

Weight

27.60 lbs (12.52 kg)

   

Environment

 
   

Power Consumption (Average / Maximum)

115 / 138 W

Maximum Current

100V/5A, 240V/3A

Heat Dissipation

471 BTU/h

Power Source

100–240V AC, 60–50 Hz

Humidity

5–95% non-condensing

Operation Temperature Range

32–104°F (0–40°C)

Storage Temperature Range

-13–158°F (-25–70°C)

   

Compliance

 
   

Certifications

FCC Part 15 Class A, C-Tick, VCCI, CE, BSMI, KC, UL/cUL, CB, GOST