Attachment filter and CDR in MailGuard

Attachment filter with signature detection, archive analysis and removal of macros for Office, PDF and archives against malware.

The attachment filter checks every attached file before delivery. It blocks risky file types, detects the real file type from its signature and removes active content before a file reaches the mailbox.

File types and content inspection

Blocked file types are rejected before they are delivered. Content inspection extracts the content and detects the real file type from the signature instead of the extension alone. An executable disguised as an image is caught that way. In addition MailGuard checks the structure of containers.

Attachment filter in MailGuard with rules for Office, PDF, HTML and archives

Attachment filter with CDR and file type rules.

Archives

Archives are unpacked and checked as well. A maximum unpacking depth limits nested structures and protects against archive bombs. The default is ten levels, adjustable between 1 and 50.

If the depth is exceeded, a separate setting decides the consequence: allow, flag, raise the score, strip attachments or block. The default is block.

Two further cases are governed separately. If checking an attachment fails, flag, raise the score, strip attachments and block are available, with block as the default. For encrypted attachments that cannot be opened there are allow, flag, quarantine and block, with allow as the default.

Where a category raises the score instead of blocking, the default addition is 10 points on the scale up to 100. How that affects flagging and blocking is described under spam and phishing.

Sanitisation

Instead of blocking an attachment completely, MailGuard can sanitise it and deliver it in a safe version. This content disarm and reconstruction, CDR for short, comprises several steps.

  • Remove macros and convert supported Office files into safe formats.
  • Remove active content such as scripts and embedded actions.
  • Convert content to PDF where required.
  • Remove metadata and embedded objects.

Confirmed malware is always blocked, in audit mode as well.

Further reading

Outgoing attachments with sensitive data are handled by the DLP rules. Blocked attachments land in the quarantine. The MailGuard page gives the overview. More on the technology on the solution pages email attachment protection and ransomware protection.