Skip to main content

About Cyber Shield

Abstract

Cyber Shield is CloudConnexa's integrated security layer — Domain Filtering blocks malicious and suspicious websites via DNS, Traffic Filtering detects and blocks threats using IDS/IPS, and Shield Policies let you apply different protection levels to different User Groups.

Overview

Cyber Shield helps protect your users and resources from malicious domains and network traffic. It provides two types of threat protection:

  • Domain Filtering provides DNS content filtering to monitor or block access to malicious, suspicious, or unwanted domains. Protection applies even when a user's internet traffic doesn't pass through your WPC.

  • Traffic Filtering uses an Intrusion Detection System (IDS) and Intrusion Prevention System (IPS) to monitor or block malicious traffic entering your WPC.

Configure Domain Filtering and Traffic Filtering through Shield Policies. Shield Policies provide per-group protection, allowing different User Groups to use different filtering settings. Every WPC has a Default Policy that provides catch-all protection when no custom policy is assigned.

Refer to About Shield Policies to understand how policies apply Cyber Shield protection.

Domain Filtering

Cyber Shield provides DNS content filtering to protect users from malicious and suspicious domains, including domains associated with threats such as malware, ransomware, and phishing. Because filtering occurs at the DNS layer, it can protect users even when their internet traffic isn't transported through the WPC.

Domain filtering classifies domains into 43 content categories organized into eight groups. You can monitor domain requests or block categories based on the protection level and content access requirements you configure.

You can also control specific domains:

  • Add a domain to the Allow List to permit it when it would otherwise be blocked.

  • Add a domain to the Block List to prevent access to it.

Cyber Shield records observed and blocked DNS requests so you can investigate which users or devices generated them.

For details about protection levels and available categories, refer to Domain Filtering.

Traffic Filtering

Cyber Shield provides a built-in Intrusion Detection System (IDS) and Intrusion Prevention System (IPS) for traffic entering your WPC.

Traffic Filtering compares network traffic against traffic signatures associated with malicious activity and other traffic of interest. Matching traffic is classified by threat priority and category.

Depending on your configuration, you can:

  • Monitor matching traffic to detect threats and investigate activity.

  • Block matching traffic to prevent identified threats from passing through the WPC.

Traffic filtering can identify activity associated with malware, intrusion attempts, denial-of-service attacks, trojans, worms, and other threats. Cyber Shield records detected and blocked events so you can investigate the users or devices involved.

For details about threat priorities, categories, and protection levels, refer to Traffic Filtering.

Shield Policies

Shield Policies determine which Domain Filtering and Traffic Filtering settings apply to your User Groups. Use custom Shield Policies when different User Groups require different levels of protection.

Every WPC also has a Default Policy. The Default Policy automatically applies to User Groups that aren't assigned to a custom policy and always applies to Networks and Hosts.

Refer to:

Existing Cyber Shield configurations

If you configured Cyber Shield before Shield Policies were introduced, your existing Cyber Shield settings automatically migrate to the Default Policy. Your filtering behavior doesn't change, and you don't need to take any action.

Refer to Migrate Existing Cyber Shield Settings to Shield Policies for details.