Common Policy Settings
[Policy] > [Basic Demilitarization Policy] > [Common] Settings
"Common" of SHIELDEX FileDecontaminationThe policy defines the basic sanitization processing criteria that are uniformly applied to the entire file format.
This setting is applied first before the detailed policies for each document type (MS Office, PDF, Hancom Office, HTML, etc.) are applied.
⚠️ The permission to set the basic de-identification policy is granted to [Administrator Type - System Administrator], and
Administrator permission settings can be found under [Administrator Settings] > [Account and Permission Management].
Detailed Description of Settings Items
| Policy Name | Description |
|---|---|
| Setting the Decontamination Treatment Strength | Set the level for identifying risk factors and extracting safe content. ('Maximum Security' recommended) --- 'Maximum Security' mode identifies all risk factors and reconstructs the document by extracting only safe content. 'Maximum Consistency' mode reconstructs the content by safely selecting it while maintaining the original document structure as much as possible. |
| Harmless Extension Filter | Enter the allowed extensions for decontamination processing, separated by semicolons. Extensions not included here are classified as unsupported extensions, and you can configure the handling method in 'Unsupported Extension Blocking Settings'. --- If no value is entered, it allows harmless processing for all extensions. Input example) docx;xlsx; |
| Harmless Block Extension Filter | Specify the extensions that block the import itself, regardless of demilitarization, separated by semicolons. Input example) docx;xlsx; |
| Setting Size Limits for Decontamination Processing | Specify the decontamination processing limit in megabytes. (100MB recommended) Files exceeding the specified size are handled according to the 'Blocking settings when exceeding harmless processing size'. (To prevent delays in decontamination due to large files or excessive consumption of system resources) |
| Blocking settings when decontamination processing size exceeds | Set whether to block the import of the file if its size exceeds the size set in 'De-identification Size Limit Setting'. |
| Password Protected Document Processing Settings | Set the handling method for documents with a password. Documents with set passwords are subject to decontamination processing restrictions and will be blocked or imported based on policy settings. |
| Password Protected Compressed File Handling Settings | Set the handling method for password-protected compressed files. Files with set passwords are restricted from being sanitized and will be blocked or returned to the original based on policy settings. |
| Encryption File Processing Settings | Set the handling method for files encrypted with DRM. Encrypted files are either blocked or imported based on policy settings due to restrictions on decryption processing. |
| Format Identification Unavailable File Processing Settings | Set the handling method for cases where the file format cannot be verified. If the file is corrupted or encrypted in an unknown manner, making it impossible to analyze its internal structure, the harmless processing is limited and will be blocked or returned to the original according to policy settings. |
| Block unsupported file extensions setting | Set the import status for extensions not supported by the service and extensions not included in the 'Allowed Extension Filter for Decontamination'. |
| Extension Tampering Prevention Settings | If the extension does not match the actual file format, it is considered tampering, and the import status is set accordingly. --- It is recommended to configure blocking settings to verify the reliability of files and to prevent the influx of disguised malicious files. For example, if the file extension appears as docx but the actual format is exe, it is considered a tampered extension. |
| File Path Length Exceed Block Setting | Set the handling method for files that exceed the maximum path length allowed in the operating environment (the combined length of the folder path and file name). |
Input Rules and Precautions
- Input extension is
세미콜론(;)You must enter it exactly without spaces as a delimiter. - If you do not enter a value for the 'harmless extension filter', it will be set to allow harmless processing for all extensions.
- The 'harmless file extension' is blocked unconditionally, regardless of the harmless allowed extensions.
- When setting the file size, configure it to an appropriate value considering system performance and degaussing processing time.
- 'Extension forgery' is an important policy to prevent attacks that exploit security vulnerabilities.
Reference Notes
- This setting isCommonly applied to all file formatsand the detailed policies for each individual format can be additionally set in each tab (MS Office, PDF, etc.).
- After changing the settings, you can check the records and restore them in the [Policy Change History] tab.