Common Policy Settings
[Policy] > [Basic Demilitarization Policy] > [Common] Settings
The "Common" sanitization policy of the SHIELDEX File defines the basic sanitization processing criteria that apply uniformly to the entire file format.
This setting is applied first before the detailed policies for each document type (MS Office, PDF, Hancom Office, HTML, etc.) are applied.
⚠️ The basic declassification policy setting authority is granted to [Administrator Type - Super Administrator], and
Administrator permission settings can be done in [Administrator] > [Administrator List].
Detailed Description of Settings Items
| Policy Name | Explanation |
|---|---|
| File Import Method | Set how to import the file. Choose from three options. 'Decontamination' — Import after decontamination according to policy. 'Original Import' — Import the original as is without decontamination. 'Record Mode' — Decontaminate and record the results according to policy, but proceed with the import as the original file. |
| Setting the Decontamination Processing Strength | Set the level for identifying risk factors and extracting safe content. ('Maximum Security' recommended) --- 'Maximum Security' mode identifies all risk factors and extracts only safe content to reconstruct the document. 'Maximum Integrity' mode selectively reconstructs safe content while maintaining the original document structure as much as possible. |
| Setting Size Limits for Decontamination Processing | Specify the decontamination processing limit in megabytes. (100MB recommended) Files exceeding this size will be processed according to the 'Block setting when exceeding decontamination processing size'. |
| Blocking settings when the decontamination processing size exceeds | If the file size exceeds the size limit set in 'Harmless Processing Size Limit Settings', it determines whether to block the import of that file. |
| Password Protected Document Processing Settings | Set the handling method for documents with a password. Documents with a password have their sanitization processing restricted and are either blocked or returned to the original based on policy settings. |
| Password-protected compressed file processing settings | Set the handling method for password-protected compressed files. Password-protected files are subject to limited remediation processing and are either blocked or imported based on policy settings. |
| Encryption File Processing Settings | Set the handling method for files encrypted with DRM. Encrypted files are subject to decontamination processing restrictions, and depending on policy settings, they may be blocked or imported in their original form. |
| Format Identification Unavailable File Processing Settings | Set the handling method for cases where the file format cannot be verified. If the file is corrupted or encrypted in an unknown manner, making it impossible to analyze the internal structure, the sanitization process is limited and will be blocked or imported based on policy settings. |
| Block unsupported file extensions setting | Set the handling method for unsupported extensions in the service and extensions not included in the 'Allowed Extension Filter' (Block / Import Original / Log Mode). |
| Extension forgery prevention settings | If the extension does not match the actual file format, it is considered tampering, and the handling method is set (block / original import / logging mode) --- To verify the reliability of the file and to fundamentally block the inflow of disguised malicious files, it is recommended to set to block. For example, if the file extension appears as docx but the actual format is exe, it is judged as a tampered extension. |
| File Extension Unspecified Block Setting | Set the handling method for files without extensions. Files without extensions are considered to be of an unclear type for security reasons, so it is recommended to set blocking. |
| Import settings for the original when a decontamination error occurs | Set the handling method for cases where the neutralization cannot be completed normally due to neutralization engine errors, processing failures, system exceptions, etc. (Block / Original Import / Logging Mode) |
| Original Import Settings on Timeout | Set the handling method for cases where the decontamination work is not completed within the time specified in 'Setting Work Time Out Criteria'. (Items where individual policy application is not possible) |
| Setting the timeout threshold (minutes) | Set the maximum time allowed for decontamination processing in minutes. If the specified time is exceeded, it will be processed according to 'Original Import Settings on Job Timeout'. (Items where individual policy application is not possible) |
| File Path Length Exceed Block Setting | Set the handling method for files that exceed the maximum path length allowed in the operating environment (the combined length of the folder path and file name). |
Input Rules and Precautions
- If you set 'File Import Method' to 'Original Import', all files will be imported as originals without decontamination processing. Use it cautiously except during the operational validation phase.
- 'Record mode' is a mode that processes and records results while importing in the original form. It can be used for policy validation and gradual application.
- When setting the file size, configure it to an appropriate value considering system performance and decontamination processing time.
- 'Extension forgery' is an important policy to prevent attacks that exploit security vulnerabilities.
Reference Note
- This setting isCommonly applied to all file formatsand the detailed policies for each individual format can be set additionally in each tab (MS Office, PDF, etc.).
- 'Harmless Allowed Extension Filter', 'Harmless Blocked Extension Filter' are set in the [Exceptions] tab.
- After changing the settings, you can check the records and restore them in the [Policy Change History] tab.