Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Anchor
top
top
What's Covered

Create a Resource Target

Create a File Scan Policy

Create a File Parameter Selection

Create a Whitelist Policy

 

This document shows you how to create a whitelist policy for your reference system that targets a collection of computers, searches for Windows executables, and then adds any Windows executables not currently in a security catalog to a whitelist. You will also add applications already included in a security catalog to the whitelist.

Resource Target

adds any Windows executables to a whitelist.

Anchor
ResourceTarget
ResourceTarget
Create a Resource Target

Back to top

First you will need to create a resource target that contains the desired reference system(s).

...

To create a resource target, do the following steps:

  1. In the Security Manager Console, click the Resources tab, expand the .
  2. In the left pane, click Resource Filterssection.
  3. Right click on Collections > Arellia > Application Control > Reference Systems and create a new Resource Target
  4. Supply a name and optional description and click OK
    Image Removed
  5. Once the target configuration page is presented click on -click the Resource Target folder.
  6. Click New > Resource Targets > Resource Target.
    Image Added
  7. Enter a name and description.
  8. Click OK.
    Image Added
  9. In the right pane under Filtering Rules, click the Add rule buttonCreate a rule that starts with all computers and then excludes computers not in Computer List and then select the .
    Image Added
  10. In the Then menu, "excludes computers not in" will be the default. 
  11. In the menu just to the right of the Then menu, choose Computer List.
  12. Then click Select.
    Image Added
  13. In the Select Item window that opens, click the computer resources that represent your reference system(s) .
  14. Click SaveOK.

Anchor
FileScan
FileScan
Create a File Scan Policy

Back to top

Now that you have your targeting established you can create the a file scan policy to populate the list of whitelisted files

...

add files to your whitelist.

  1. In the Security Manager Console, click the Policies tab.
  2. In the left pane, navigate to the Arellia Solutions > File Inventory > Policies folder and create a new Policies folder.
  3. Right-click the Policies folder and click New > General Scheduled Client TaskGive .
    Image Added
  4. In the Create Item dialog box, give the task a name and optional description
  5. Set the client command to File Scan Command
  6. Set the resource target to the target created in the section above 
  7. Click OK
  8. Configure the description.
  9. Under Client Command, click the Select link.

    Image Added
  10. In the Client Command dialog box, click File Scan Command.
  11. Click OK.

    Image Added
  12. Under Resource Targets, click the All Managed Computers (Target) link.
  13. In the Resource Targets dialog box, choose the endpoints you want to include in the policy.
  14. In the Create Item dialog box, click OK.
  15. Configure the new policy settings as follows:
    1. Turn on the new policy.
    2. Under File Specifications:  choose Executables in Windows Directories.
    3. Under Reporting Specifications: choose Executions in Windows Directories not present in Security Catalogs.
    4. Configure the schedule interval for how often the file scan will execute.

      Note
    that during
    1. : During the initial testing phase the file scan can be started manually using Windows Task Scheduler on the reference system.

      Image Modified

  16. Click Save.

Anchor
Parameters
Parameters
Create a File Parameter Collection

Back to top

Once the file scan has run on the reference system(s) you will have a list of all executables in the Windows directories that are not contained in a security catalog.

...

You can create a file parameter collection that contains this list of files which can then be used in a whitelist policy

...

.

Create a file parameter collection by doing the following steps:

  1. In the Security Manager Console, click the Policies tab.
  2. In the left pane, navigate to the Arellia Solutions > Application Control > Filters > Inventory Filters.
  3. Right-click the Inventory Filters folder.
  4. Click New > File Parameter Collections folder and create a new File Scan Results Filter (Policy).
    Image Added
  5. Give the filter a name and optional description.
  6. Click OK.

    Image Added
    Configure the parameters to reflect the File Scan policy settings
    1. Set the File Scan Policy to the policy created in the above steps
    2. Set the Reporting Filter to the same one that was configured in the above steps
    3. Set the Results to be Included
    4. Click Save
    Image Removed

Whitelist Policy

...


  1. In the Right pane, set the Data Source to the new policy.
  2. Next to Reporting Filter click the Select link and choose the reporting filter you configured in the previous steps.
  3. Under Results click Included.
  4. Click Save.

    Image Added

Anchor
Whitelist
Whitelist
Create a Whitelist Policy

Back to top

When you have completed the previous steps, put them all into a Reference System Whitelist Policy .

...

by doing the following steps:

  1. In the Security Manager Console, click the Policies tab.
  2. In the left pane, navigate to Arellia Solutions > Application Control > Policies > Whitelisting folder and create a new Whitelisting.
  3. Right-click the Whitelisting folder.
  4. Click New > Blank Application Control Policy.
    Image Added
  5. Give the policy a name and optional descriptionSet the Applications to .
  6. Click OK.

    Image Added
     
  7. In the Applications to Control tab, click the Select Applications to control... link.
  8. In the Select Items dialog box that opens, select the file parameter collection you created abovepreviously.
  9. Under In the Policy EnforcementSet the Policy priority to be tab, set the Policy priority at a number that is lower than your orange list / orangelist or deny policy priorities.
  10. Ensure that Continue enforcing policies after enforcing this policy is unchecked.
  11. Click Save.

You now have a working reference system whitelist policy configured.

Whitelisting