Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

file pattern

Hi all, in AntiVirus-->File Pattern, Does FG block based on extention of file or consider the signature of file? If just based on extention,one can simply change the extention and pass through FG. Best, Kamyar
3 REPLIES 3
abelio
SuperUser
SuperUser

Indeed, AV File pattern is exactly that: a PATTERN detector; you can define file patterns by name, extension, or any other pattern in the file. If you change the file pattern by changing the extension, you' ll have another pattern to match ...

regards




/ Abel

regards / Abel
red_adair
New Contributor III

Kamyar - i' ll help you with my common understanding. The " matching" is based on File-extension only. The Av Engine though - will perform a Magic-byte analysis of the file. So if it' s a renamed executable the AV Engine will scan it. In the next Version of FortiOS (i know it, because their Mobile Solution alread does it) the " Fileblock" will work with pure extentions as well as with " magic by analysis" . I' m happy with this now :) Hope this helps. -R.
abelio

Kamyar - i' ll help you with my common understanding. The " matching" is based on File-extension only.
Hi red.adair: excuse me, but that' s not accurate. " File pattern AV" matchs patterns in the filename, not only extension; try it by yourself or confirm it through the docs. Let me paste it here: " Configure file patterns to block all files that are a potential threat and to prevent active computer virus attacks. Files can be blocked by name, extension, or any other pattern. File pattern blocking provides the flexibility to block potentially harmful content"
The Av Engine though - will perform a Magic-byte analysis of the file. So if it' s a renamed executable the AV Engine will scan it.
That' s another thing: AV machine includes AV Fortiguard service that indeed do that you' ve described. But the non-licensed ' static' part of AV features as FilePattern doesn' t do that magic

regards




/ Abel

regards / Abel
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors