Configuring file signatures
If you have the SHA-1or SHA-256 (Secure Hash Algorithm) hash values of some known virus-infected files, then you can add these values as file signatures and select the action to apply in the antivirus profile (see Configuring antivirus profiles).
Some file types do not contain viruses, so FortiMail file signature check only supports these attachment file types:
|
|
File signatures can be added either individually, or batch imported via a threat feed, a list of checksums in CSV (comma-separated values), or a plain text file. File signatures also can be exported as a CSV file.
To add a new file signature manually or via threat feed
-
Go to Profile > AntiVirus > File Signature.
-
Click New.
-
Configure the following:
GUI item
Description
Enable or disable the profile.
Enter a unique name for the profile.
Enter a comment or description.
Select where the file signatures are stored, either:
- Local — On the FortiMail unit.
- Remote — A threat feed on an external server.
-
If Source is Local, then configure the following:
GUI item
Description
Select either:
-
SHA-1
-
SHA-256
Click New. Enter the checksum value for a file, and then click OK. Repeat this step until you have entered all of the checksums.
Else if Source is Remote, then configure the following:
GUI item
Description
Select a threat feed that contains file signatures. (Its Resource type is Malware Hash.) See also Configuring a threat feed.
-
-
Click Create.
To import a signature list in CSV format
-
Go to Profile > AntiVirus > File Signature.
-
Click to select a profile.
-
Click Import.
-
Browse to the CSV file and click OK.
The CSV file must contain SHA-1 or SHA-256 hash values, one per line.
To export file signatures in CSV format
-
Go to Profile > AntiVirus > File Signature.
-
Click to select a profile.
-
Click Export.
Depending on your browser settings, your browser may prompt you for a file name and location before downloading the CSV file.