Hi ,
I would like to ask a question regarding the detection feature in Collaboration Protection.
In our environment, we frequently see detection results indicating harmful URLs, with severity levels ranging from low to high.
What I would like to understand is:
Based on what logic are these URLs identified as harmful, and how are they classified into different severity levels?
Are there any specific evaluation criteria or rules behind this classification?
For example, is it based on threat intelligence feeds, behavioral analysis, reputation scoring, or other mechanisms?
If anyone has insights or experience with how this detection works in practice, I would really appreciate it if you could share.
Thank you in advance!
————————————————————————————————
皆様
Collaboration Protectionの検知(detection)機能について質問させていただきます。
弊社環境では、有害と判定されたURLの検知が頻繁に発生しており、
そのリスクレベルも「低」から「高」までさまざまに分類されています。
そこで、以下の点について教えていただけますでしょうか。
これらのURLはどのようなロジックに基づいて有害と判定され、
また、どのようにリスクレベルが分類されているのでしょうか。
具体的には、脅威インテリジェンス、挙動分析、レピュテーション評価など、
どのような基準や仕組みによって判断されているのかを知りたいと考えております。
本機能について実際の運用経験や知見をお持ちの方がいらっしゃいましたら、
ご教示いただけますと幸いです。
何卒よろしくお願いいたします。