Sysnet · Threat intelligence and update service
The intelligence layer behind the Sign product family
SignGuard is not a separate product. It collects domain categories, threat intelligence and signature updates centrally, verifies them and distributes them to SignLogger, SignBackup, SignDLP, SignWall and SignPassword.
Distribution flows from the core to the products, left to right.
Architecture
Not a sixth product, but the layer beneath
Single source
A domain is classified once and a threat is verified once; the result reaches every product in the same release. No inconsistent decisions between products.
Runs inside the product
There is no separate installation or interface. The product shows the SignGuard data version it uses and the time of the last update on its own update screen.
Visible through the badge
A product carrying the "powered by SignGuard" mark makes its decisions with current data from SignGuard. The mark sits apart from the product logo.
Services
What it provides to the products
Four data streams; each product receives the set it needs.
Domain and URL categories
Websites are grouped into content categories; filtering and reporting policies are built on those categories.
Threat intelligence
Domain and IP indicators linked to malware, phishing and command-and-control infrastructure.
Signature and rule updates
Detection signatures, classification rules and policy templates are shipped to products as versioned releases.
Software updates
Product releases, fixes and component updates are published from a single distribution point.
Product family
Five products, one source
The five stops of the gradient are the order of the five products. Each product receives the data set it needs from SignGuard; the scope is defined in the product documentation.
SignLogger
Log management & Law 5651 compliance
Receives from SignGuard
Web categories for hotspot and captive portal; domain classification in reports; software updates.
Product siteSignBackup
Storage & backup
Receives from SignGuard
Software and component updates; threat indicators.
Product siteSignDLP
Data security (DLP)
Receives from SignGuard
Sensitive-data classification rules, policy templates and software updates.
Product siteSignWall
Network security (NGFW)
Receives from SignGuard
URL-filtering categories, threat intelligence and signature updates.
Product siteSignPassword
Identity & access (IAM)
Receives from SignGuard
Threat intelligence and software updates.
Product siteHow it works
Collect, verify, distribute
Data is processed centrally; products only pull verified releases.
- 01
Collection
Domain, URL and threat data is gathered centrally from many sources. Miscategorisation reports coming from the products join the same pool.
- 02
Analysis and verification
Records are scored by automatic classification. Records below the threshold, or in conflict, drop into an analyst queue and are verified by hand.
- 03
Versioning
Verified changes are packaged under a version number. Every release records what it changed; distribution always happens through a complete release.
- 04
Distribution
Products pull the new release periodically, check its integrity and put it into service. The data version and time are shown on the update screen.
Tools
Domain lookup
See the category and risk status of a domain in the SignGuard database. The lookup tool is being prepared for release.
Badge
What "powered by SignGuard" means
The mark you see on product sites, on the box, in proposals and partner decks shows that the product receives live data from SignGuard. Resellers and partners can download the badge together with its usage rules.
Have a question?
Write to us about scope, integration or to report a miscategorised domain.