Services
Four data streams, one distribution point
SignGuard provides four kinds of data to the products. Each stream is collected from its own sources, verified and published as a release.
Domain and URL categories
Domains on the internet are classified by content type: news, social networks, gambling, adult content, file sharing and so on. Products bind a policy to the category rather than to the domain itself, so new sites fall under the right rule without extra configuration.
What it includes
- Domain and URL classification
- Category-based policy support
- Continuous updates for new and changed sites
- Miscategorisation reports and correction process
Products using it
Threat intelligence
Domains and IP addresses associated with malware distribution, phishing and command-and-control traffic are compiled into indicator lists. Indicators are verified and stale records are retired; products use these lists in blocking and alerting decisions.
What it includes
- Malicious domain and IP lists
- Phishing and fake-site indicators
- Command-and-control (C2) infrastructure indicators
- Record ageing and withdrawal
Products using it
Signature and rule updates
The signatures, patterns and ready-made policy templates that drive product decisions are packaged under a version number. When a product receives a new release, the rule set in use is shown on its update screen.
Software updates
Product software, fix packages and component updates are published from the same distribution point. A product learns about a new release through SignGuard and downloads it with an integrity check.
What it includes
- Release and fix packages
- Component and dependency updates
- Integrity-checked downloads
- Links to release notes
Products using it