Endpoint Protection

 View Only
  • 1.  What Data Gets Sent to Symantec Insight During a Reputation Risk Query?

    Posted Apr 29, 2015 01:07 PM

    I need to know what data is sent from a client to the Insight website https://ent-shasta-rrs.symantec.com whenever it queries the reputation risk database about an unknown file.

    Does it actually transmit the suspect file, or just the name? Does the computer name and/or IP address get sent? 

     



  • 2.  RE: What Data Gets Sent to Symantec Insight During a Reputation Risk Query?

    Posted Apr 29, 2015 02:08 PM

    I do know the hash gets uploaded.

    If no one else checks in, you may want to engage support.



  • 3.  RE: What Data Gets Sent to Symantec Insight During a Reputation Risk Query?
    Best Answer

    Trusted Advisor
    Posted Apr 30, 2015 02:27 AM

    Hello,

    This is the URL that SEP clients send reputation requests to.

    A client computer sends information about reputation detections to Symantec Security Response for analysis. The information helps to refine Insight's reputation database. The more clients that submit information the more useful the reputation database becomes.

    Data in a reputation request:
     
    SEP engine making the reputation request
    File name
    File path
    Hash of the file (SHA256 and MD5)
    File attributes
     
    Additional data, if applicable or available:
     
    Company name from signature
    Signature issuer
    URL (and corresponding IP address)

    Reference:

    What's included in a Reputation Request made by the SEP 12.1 Reputation Engine?

    http://www.symantec.com/docs/HOWTO59336

     

    You can disable the submission of reputation information. Symantec recommends, however, that you keep submissions enabled.

    Check this Article:

    How Symantec Endpoint Protection uses reputation data to make decisions about files

    https://support.symantec.com/en_US/article.HOWTO80989.html

    Insight determines a file's security rating by examining the following characteristics of the file and its context:

    • The source of the file

    • How new the file is

    • How common the file is in the community

    • Other security metrics, such as how the file might be associated with malware

     

    Regards,



  • 4.  RE: What Data Gets Sent to Symantec Insight During a Reputation Risk Query?

    Posted Apr 30, 2015 05:22 AM

    Hello,

    here's the most detailed answer for you:

    What's included in a Reputation Request made by the SEP 12.1 Reputation Engine?
    Article URL: http://www.symantec.com/docs/HOWTO59336
     



  • 5.  RE: What Data Gets Sent to Symantec Insight During a Reputation Risk Query?

    Posted Apr 30, 2015 08:02 AM

    Thank you. This is exactly what I was looking for.