Web Content and Reputation

Gateways and Access Points (APs) additionally integrate the Brightcloud Web Content and Reputation technology to classify billions of URLs and domains. This service, included in the HPE Aruba Networking Central subscription, provides an always-up-to-date classification of all web traffic traversing the network infrastructure. Websites are classified both in terms of their content as well as their reputation.

To use this service, the Deep Packet Inspection (DPI) engine present in APs and gateways need to inspect the first few packets in a given session to identify the URL (for HTTP traffic) or the domain (for HTTPS traffic).

In the case of HTTPS traffic, even though the content of encrypted packets is not visible, the DPI engine can analyze the leverage Server Name Indication (SNI) information as part of its analysis to identify and classify encrypted traffic.

Note that SNI is an extension of the Transport Layer Security (TLS) protocol, often used in HTTPS connections, that allows a client or browser to indicate which domain it is trying to connect to at the start of the TLS handshake.

Figure 1: Domain Inspection

URL and Domain Classification

The URL classification process is a multi-step process that uses advanced machine learning to identify and classify web sites. The process is designed to ensure that results are timely and accurate. A high-level overview of the process is shown in the diagram below:

Figure 2: URL & Domain Classification Process

Throughout the day, the automated crawler/downloader identifies new sites and also revisits sites to determine/update classification data. Then, using machine learning, a site is classified into one or many (up to 5) categories.

In total, there are more than 80 categories and classifications that are supported for 40+ languages. The full description of supported categories can be found in https://www.brightcloud.com/threat-intelligence-resource-center.

As shown in the figure URL & Domain Classification Process, the classification process is almost entirely automated. When a site is newly classified or re-classified, these changes are published and made available to customers through real-time updates.

The BrightCloud service also revisits sites regularly to update classification data. The revisit frequency varies based on the change velocity of the site, popularity, ranking, history of previous changes, etc. Some interesting statistics about this service include:

  • Brightcloud's database includes more than 43 billion URLs, 1 billion domains, and a historical record of more than 38 billion files being analyzed.

  • These URLs and domains are constantly scanned by a network of close to 100 million sensors, generating an aggregated database of 32PB worth of information.

  • As a result of this, an average of 25,000 URLs and threats get analyzed every day, with a reported false positive rate less than 0.2%.

Application and Domain Reputation

Web Reputation consists of an up-to-date security check of the websites' users visit. This enables technology partners to add a layer of real-time security to their customers’ web defenses by accurately assessing the risk posed when opening a URL, independent of its site category.

While the BrightCloud Web Classification Service provides site classification across 82 categories, the Web Reputation Service offers an additional lens through which a site can be evaluated as a potential threat.

In addition to category, it uses site history, age, rank, location, networks, links, real-time performance, as well as other contextual and behavioral trends to determine a site’s Web Reputation Index (WRI). WRI scores range from 1 to 100, with tiers split into Trustworthy, Low Risk, Moderate Risk, Suspicious, and High Risk.

The service also provides domain-level reputation scores based on the domain’s threat history, age, popularity and other factors, such as its underlying URLs. These reputation tiers enable customers to finely tune their security settings based on their risk tolerance and proactively prevent attacks by limiting the risk of end-user exposure to inappropriate or malicious web content.

For the URL and domain classification, the reputation assessment is automated and uses the same sensors to take care of both classification and reputation analysis for over 95% of the known Internet covered.

Figure 3: BrightCloud Web Classification and Web Reputation Services

Table 1: Brigthcloud Web Reputation Index

Reputation Index

Description

01-20

High Risk

These are high-risk sites. There is a high predictive risk that the user will be High Risk exposed to malicious links or payloads.

21-40

Suspicious

These are suspicious sites. There is a higher than average predictive risk that the user will be exposed to malicious links or payloads.

41-60

Moderate Risk

These are generally benign sites but have exhibited some characteristics that suggest security risk. There is some predictive risk that the user will be exposed to malicious links or payloads.

61-80

Low Risk

These are benign sites, and rarely exhibit characteristics that expose the user to security risks. There is a low predictive risk of malicious links or payloads.

81-100

Trustworthy

These are well known sites with strong security characteristics. There is a very low predictive risk that the user will be exposed to malicious links or payloads.