Email Security
Register for Free Trial Download

Blended Threats Module

The Blended Threats Module is a unique solution that addresses the growing issue of Blended Threats that originate in Email and infect through Web use. Blended threats are successful because they by-pass email malware scanning as there is no attachment and yet downloads its malicious payload through the web gateway where there is usually next to no malware scanning when a user clicks on the embedded URL link. It goes beyond the protection offered by leading signature-based malware scanners by using innovative cloud-based behavioral analysis to determine the malicious nature of any suspect URL links found within Email and then feeds that data into M86's Web Security solutions.


Blended Threats Module

The Blended Threat Module in MailMarshal SMTP firstly checks any suspicious links against the locally cached copy of the blended threats knowledge service, if still unknown it forwards the suspicious link to the cloud-based Blended Threat Knowledge Service for analysis and identification. The cloud service also includes URL databases updated by M86 Security Lab analysts and other proprietary messaging sources, providing an additional means to identify potential threats on the Web. These threats are automatically and proactively analyzed to observe the actual behavior of the message or content in a secure and protected environment.

These confirmed threats are submitted to the Blended Threat Knowledge Service. This service is then fed back and integrated into M86's Web products—such as the R3000 Internet filter and WebMarshal—to provide accurate, reliable protection against blended threats across email and web.

Blended Threats Module for MailMarshal SMTP
Click to Enlarge

The analysis engine behind the Blended Threats Knowledge service observes the behavior of potential blended threats with the behavioral observation engine, reviewing the active content and even activating links to the embedded URLs. Multiple instances of the Observation Engine provide the performance to handle large traffic volumes and administrator settings provide options to blacklist and whitelist URLs, as well as, block, warn, or neutralize the blended threats. Because the Blended Threat Module doesn't rely on signatures, it provides a critical layer for catching and neutralizing new exploits.