Educause Security Discussion mailing list archives

Re: Blocking URLs


From: "Barton, Robert" <bartonrt () LEWISU EDU>
Date: Fri, 31 Jul 2015 16:53:52 +0000

Research if you can use a FQDN or domain name in the rule.  This will solve for a dynamic IP and possible get the 
larger group of servers.  This still is not the best solution, but may ease the pain.

Can you do the blocking of the sights at your proxy server, if you have one?  This will not stop C&C communications 
like a firewall rule, but would stop the users from hitting websites that are phishing.

Robert W. Barton
Director of Information Security
Lewis University
One University Parkway
Romeoville, IL  60446-2200
815-836-5663

From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Chris 
Green
Sent: Friday, July 31, 2015 11:47 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Blocking URLs

All,

We are looking for a cost effective solution to prevent users from accessing sites when they fall for phishing 
attempts. Right now we are blocking IPs for those sites in our firewall, but this is not a great solution for us as we 
don't want to load up our firewall with these types of rules, and the majority of these sites use dynamic IPs, so it's 
a temporary fix at best.

I wanted to see if anyone had come up with a solution for this dilemma that doesn't involve dropping six figures on an 
application firewall.

Thanks,

-C.

Chris Green
Information Security Officer
University of Texas at Tyler


This message (including any attachments) is intended only for
the use of the individual or entity to which it is addressed and
may contain information that is non-public, proprietary,
privileged, confidential, and exempt from disclosure under
applicable law or may constitute as attorney work product.
If you are not the intended recipient, you are hereby notified
that any use, dissemination, distribution, or copying of this
communication is strictly prohibited. If you have received this
communication in error, notify us immediately by telephone at (815)-836-5950 and
(i) destroy this message if a facsimile or (ii) delete this message
immediately if this is an electronic communication.

Thank you.

Current thread: