Page 1 of 1

Can we block all pornographic websites for all the users via SafeSquid-SWG? ( Client Discussion #2 )

Posted: Fri Apr 24, 2020 9:07 am
by aashish97
Hello All,

I have received questions from user focusing on blocking pornographic websites for their enterprise.

Before Actually beginning with the discussion let's first understand how are websites blocked in SAFESQUID-SWG.

Whenever user makes a request to remote server via SafeSquid-SWG, SafeSquid will first extract the domain name from the client request. And then it will use the Respective Categorisation Engine ( SSQORE [ Not used in the newer versions of SafeSquid ] or SQSCAN ) to fetch the web Category for that domain and then check the policy if that web Category is blocked for this user or not.
If it is blocked in the policy.
Then SafeSquid will block the web request and send a Template with necessary information to the user
If it is not Blocked
Then SafeSquid will initiate a connection to the respective web server.

SafeSquid also has Request Profiles which help user to manually add website name in REGULAR EXPRESSION FORMAT ( REGEX ) and after creating that Request Profile ( Application Sigbature.) A policy can be created to block that Request Profile.

The below discussion a simple scenario of most asked question.

After some detailed discussion with the client

I have added that discussion below which might also solve your questions.

Questions

-----------1----------

1) Can we block all pornographic websites for all the users via SafeSquid-SWG?

Solution:
--------------

The Answer is Partially yes depending upon the use case.
Let's first understand and elaborate the question.

The use case is to block user from accessing any pornographic websites while user is surfing via SafeSquid-SWG
And if the user tries to access any pornographic website then he will be blocked and a block template will be displayed.

However here, if we try to search porn or any adult content on any search engine we will find lakhs of results with websites providing pornographic content.

And Inorder to block these websites we need to group them together and then block that group.
This helps to easily block many websites,

To achieve such Grouping Web Categories were created.

In simple words,
Web Categories is group similar Category of websites under group with a name
Some Web Category are listed

Adult Content -> porn.com, xxx.com, sex.com, etc and all pornographic websites are grouped under this category

Search Engines -> google.com, yahoo.com, bing.com, etc and all web sites that provide searching are grouped under this

Same ways their are many Category depending upon the Providers.

SafeSquid uses Quick Heals Web Categorisation Engine which has predefined list of websites added to their respective Categories.

And in SafeSquid if we want to block Pornographic Websites we need to block Web Category -> Pornography and all websites which are categorised as Pornography will get blocked.

Now the problem over here is their are lakhs of websites which server pornographic content

If
It is grouped in the Web Category -> Pornography Then
It is will be block
Else
It will not be Blocked. Untill and unless it is added by the Web Categorisation Provider.

--------------------2------------------

2) Then how are we going to block websites that are not Categorised as Pornography?

Solution:
---------------

In Such Scenarios, SafeSquid's Private Categorisation will help to solve the problem.

This Feature of SafeSquid let clients create their own category and add websites to these category.

Advantages of Private Category:
----------------------------------------------------
1. Custom Name Selection
2. Creating Group As Per Business Logic
3. RealTime Addition
4. Easy Management

Client can create their own web Category add websites to this category easily. And then block this category.

Over here the user has liberty to add websites to their own Category and then apply Restrictions on it.

This will solve the problem for websites that are not Categorised by the Web Categorisation Engine.

Note: This is a very Helpful and Most Used Technic to group websites inside a business organisation using their Way of Usage.
But the Problem still remains the same in this case as well
Since there are huge number of websites, the client will have to identify and then add them to the provate Category and then it will be blocked in Real-time.

Reasons Why we cannot Block Pornographic Websites Completely:
1. Because Such Websites are Added daily
2. Their domain name are changed.
3. They can also be in IP based Websites.
4. Blogging Websites also Provide Pornographic Content.


We can Mitigate The Risk of Access Most of Pornographic Websites but we cannot block all of them.

-------------------3-------------------

3) Which means even by using Private Category we cannot block ALL Pornographic Websites??

Solution:
---------------

Over here, to actually solve this problem
The Best way to solve this Problem is by Creating Smart Policies or More Stringent POLICIES.

The Best Policy To block all Such Unwanted content is using the

BLOCK ALL & ALLOW SPECIFIC STRATEGY
----------------------------------------------------------------------

Which means we will block all the websites and allow specific Category of Websites which is required by the Organisation.
This Strategy will help you solve your problem but again doing so Restricts some important websites which are used by web application in some or the other ways.

This require us to Properly analyse the Organisation Needs and Create Problem list of websites required by the Organisation.