Endpoint Protection

 View Only

Submitting information about detections to Symantec Security Response 

Aug 12, 2011 12:02 PM

Submitting information about detections to Symantec Security Response

 We can configure your computer to automatically submit information about detections to Symantec Security Response for analysis.

 Symantec Response and the Global Intelligence Network use this submitted information to quickly formulate responses to new and developing security threats. The data that you submit improves Symantec's ability to respond to threats and customize protection. Symantec recommends that you always allow submissions.

 We can choose to submit any of the following types of data:

 

File reputation

Information about files that are detected based on their reputation. The information about these files contributes to the Symantec Insight reputation database to help protect your computers from new and emerging risks.

 ■ Antivirus detections

Information about virus and spyware scan detections.

 

Antivirus advanced heuristic detections

Information about potential threats detected by Bloodhound and other virus and spyware scan heuristics. These detections are silent detections that do not appear in the Risk log. Information about these detections is used for statistical analysis.

 ■ SONAR detections

Information about threats that SONAR detects, which include high or low risk detections, system change events, and suspicious behavior from trusted applications.

 

SONAR heuristics

SONAR heuristic detections are silent detections that do not appear in the Risk log. This information is used for statistical analysis. We can also manually submit a sample to Response from the Quarantine.

 

We can enable your computer to submit information about detected threats to Symantec Security Response. Symantec Security Response uses this information to protect your client computers from new, targeted, and mutating threats. Any data we submit improves Symantec's ability to respond to threats and customize protection for your computer. Symantec recommends that you submit as much detection information as possible.

  

We can manually submit a sample to Symantec Response from the Quarantine page. The Quarantine page also lets you determine how items are submitted to Symantec Security Response.

 

To configure submissions to Symantec Security Response

 

1) Select Change Settings > Client Management.

 

2) On the Submissions tab, check Let this computer automatically forward selected anonymous security information to Symantec. This option lets Symantec Endpoint Protection submit information about the threats that are found on our computer.

Symantec recommends that you keep this option enabled.

 

3 Select the types of information to submit:

 ■ File reputation

■ Antivirus detections

■ Antivirus advanced heuristic detections

■ SONAR detections

■ SONAR heuristics

SONAR heuristic detections are silent detections that do not appear in the Risk log. This information is used for statistical analysis.

 

4) Enable Allow Insight lookups for threat detection to allow Symantec Endpoint Protection to use Symantec's reputation database to make decisions about threats.

 

Insight lookups are enabled by default. Symantec recommends that we allow Insight lookups. Disabling this feature disables the Download Insight and may impair the functionality of SONAR and Insight Lookup.

However, we can disable this option if you do not want to allow Symantec to query Symantec Insight.

Statistics
0 Favorited
5 Views
0 Files
0 Shares
0 Downloads

Tags and Keywords

Comments

May 22, 2019 03:31 AM

Also, "Basic protection only" is not recommended.  The more SEP components, the better. &: )

SEP Times in the City: A Helpful Symantec Endpoint Protection Analogy
https://www-secure.symantec.com/connect/articles/sep-times-city-helpful-symantec-endpoint-protection-analogy

May 22, 2019 03:30 AM

Disable Telemetry submissions:

Symantec Endpoint Protection Telemetry Submissions

https://www.symantec.com/docs/HOWTO124992

May 08, 2019 12:34 PM

Does anybody know why SEP v14.x with basic protection submits files to Symantec? In AV policy the Submissions are enabled, but the SONAR component is not installed on client. In log there is message:

[SONAR detection Submission] File submitted to Symantec......

As well message:

[File reputation submission] Information submitted to Symantec.  Size (bytes): 2121.

 

 

May 13, 2014 06:41 AM

This new article may be of interest to anyone needing to send files to Security Response for analysis:

Symantec Insider Tip: Successful Submissions!
https://www-secure.symantec.com/connect/articles/symantec-insider-tip-successful-submissions

It contains details on both the anonymous submissions and web portal submissions which generate a tracking number.

Many thanks!

Mick

Jan 16, 2012 03:07 PM

Really useful, expecially for SEP 12.1!

Related Entries and Links

No Related Resource entered.