Blocking Malicious Users

Prev Next

Users that you suspect of triggering ransomware attacks can be blocked by adding them to a Blocked Users group. Blocked users are prevented from accessing the edge filer by all authenticated protocols, including SMB, NFS, FTP, and the edge filer user interface.

Users can be blocked automatically or manually. Users that trigger a ransomware incident can be automatically added to a Blocked Users group.

Note

When users are added to the Blocked Users group, their existing SMB sessions are immediately closed. Existing connections via other protocols are not immediately terminated, but the user is not able to create a new session.

To block users automatically:

  1. In the Configuration view, select Security > Ransom Protect in the navigation pane.
    The Ransom Protect page is displayed.
    image.png
  2. Click Settings and slide Block Malicious Users on.
    image.png
  3. If you made any changes, click Save, otherwise click Revert to revert to the last saved configuration.

Any incident that CTERA Ransom Protect identifies as a ransomware attack, whether via behavioral detection or honeypot detection, causes the user who initiated the incident to automatically be added to the Blocked Users group. The existing SMB session is immediately closed and the user is not able to create a new session.

Two separate incidents may be created for the same user, as the counting of behavioral and honeypot strikes is independent.

Note

CTERA recommends blocking the user in Active Directory as well.

To block users manually:

  1. In the Configuration view, select Security > Ransom Protect in the navigation pane.
    The Ransom Protect page is displayed.
    image.png
  2. Click the number below Blocked Users.
    The Specify Group Name window is displayed.
    image.png
  3. Click Next.
    The Select Group Members window is displayed.
    image.png
  4. Select the user to block.
    1. Select Local Users, Domain domainName Users, or Domain domainName Groups.
      image.png
    2. In the Quick Search box start entering the name of the user or group to block or click ... and select the user from the list.
  5. Click Next.
    The Wizard Completed window is displayed.
  6. Click Finish.

The user is blocked from access to the edge filer.
image.png

Removing Users From the Blocked Users Group

A user that has been blocked from accessing the edge filer, can be unblocked.

To remove a user from the Blocked Users group:

  1. In the Configuration view, select Security > Ransom Protect in the navigation pane.
    The Ransom Protect page is displayed.
    image.png
  2. Click the number below Blocked Users.
    The Specify Group Name window is displayed.
    image.png
  3. Click Next.
    The Select Group Members window is displayed.
    image.png
  4. Select Local Users, Domain domainName Users, or Domain domainName Groups to display the blocked users in that group and click the image.png icon next to the user to remove from the list.

The user is removed from the Blocked Users list.