Specification Sheet

3
Capture Cloud Platform
SonicWall's Capture Cloud Platform
delivers cloud-based threat prevention
and network management plus reporting
and analytics for organizations of any
size. The platform consolidates threat
intelligence gathered from multiple
sources including our award-winning
multi-engine network sandboxing service,
Capture Advanced Threat Protection, as
well as more than 1 million SonicWall
sensors located around the globe.
If data coming into the network is found
to contain previously-unseen malicious
code, SonicWall’s dedicated, in-house
Capture Labs threat research team
develops signatures that are stored in
the Capture Cloud Platform database
and deployed to customer rewalls for
up-to-date protection. New updates take
effect immediately without reboots or
interruptions. The signatures resident
on the appliance protect against wide
classes of attacks, covering tens of
thousands of individual threats. In
addition to the countermeasures on
the appliance, TZ rewalls also have
continuous access to the Capture Cloud
Platform database which extends the
onboard signature intelligence with tens
of millions of signatures.
In addition to providing threat prevention,
the Capture Cloud Platform offers
single pane of glass management and
administrators can easily create both
real-time and historical reports on
network activity.
Advanced threat protection
At the center of SonicWall automated,
real-time breach prevention is SonicWall
Capture Advanced Threat Protection
service, a cloud-based multi-engine
sandbox that extends rewall threat
protection to detect and prevent zero-
day threats. Suspicious les are sent
to the cloud where they are analyzed
using deep learning algorithms with
the option to hold them at the gateway
until a verdict is determined. The multi-
engine sandbox platform, which includes
Real-Time Deep Memory Inspection,
virtualized sandboxing, full system
emulation and hypervisor level analysis
technology, executes suspicious code
and analyzes behavior. When a le is
identied as malicious, it is blocked
and a hash is immediately created
within Capture ATP. Soon after, a
signature is sent to rewalls to prevent
follow-on attacks.
The service analyzes a broad range
of operating systems and le types,
including executable programs, DLL,
PDFs, MS Ofce documents, archives,
JAR and APK.
For complete endpoint protection, the
SonicWall Capture Client combines
next-generation anti-virus technology
with SonicWall's cloud-based
multi-engine sandbox.
Streaming Data
PDF
Email
Data File
101001001010
010100101101
010010100100
101001010010
110101010010
010100100010
1 01100100101
Endpoint
Arfact 1
Arfact 2
Arfact 3
Arfact 4
Hypervisor
Emulaon
Virtualizaon
RTDMI
Deep Learning
Algorithms
MACHINE
LEARNING
Classified Malware
RANSOMWARE
Locky
RANSOMWARE
WannaCry
TROJAN
Spartan
UNKNOWN
CLOUD CAPTURE
SANDBOX
SENT
BLOCK
A
B
C
D
A
B C
D
BLOCK
unl
VERDICT
GoodBad