---
title: "Configure an Anti-Malware ruleset"
canonical: "https://docs.aryaka.com/space/KNOW/30704707/Configure%20an%20Anti-Malware%20ruleset"
format: markdown
---
This topic describes how to create or edit an Anti-Malware ruleset. Anti-Malware rules are used to permit or deny file transfers in your network. You can add multiple Anti-Malware rules to a ruleset and then apply the ruleset to one or more sites. If you want to create an Anti-Malware rule that applies only to one site, see the  Configure site-level security features  help topic.  Anti-Malware Aryaka uses  Webroot  and  Sophos  to classify a file's reputation as Good, Bad, or Unknown. Files are separated into sections of data that are classified one at a time to reduce the bandwidth required for classifying large files. If a Bad section is detected, the transfer of the file can be blocked without the rest of the file needing to be classified. For files that are classified as Unknown, you can  configure Unknown Traffic Control  to determine whether they should be permitted or denied.  See the  Anti-Malware  topic for additional details on the Anti-Malware security engine. Create a ruleset The Anti-Malware page displays a table of Anti-Malware rulesets. Rulesets are associated with one or more of your sites and include one or more rules that permit or deny traffic based on configured match criteria. See the  Security engine rulesets  topic for an overview of the different types of security rulesets. Complete the procedures later in this topic to create or edit an Anti-Malware ruleset.  Default rule If you do not configure any Anti-Malware rulesets or  site-level rules , the Anti-Malware Default template is applied to traffic for all sites. The Default template includes a rule that matches all traffic and permits it without verifying the file's reputation. Manage the Rules table The Rules table within a ruleset displays a list of configured rules that are evaluated when traffic is inspected by the associated security engine for any sites that the ruleset is applied to. Each table row includes the following details: Rule ID—Identification number for the rule, used in security logs. Name—User-defined name for the rule. Source—Match criteria related to the source of the traffic (for example, source IP address or user).  Destination—Match criteria related to the destination of the traffic (for example, destination IP address or domain). Services—Match criteria related to traffic protocol and destination port. Payload—Match criteria related to HTTP method and HTTP header. Schedule—Match criteria related to a defined schedule. Action—Action applied to matched traffic (for example, permit or drop).  Note the following when interacting with the Rules table: If a single match criteria has more than four entires, click  Show More  to view all entires.  If an asset is used as match criteria, click the asset name to display an in-page view of what the asset includes. The Rules table also includes the following components: Detailed View toggle—Turn this toggle on to display details on the type of match criteria (for example, IP or URL) and the required condition (for example, is or is not) included in a rule. When this toggle is turned off, only the specific match criteria are displayed.  Download Table icon—Download the rule table as a CSV file. Configure table icon—Select whether to display the columns related to match criteria (for example, source, destination, and schedule) in the table. Reorder button—Reorder the rules in the table. See step 10 of the  Add an Anti-Malware ruleset  procedure for details.  Note that Rule tables are evaluated from top to bottom. If a more specific rule appears above a more generic rule, and the traffic matches the more specific rule, the rule's corresponding action is executed and the next (more generic) rule is not evaluated. When you configure the Anti-Malware rules within a ruleset, you can use the following match criteria to permit or deny file transfers in your network: Source IPs Source zones Source geolocations Users Applications Domain names HTTP headers Protocols URLs Destination IPs Destination networks Destination sites Destination geolocations Schedule These match criteria can be specified individually when you create a rule or as part of a named asset, defined on the  Asset Management  page. Assets can be reused in your security rules, but must be configured  before  you create the rule in which you want to use it To add an Anti-Malware ruleset Open the Anti-Malware page if it is not already open: Log in to MyAryaka. The Home page appears. Click  Security  >  Anti-Malware  in the left navigation pane. The Anti-Malware page appears and displays a list of configured rulesets. Click the  Add  icon. The Add a Template page appears and displays the Ruleset Details pane and the Rules table.  In the Ruleset Details pane, enter a name and, optionally, a description for your new ruleset, then click the  Type  drop-down list and select one of the following options:  High Priority Custom Template—Define a set of high priority rules for a specific site or group of sites. Only rules in the Global Non-Overridable Template take precedence over the rules in this ruleset. You can only configure one ruleset of this type for a given site.  Normal Priority Custom Template—Define a set of rules for a specific site or group of sites. Rules in this ruleset are evaluated after all rules in Global Non-Overridable and High Priority Custom templates. The rules in this ruleset can be overridden by  site-level rules  and rules in other Normal Priority Custom templates, based on your configured evaluation order. Note:  You cannot add a Global Non Overridable template, but you can edit the existing one. You cannot add a Default template or edit the existing one. See the  Security engine rulesets  topic for an overview of the different types of security rulesets. Click  Add  on the Rules table. The Add a Policy page appears and displays a Details pane and a Match Criteria pane. In the Details pane, enter a name for your rule, then click the  Actions  drop-down list and select one of the following actions to take when a condition of the rule is met: Enforce Verdict—File reputation is verified and only those with a  Good  classification are permitted. Ignore Verdict—File reputation is verified, but all files are permitted.  Log Only—File reputation is verified, but all files are permitted. This is intended as a temporary action while you evaluate traffic. After you have evaluated traffic, update the rule with one of the other actions. Skip Engine—File reputation is not verified.  In the Match Criteria pane, complete the following procedure for each of the criterion you want to include in the rule:  Click the  Condition  drop-down list and select a condition for the criterion. Complete one of the following procedures to add match criteria: Type a criterion into the appropriate field and hit Enter. The criterion is added. Click the  Add  icon. The Add < criterion > dialog appears. Depending on the type of match criteria selected, do one of the following: Click one or more entities you want to include as match criteria for the rule. The selected entities are highlighted in green and display a check. Click  Add Selected . The page displays the selected entities for each criterion.  Enter one or more entities you want to include as match criteria for the rule. Click  Add Selected . The page displays the selected entities for each criterion.   Click  Continue . The Add a Template page appears with the rule you added included in the Rules table. (Optional) Repeat steps 4–7 to add additional rules to your ruleset.  Do one of the following: Click  Save as Draft  to save a draft of the ruleset. Click  Submit  to save the ruleset. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the Anti-Malware page displays your new ruleset in the list of Anti-Malware rulesets. Note:  The rules included in the ruleset are not applied to network traffic until the ruleset is associated with at least one site. Complete the  Associate an Anti-Malware ruleset with a site  procedure to associate a ruleset with one or more sites.  (Optional) Complete the following procedure to reorder the Rules table: Note:  Rules are evaluated in a top-down manner based on the table. The first rule that matches the traffic is executed and the rest are ignored.  Click  Reorder  in the rule table. The displayed table now includes the Precedence column, which indicates the evaluation order for the rule, and the Reorder column, which displays the following actions: Move Down—Move the selected rule down one row in the table. Move Up—Move the selected rule up one row in the table. Move to Bottom—Move the selected rule to the bottom of the table. This rule is now evaluated last.  Move to Top—Move the selected rule to the top of the table. This rule is now evaluated first.  Change Precedence—Use the Reorder dialog to enter a new precedence value for the selected rule. For example, if your rule list contains five rules and you want the selected rule to be evaluated third, enter 3 in the Reorder dialog, then click  Update . Click  Submit . The Rules table is updated according to the modified rule order. To associate an Anti-Malware ruleset with a site Open the Anti-Malware page if it is not already open: Log in to MyAryaka. The Home page appears. Click  Security  >  Anti-Malware  in the left navigation pane. The Anti-Malware page appears and displays a list of configured rulesets. On the Anti-Malware page, click the name of the ruleset you want to associate with a site. The  <rulesetName>  page appears and displays two tiles: Ruleset Details—Displays the number of rules included in the ruleset and the current status of the ruleset. This tile is selected by default. Site Associations—Displays the number of sites and site classes associated with the ruleset and the current status of the site associations. Click the  Site Associations  tile. The  <rulesetName>  page displays the Associated Sites pane and the Associated Site Classes pane in read-only mode. Click  Edit . The Site Associations page appears. Complete at least one of the following procedures to associate the ruleset with a site or a group of sites: To associate the ruleset with a site:  In the Associated Sites pane, click  Add . The Add Site dialog displays the sites that you can associate with this Anti-Malware ruleset.  Note:  Sites must have an Aryaka SmartSecure Anti-Malware Add-on subscription to be associated with this ruleset.  Click one or more sites you want to associate with this Anti-Malware ruleset. The selected sites are highlighted in green and display a check. Click  Add Selected . The Add a Template page displays the selected sites in the Associated Sites table.  To associate the ruleset with a group of sites: In the Associated Site Classes pane, click  Add . The Add Site Class dialog displays the site classes that you can associate with this Anti-Malware ruleset. Click one or more site classes you want to associate with this Anti-Malware ruleset. The selected site classes are highlighted in green and display a check. Click  Add Selected . The Add a Template page displays the selected site classes in the Associated Site Classes table. Click  Submit . You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the rules included in the Anti-Malware ruleset are now used to permit or deny file transfers for the sites the ruleset is associated with. To edit an Anti-Malware ruleset Open the Anti-Malware page if it is not already open: Log in to MyAryaka. The Home page appears. Click  Security  >  Anti-Malware  in the left navigation pane. The Anti-Malware page appears and displays a list of configured rulesets. Click the name of the Anti-Malware ruleset you want to edit. The < rulesetName > page appears and displays two tiles: Ruleset Details—Displays the number of rules included in the ruleset and the current status of the ruleset. This tile is selected by default. Site Associations—Displays the number of sites and site classes associated with the ruleset and the current status of the site associations. (Optional) Click  Disable  to render the ruleset inactive. The ruleset can be enabled again later.  (Optional) Click the  Delete  icon to remove the ruleset. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the ruleset is removed from the list of Anti-Malware rulesets. Note:  You cannot delete the global or default rulesets. (Optional) Click  Reorder  in the Rules table. The displayed table now includes the Precedence column, which indicates the evaluation order for the rule, and the Reorder column, which displays the following actions: Move Down—Move the selected rule down one row in the table.  Move Up—Move the selected rule up one row in the table. Move to Bottom—Move the selected rule to the bottom of the table. This rule is now evaluated last.  Move to Top—Move the selected rule to the top of the table. This rule is now evaluated first.  Change Precedence—Use the Reorder dialog to enter a new precedence value for the selected rule. For example, if your rule list contains five rules and you want the selected rule to be evaluated third, enter 3 in the Reorder dialog, then click  Update . Click  Edit  in the Ruleset Details pane. The < rulesetName > page appears in edit mode. Use the following options to modify rules as needed: Edit —Displays the match criteria in edit mode. Add, edit, or remove entities from any of the match criteria. Complete step 6 of the  Add an Anti-Malware ruleset  procedure to add or edit the entities included in a criterion, then click  Continue . Add Below —Adds a new blank rule below the selected rule. Options  >  Clone —Adds a new rule with the same match criteria as the cloned rule. The new rule is added to the rule table directly after the rule it was cloned from. Options  >  Disable —Renders the rule inactive, but does not remove it from the rule table. The rule can be reenabled later.  Options  >  Delete —Removes the rule from the site's rule table.  Do one of the following: Click  Save as Draft  to save a draft of the ruleset changes. Click  Submit  to save the ruleset changes. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the changes to the Anti-Malware ruleset are saved. Click the  Site Associations  tile. The  <rulesetName>  page displays the Associated Sites pane and the Associated Site Classes pane in read-only mode. Click  Edit . The Site Associations page appears. Complete the  Associate an Anti-Malware ruleset with a site  procedure to edit the sites with which the ruleset is associated.  Click  Submit  to save the ruleset changes. You are prompted to select one of the following options:  Activate Later  or  Activate Now . See  Activate configuration updates  for details. When your update is activated, the changes to the Anti-Malware ruleset are saved.  In this topic Related topics Anti-Malware Configure site-level security features Security engine rulesets Asset management Configure Unknown Traffic Control