Insights: Advanced URL Filtering
Focus
Strata Cloud Manager

Insights: Advanced URL Filtering

Table of Contents

Insights: Advanced URL Filtering

The Advanced URL Filtering Operator Dashboard provides a central view of web threat activity with immediate, actionable insights for security teams.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
Each of these licenses include access to Strata Cloud Manager:
The other licenses and prerequisites needed for visibility are:
  • A role that has permission to view the dashboard
  • Advanced URL Filtering
  • Strata Logging Service
The features and capabilities available to you in Strata Cloud Manager depend on which license(s) you are using.
  • Click Strata Cloud ManagerInsightsSecurityAdvanced URL Filtering to get started.
This image shows a partial view of the dashboard. Additional widgets may be available, and dashboard content is subject to change.

Dashboard Scope and Capabilities

The Advanced URL Filtering Operator Dashboard is a subscription-specific view that delivers a centralized hub for web threat activity, offering immediate and actionable insights. Interactive widgets surface critical efficacy metrics—such as day-zero malicious URL detections, daily threat trends, and top risky domains—providing an intuitive starting point for deeper drill-down analysis. By utilizing contextual data on users, devices, and policies, security teams can detect, investigate, and remediate web-based threats more efficiently than ever before.
Flexible Data Filtering: Customize the dashboard time range (from the last 15 minutes up to 45 days, or define a custom range) and apply general filters to isolate specific datasets.
Interactive Widgets: Interact directly with individual widgets to filter data, reorder columns, zoom, view raw data, export as CSV, and toggle legends and labels.
Key Visibility Metrics
The dashboard provides granular visibility into the following areas:
  • Key statistics—Total URL requests, total malicious URL requests detected, malicious IP addresses, and zero-day threats (malicious URLs detected in real time), providing an at-a-glance assessment of URL filtering efficacy and the scale of real-time protection.
  • Daily threat trends—Daily threat activity over time including real-time detections and phishing attempts. Spikes indicate anomalies and need investigation.
  • URL categorization—URL request distribution (the balance of safe versus risky traffic) and breakdown of malicious URL categories (such as command-and-control, phishing, grayware, and ransomware).
  • Domain analysis—Top visited domains overall and top visited malicious domains, identifying the external infrastructure that attackers are utilizing.
  • User and firewall attribution—Top users accessing malicious URL categories and top firewalls contributing to malicious traffic, pinpointing the human and network hotspots driving risk.
  • Policy effectiveness—Security rules triggered most often, indicating policy coverage and identifying opportunities for optimization.
Operational Use Cases
Leverage the dashboard data to drive the following investigative and operational initiatives:
  • Scope the initial attack vector—Modern campaigns like Zloader begin at the web gateway. Identify immediate spikes in real-time detection and phishing attempts. Zero-day threat counts show malicious URLs detected in real time that represent proactive prevention of novel, never-before-seen attacks before they enter your network.
  • Identify human hotspots—Pinpoint users accessing the most malicious URL categories. This enables you to move from general blocking to targeted intervention (such as security training or network isolation) for high-risk users who are repeat offenders.
  • Identify infrastructure hotspots—Identify the external infrastructure attackers are utilizing, and identify enforcement points that may be misconfigured or serving high-risk network segments, allowing targeted policy tightening.
  • Investigate and apply targeted blocks—Understand the nature of threats by category (C2, phishing, grayware, ransomware) and cross-reference with risky domains to zero in on high-risk areas and apply targeted URL category or domain blocks in your security policies.
  • Confirm safety and investment value—Compare total URLs versus malicious alongside zero-day detections and daily trends to demonstrate ROI. These metrics help CISOs confidently answer whether the organization is protected and whether the Advanced URL Filtering investment is delivering value.