{"id":7067,"date":"2014-10-29T09:17:16","date_gmt":"2014-10-29T16:17:16","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=7067"},"modified":"2023-03-28T13:34:49","modified_gmt":"2023-03-28T20:34:49","slug":"web-security-tips-pan-db-works","status":"publish","type":"post","link":"https:\/\/www2.paloaltonetworks.com\/blog\/2014\/10\/web-security-tips-pan-db-works\/","title":{"rendered":"Web security tips: How PAN-DB works"},"content":{"rendered":"<p>PAN-DB is our URL and IP database, designed to fulfill an enterprise\u2019s web security needs. PAN-DB is tightly integrated into PAN-OS, providing you Advanced Persistent Threat (APT) protection with high-performance beyond traditional URL filtering.<\/p>\n<p>Traditional URL filtering is intended to control unwanted web surfing such as non-business or illegal sites, but it usually doesn\u2019t cover up to the minute malicious web sites such as newly discovered malware site, exploit site or command and control sites. Let me explain how PAN-DB works for you.<\/p>\n<p><!--more--><\/p>\n<h3>How PAN-DB maximizes your URL lookup performance<\/h3>\n<p style=\"text-align: center;\"><strong>\u00a0<a href=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2014\/10\/PAN-DB.png\"><div style=\"max-width:100%\" data-width=\"282\"><span class=\"ar-custom\" style=\"padding-bottom:129.79%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"alignnone size-full wp-image-7068 lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2014\/10\/PAN-DB.png\" alt=\"PAN-DB\" width=\"282\" height=\"366\" srcset=\"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2014\/10\/PAN-DB.png 282w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2014\/10\/PAN-DB-230x298.png 230w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2014\/10\/PAN-DB-231x300.png 231w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2014\/10\/PAN-DB-30x40.png 30w\" sizes=\"auto, (max-width: 282px) 100vw, 282px\" \/><\/span><\/div><\/a><\/strong><\/p>\n<p style=\"text-align: center;\">Figure1. PAN-DB classification and cache system<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>PAN-DB Core:<\/strong> The PAN-DB Core, located in the Palo Alto Networks threat intelligence cloud, has a full URL and IP database to cover web security needs.<\/p>\n<p><strong>Seed database:<\/strong> When the PAN-DB is enabled on your firewalls, a subset of the full URL database is downloaded from the Palo Alto Networks threat intelligence cloud to firewalls based on the selected geographic region. Each region contains a subset of the URL database that includes URLs most accessed for the given region. This regional subset of the URL database allows the firewalls to store a much smaller URL database, in order to greatly improve URL lookup performance. You can download a seed database by region to the each firewall from our Panorama centralized management system as well.<\/p>\n<p style=\"text-align: center;\">\u00a0<a href=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2014\/10\/Seed.png\"><div style=\"max-width:100%\" data-width=\"343\"><span class=\"ar-custom\" style=\"padding-bottom:52.19%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"size-full wp-image-7069 aligncenter lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2014\/10\/Seed.png\" alt=\"Seed\" width=\"343\" height=\"179\" srcset=\"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2014\/10\/Seed.png 343w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2014\/10\/Seed-230x120.png 230w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2014\/10\/Seed-76x40.png 76w\" sizes=\"auto, (max-width: 343px) 100vw, 343px\" \/><\/span><\/div><\/a>Figure 2. Seed database by regions<\/p>\n<p><strong>Management plane cache:<\/strong> The seed database is placed into the management plane (MP) cache to provide quick URL lookups. The MP cache will pull more URLs and categories from the PAN-DB core as users access sites that are not currently in the MP cache. If the URL requested by a user is \u201cunknown\u201d to Palo Alto Networks, the URL will be examined, categorized, and implemented as appropriate.<\/p>\n<p><strong>Dataplane cache:<\/strong> A dataplane cache (DP) contains the most frequently accessed sites for quicker URL lookups.<\/p>\n<h3>Malicious URL database delivered from WildFire<\/h3>\n<p>Millions of URLs and IPs are classified in a variety of ways. In addition to the \u201cMulti-language classification engine\u201d and the \u201cURL change request from users,\u201d PAN-DB receives malicious URL and IP information from WildFire. Examples of malicious URL and IP database are shown below.<\/p>\n<ul>\n<li><strong>Malware Download URL and IP address:<\/strong> Prevent from downloading malware.<\/li>\n<li><strong>C&amp;C URL and IP address:<\/strong> Disable malware communications.<\/li>\n<\/ul>\n<p>The malicious URLs are generated as WildFire identifies unknown malware, zero-day exploits and APTs by executing them in a virtual sandbox environment.<\/p>\n<h3>PAN-DB will block malicious URL with low latency<\/h3>\n<p>PAN-DB has a superior mechanism to lookup URL faster, and then you will get URL category information without sacrificing the throughput.<\/p>\n<p>The malicious URLs are generated as WildFire identifies unknown malware, zero-day exploits, and Advanced Persistent Threats (APTs) and executes them in a virtual sandbox environment.\u00a0The ongoing malicious URL updates to PAN-DB allows you to block malware downloads and disable malware command and control communications.<\/p>\n<p>By utilizing malicious URL database, you can block variety of malicious web access and communication without compromising web access performance.<\/p>\n<p>To learn more about web security, please visit our resource page, <a href=\"https:\/\/www.paloaltonetworks.com\/products\/features\/url-filtering.html\" target=\"_blank\" rel=\"noopener\">Control Web Activity with URL Filtering<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>PAN-DB is our URL and IP database, designed to fulfill an enterprise\u2019s web security needs. PAN-DB is tightly integrated into PAN-OS, providing you Advanced Persistent Threat (APT) protection with high-performance beyond traditional &hellip;<\/p>\n","protected":false},"author":40,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[155,744],"tags":[164,745,506,852,69],"coauthors":[716],"class_list":["post-7067","post","type-post","status-publish","format-standard","hentry","category-cybersecurity-2","category-web-security","tag-apt","tag-pan-db","tag-url-filtering","tag-web-security-2","tag-wildfire"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/7067","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/40"}],"replies":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=7067"}],"version-history":[{"count":6,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/7067\/revisions"}],"predecessor-version":[{"id":182188,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/7067\/revisions\/182188"}],"wp:attachment":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=7067"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=7067"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=7067"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=7067"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}