Custom Gatelet for WhatsApp is unable to block uploads or see login logout properly
search cancel

Custom Gatelet for WhatsApp is unable to block uploads or see login logout properly

book

Article ID: 249442

calendar_today

Updated On:

Products

CASB Gateway Advanced

Issue/Introduction

Custom Gatelet for WhatsApp using Whatsapp.com and Whatsapp.net domains is unable to block uploads or inspect content. CASB Data Transfer via Gatelet policy (see example below) to block all uploads or downloads is not effective. A DLP policy that requires content inspection fails to inspect the file. Access Enforcement policy to block uploads and download fails as well. Login \ Logout is seen in CASB as file Upload and Download event.

Resolution

WhatsApp custom Gatelet will not report uploads and downloads correctly and will report the login process as a file upload. If uploads are blocked the WhatsApp page may fail to load properly.

The custom Gatelet feature will not correctly detect and inspect a file upload\download or login\logout for some applications including WhatsApp. This is because of the way the SaaS's mechanisms performs the upload including file encryption before the upload which is the case for WhatsApp. DLP content inspection will not be available for WhatsApp content (such as file uploads) as the content is encrypted before it is sent.

Custom Gatelets are best effort based as there are many ways SaaS login\logout upload\download occurs, the custom Gatelet may not be successful as the HTTP header may not have what is needed.

 

Additional Information

Custom Gatelets are best effort based on the content-type header being available with attributes. If the SaaS uploads or downloads in a different way the custom Gatelet may not work.

The best way to test a custom Gatelet is to make sure that all domains of interest are added to the Gatelet configuration. Those can be obtained by analyzing the browser Website activity trace gathered during the expected action to be monitored. Such network activity tracing is usually available in the Developer Tools of the browser, under the "Network" tab but it may differ based on the browser used. If the application is present in the CASB Audit feature it can also be used as a base for the customer Gatelet. If the custom Gatelet does not provide login, logout, upload\download with content inspection contact support with Gatelet details and capture a HTTP Archive file (har) after performing the activity and consult the product support.