Skip to main content

upT59VH0TqYuvrSWEdju3yrKk1Vq6nTaeXZjF54SfmqBCmN_aWc0sVL2YNtg1RVms2ZSYHkaP24Qvn4kBkRecmBW9fULqsKiKgG6_DGOh3ODsQw-hkdDOnbn1HorC_vpmRfv3jwFELgyxFTRgplMnGU

Netskope Global Technical Success (GTS)

Use Case - Block the downloading of TikTok from any website

 

Netskope Cloud Version - 113

 

Objective

To demonstrate the process for block downloading of Tik Tok from any website 

 

Prerequisite

Netskope SWG license is required

 

Context

This article outlines the rationale and step-by-step process for downloading the TikTok application from any website.

Upon analyzing various websites offering the TikTok application for download, it was observed that the URL consistently includes the keywords "tiktok" or "tik-tok" in its path. Therefore, the proposed approach is to prevent downloads from websites containing these keywords in their URL paths. This concept can also be extended to other scenarios, such as blocking access to the career section of any website.

Please see the example snapshot below for reference -

lfMHQY0UtEI4DUWirnnC7F8WP4kDmgm9MmXQ5waVqjHMqKEtbE1KMc1L0wJFgXcqdXQ58ZthhHAunTZj9IsAd7N021pVB9EbQ40wL2p2qxHyJKIsXzt7mhqy5hTtTqmOqy52Q8T8-EJ3EctKp4PLRfE

 

 

Lab Recreate:

The idea here is to create a Regex that will match the keyword “tiktok” and “tik-tok” in the URL path and to create a policy that will block downloads from such URL but at the same time it should not block background downloads from any search made on any search engine related to the word “tiktok” and “tik-tok”

Eg : https://tik-tok.en.softonic.com/download : Downloads from this Website should get blocked

 

However, the any downloads from the second URL as shown below that appears when you simply type the keyword “tiktok” or “tik-tok” in the search option of a search engine, should not be blocked : 

mZlemPVdsexLlh_HlJ44UKFCNGSSuKHRCNscgmDtZ-DHz3_sEpyBGS36H127r4Iugt9B91WoFXFmHG2_2madQ3gGP23XFAa6656THfVfS-KOG8RICeUMUza5ZdYRKPD2CbKXVC77r5NgBbS6_mwcsMI

 

To create a Regex and understand the supported syntax, you can leverage this document from Netskope Knowledge base

Below steps can be followed to accomplish this use case : 

  • Create a Regex that will detect the keyword “tiktok” and “tik-tok” in any URL : 
  • Regex 1 : .*tiktok.*

1zW-SVBtysZjjpTS38oeshOeVIS7o65nEvmolDxdjcsqxwbzZtt52YSF4CykkK8_pqOYK8lC2CGf7c-bm_z5Pw2i6pwy9sN4KNEWYi8FGruDoFutu_qf1uJ9SJgaz8eciEETHjWRpd-LegywZQZ9dw4

 

  • Regex 2 : .*tik-tok.*

Iq03I_dv1bQlB5x7-T50PR47A6DkxIb0T-DwYpIJ49jZOdDh7alwt99BtStKm0zH3Rg5cNCrLj0UmeHSRB7u5s8eTdiWCAeTW3sTnQ8VZiAGp1R4EWLfjZEgQ1zehGqskndln5p5GLeDk13mn-nf1AU

 

To validate the regex you can use Regex Tester Tools

  • Create a Regex that will exclude the google searches for the keyword “tiktok” “tik-tok” and else the above regex will also block the URLs that are associated with search of these keywords
  • Regex 1 : .*search.*tiktok.*|^.*tiktok.*search.*
  • Regex 2 : .*search.*tik-tok.*|^.*tik-tok.*search.*

VnmrJgF43u3M5RSeqcTDCeqmD-Aq757ec66GtmkBOQWj3ioJjRVT9o5lVn3w0mld7XRHTtDAyQ6Tg0Aa5MxGhNbqpAnZpRGqEwhgeJS1oZheYTDiLRpCwz9SnSXpZ4Rx9MArHvPTeG4bYh5u_4_Azzc

 

Step 1 : Create a custom URL list under Policies - Web - URL List - New URL List with the first two regexes : 

sONLkVhj1v1BMt22MkeMx0SlqJNb729TO4jKvcmQJoGwUKzScSlcbH9qkf6wSI1gF7Cny4r2llLIIAOp1C2V-JhJJ2OgXRI8-w4EiNaRqegp5zOt-7xYt_19rgwd6aScnEvHjYP6H9PNgbKhaQ76OBg

 

Step 2 :  Create a custom URL list under Policies - Web - URL List - New URL List with the exclusion regexes

B277ZzkpFGQvhR-FOEy_obZtTJva0RKsTWfjHhTZCwxy6QtUKTnCHnmiOrPZGuA20s_dmIC0Zxzl-4uGGjMkOQUeE2Z117ZNkyx-1wfG_-dheDG_nxkzVTab5EMV9N7XTFG_RJokVOU3wgv2p7f-6bA

 

Step 3 : Now create a Custom category with the URL list 1 in Inclusion and the URL list 2 in exclusion

_Jgg3sYrO7fV9mlvNqPih-1o-AeCoZ50C2MpeFIGu9Pf9jkqB5s76w7Sv92aGbgmYCZl1DOwRAAVewdOgyC7Im1rDyJ00Hxkx_Xjh_1n5I0Vw7nA2fA95M_-y8vqKxDfZJzTGyEFttSn3trckOZ6OhI

 

Step 4 : Now go to the Real time protection policy page under Policies - Real Time protection policies - Web and create a Real time protection policy as shown below : 

Always restrict the testing to a subset of users before rolling out in production

AtrV2ohvE3pnlfpg_9lrbesceY-n-O0-qmT5d88Hl12Kc9kUYmY4RbF3eyFVrY85HIDLIP7dKNodd_5q7nD4YvBkU1oCyqqeDyB45DD29T_VBnYYz0_0l2LBze1pVeERyaa-DWioQVDX1Nv4E1wM3Iw

 

 

Terms and Conditions

  • All documented information undergoes testing and verification to ensure accuracy.
  • In the future, If any such platform changes are brought to our attention, we will promptly update the documentation to reflect them.

 

Notes

  • This article is authored by Netskope Global Technical Success (GTS).
  • For any further inquiries related to this article, please contact Netskope GTS by submitting a support case with 'Case Type – How To Questions'.
Be the first to reply!