Introduction
Menlo Security File Protection for Amazon S3 provides advanced Content Disarm and Reconstruction (CDR) and Data Detection and Response (DDR) capabilities to keep every file in your S3 environment safe and compliant. Each file uploaded to your S3 bucket is automatically analyzed to remove malware, malicious code, and active content.
Sensitive data such as PII, PCI, and PHI is detected and masked according to the security policies of your organization. Deployment is fully automated through AWS Quick Launch, with no manual setup or maintenance required. All actions are tracked and visible in the Menlo Security Management Console for monitoring and compliance.
Purchase Options
Menlo offers a 14 day free trail and then there is the basic subscription model:
| Dimension | Description | Cost/month |
| Base Subscription | Flat subscription covering up to 25 GB of data sanitization and 10,000 files processed per month. This charge represents the core service access and base capacity included in the plan. | $500 |
Additional Usage Costs
| Dimension | Description | Cost/unit |
| Additional Volume Consumption (GB) | Additional file sanitization - per 25GB | $100 |
| Additional File Processed | Additional file sanitization - per 10,000 files | $100 |
Costing Example:
If you use 75GB in a month you will pay $700, this is an automatic payment ($200 overage).
File count calculation: An archive file with 10 compressed documents inside will be counted as 10 files, a single .docx with embedded images will be counted as 1 file.
Pre-Requisites
You will require access to the AWS Console, with privileges to access S3, IAM and Cloud Formation.
Configuration
From your AWS account, search Marketplace for Menlo File Security.
- Click on Menlo File Security.
- Click on View Purchase Options or Try for Free.
- Once the plan has been selected, click subscribe.
- Click on Set up your account.
The configure and quick launch dialogue will appear. There are 4 steps for the quick launch process:
- Step 1: Make sure you have the required AWS permissions
- Step 2: Sign In and Create a vendor account
- Step 3: Configure your software and AWS integration
- Step 4: Launch your software
Step 1: Make sure you have the required AWS permissions
This step requires permissions to be added to a role.
- From the install template click on required permissions.
- Copy the permissions.
- In the AWS console navigate to IAM.
- Click on Roles. Edit a role to include the additional permissions - this role must have the trusted entity AWS Service: cloudformation.
- Click Add permissions.
- Select Create inline policy.
- Select the JSON tab.
- Remove the default content and paste the permissions into the editor.
- Click Next.
- Provide a name for the policy.
- Click Create Policy.
Step 2: Sign in and create a vendor account
This step will create the Menlo CDR tenant, when complete you will be presented with an email address, a username and an initial password.
- Click on the Go to Votiro button.
- When prompted enter the email address and click Sign In.
- Enter the Username and Password and click Sign In again.
- You will then be prompted to change your password. When complete click Send.
You are now in the Votiro CDR Management Console. For further information refer to the following documentation:
https://csportal.menlosecurity.com/hc/en-us/sections/38776922116621-Votiro-Management-Console
The default policy will be enforced on files.
Currently you are given full access to the environment, if you use any of the other integrations/connectors/channels you are liable for further billing.
Step 3: Configure your software and AWS integration
This step will allow you to automatically launch and configure resources and dependencies.
- Navigate back to the AWS Quick Launch configuration.
- Click Launch template. This will launch the S3 CloudFormation console.
- Select the region from the drop down (not all regions are available).
- Click Launch template, this will display the Create Quick Stack screen.
- Enter a Stack name (or you can use the default).
- Enter the S3 bucket ARN. This is obtained from the Amazon S3 | Buckets | Properties | Bucket Overview.
Menlo CDR does support multiple buckets but the quick launch only supports 1 bucket. If you want to add additional buckets this is done in the Votiro CDR management console. Select Cloud Connectors | AWS S3 and Click Add. You can also assign a different policy to the additional buckets.
- Optionally tag the resources that are being created. Enter Key: DemoTag and Value: MenloCDR.
- Enter the permissions - this will be the role you created earlier. The role will appear in the drop down menu.
- Scroll down to Capabilities and click I Acknowledge that the AWS CloudFormation might create IAM resources with custom names.
- Click Create Stack.
This will create a session of 21 events. Once complete, access will be given to the connector which will enable Menlo CDR Sanitization to the files uploaded into the S3 bucket.
Step 4: Launch your software
Clicking Launch your software will navigate you back to the Votiro CDR management console, where you can make changes to your policy.
The AWS Quick Launch is now complete.
Test the Integration
Validate the configuration by uploading some files to your s3 bucket.
- Navigate to your S3 bucket.
- Click objects.
- Click upload.
- Select different file types, click upload.
- Navigate to the Menlo CDR management console, click Events. All the files uploaded will be displayed with the associated actions. Further details can be viewed by clicking on View Full Details.
Further details on the Votiro Management Dashboard can be reviewed in the Knowledge base Articles in the folder Votiro Management Console.
- Navigate back to the Objects folder in AWS, if any files were blocked you will see the file name with an appended name of _blocked.pdf.
- This file can be viewed by clicking on Open.
Troubleshooting
If you do not have the necessary privileges for the AWS Marketplace deployment, you may see the following alert in Step 1. Click Enable integration to create the service-linked role.
For further information please review the following AWS documentation:
https://docs.aws.amazon.com/marketplace/latest/buyerguide/buyer-creating-service-linked-role.html
Comments
0 comments
Please sign in to leave a comment.