FortiSandbox, ML Detection & Zero Trust Concepts

FortiGate — FCP track EVE-NG — FortiGate VM (GUI + CLI)

مقصدObjectiveObjective

اس نظریاتی لیسن میں آپ سیکھیں گے کہ FortiSandbox اور ML بیسڈ ڈیٹیکشن زیرو ڈے تھریٹس کیسے روکتی ہے، اور زیرو ٹرسٹ، ZTNA اور SASE کانسیپٹس جدید FortiGate ڈیپلائمنٹس میں کیسے لاگو ہوتے ہیں۔Is nazaryati lesson mein aap seekhenge ke FortiSandbox aur ML-based detection zero-day threats kaise rokti hai, aur Zero Trust, ZTNA aur SASE concepts jadeed FortiGate deployments mein kaise lago hote hain.In this theory lesson you will learn how FortiSandbox and ML-based detection stop zero-day threats, and how Zero Trust, ZTNA, and SASE concepts apply to modern FortiGate deployments.

آسان مثالSimple AnalogySimple Analogy

FortiSandbox ایسے ہے جیسے مشکوک پارسلز کے لیے قرنطینہ روم: نامعلوم پارسل کو دفتر میں لانے کے بجائے سیل کمرے میں کھول کر دیکھتے ہیں کہ اندر کیا ہوتا ہے۔FortiSandbox aise hai jaise mashkook parcelon ke liye quarantine room: namaloom parcel ko daftar mein lane ke bajaye seal kamre mein khol kar dekhte hain ke andar kya hota hai.FortiSandbox is like a quarantine room for suspicious packages: instead of letting an unknown parcel into the office, you open it in a sealed room and watch what happens.

سیٹ اپLab SetupLab Setup

نظریاتی لیسن — EVE-NG ڈیوائسز کی ضرورت نہیں۔ کانسیپٹس ان FortiSandbox، FortiSASE اور ZTNA فیچرز سے جڑتے ہیں جو آپ اصلی FortiGates پر دیکھیں گے۔Nazaryati lesson — EVE-NG devices ki zaroorat nahi. Concepts un FortiSandbox, FortiSASE aur ZTNA features se jurte hain jo aap asli FortiGates par dekhenge.Theory lesson — no EVE-NG devices needed. Concepts map to the FortiSandbox, FortiSASE, and ZTNA features you will see on real FortiGates.

اقداماتStepsSteps

Step 1

سینڈ باکسنگ سمجھیں۔ جب FortiGate کوئی مشکوک فائل دیکھتا ہے جسے پہچان نہیں سکتا، تو اسے FortiSandbox بھیجتا ہے — ایک الگ اپلائنس، VM یا کلاؤڈ سروس جو فائل کو الگ ورچوئل مشین میں چلا کر دیکھتا ہے کہ یہ کیا کرتی ہے۔Sandboxing samjhen. Jab FortiGate koi mashkook file dekhta hai jise pehchan nahi sakta, to use FortiSandbox bhejta hai — aik alag appliance, VM ya cloud service jo file ko alag virtual machine mein chala kar dekhta hai ke yeh kya karti hai.Understand sandboxing. When FortiGate sees a suspicious file it cannot identify, it sends it to FortiSandbox — a separate appliance, VM, or cloud service that runs the file in an isolated virtual machine and watches what it does.

Step 2

ML بیسڈ زیرو ڈے ڈیٹیکشن سیکھیں۔ FortiGuard Labs لاکھوں مال ویئر سیمپلز پر مشین لرننگ ماڈلز ٹرین کرتا ہے۔ یہ ماڈلز فائل کے رویے اور اسٹرکچر کو جج کرتے ہیں — نیا (زیرو ڈے) مال ویئر پکڑتے ہیں جس کی ابھی کوئی سگنیچر نہیں۔ML-based zero-day detection seekhen. FortiGuard Labs lakhoN malware samples par machine learning models train karta hai. Yeh models file ke rawaiye aur structure ko judge karte hain — naya (zero-day) malware pakarte hain jis ki abhi koi signature nahi.Learn ML-based zero-day detection. FortiGuard Labs trains machine learning models on millions of malware samples. These models judge a file's behavior and structure — catching brand-new (zero-day) malware that has no signature yet.

Step 3

سینڈ باکس ورک فلو سمجھیں: مشکوک فائل سبمٹ، چلائی اور آبزرو کی گئی، ورڈکٹ ملا (malicious، suspicious یا clean)۔ Malicious ورڈکٹ ایک IOC بن جاتا ہے جو پوری سیکیورٹی فیبرک میں شیئر ہوتا ہے تاکہ ہر ڈیوائس اسے بلاک کرے۔Sandbox workflow samjhen: mashkook file submit, chalai aur observe ki gayi, verdict mila (malicious, suspicious ya clean). Malicious verdict aik IOC ban jata hai jo poori Security Fabric mein share hota hai taake har device ise block kare.Follow the sandbox workflow: suspicious file submitted, detonated and observed, verdict assigned (malicious, suspicious, or clean). A malicious verdict becomes an IOC shared across the whole Security Fabric so every device blocks it.

Step 4

زیرو ٹرسٹ سمجھیں: کبھی بھروسا نہیں، ہمیشہ ویریفائی۔ ہر یوزر اور ڈیوائس کو رسائی سے پہلے آئیڈینٹیٹی اور ہیلتھ پر ویریفائی کیا جاتا ہے، نیٹ ورکس مائیکرو سیگمنٹڈ ہوتے ہیں، اور رسائی per-application ہوتی ہے — per-network نہیں۔Zero Trust samjhen: kabhi bharosa nahi, hamesha verify. Har user aur device ko rasai se pehle identity aur health par verify kiya jata hai, networks micro-segmented hote hain, aur rasai per-application hoti hai — per-network nahi.Grasp Zero Trust: never trust, always verify. Every user and device is verified by identity and health before getting access, networks are micro-segmented, and access is per-application — not per-network.

Step 5

ZTNA اور SASE سیکھیں۔ ZTNA VPN کی وسیع رسائی کو آئیڈینٹیٹی اور ڈیوائس چیکس کے بعد per-application رسائی سے بدل دیتا ہے۔ SASE نیٹ ورکنگ اور سیکیورٹی (SWG، CASB، ZTNA، فائر وال) کو کلاؤڈ ڈیلیورڈ سروس میں جوڑ دیتا ہے — FortiSASE فورٹی نیٹ کی آفرنگ ہے۔ZTNA aur SASE seekhen. ZTNA VPN ki wasee rasai ko identity aur device checks ke baad per-application rasai se badal deta hai. SASE networking aur security (SWG, CASB, ZTNA, firewall) ko cloud-delivered service mein jor deta hai — FortiSASE Fortinet ki offering hai.Learn ZTNA and SASE. ZTNA replaces broad VPN access with per-application access after identity and device checks. SASE converges networking and security (SWG, CASB, ZTNA, firewall) into a cloud-delivered service — FortiSASE is Fortinet's offering.

تصدیقVerifyVerify

آپ اپنے الفاظ میں (تینوں زبانوں میں سے کسی میں) وضاحت کر سکیں: FortiSandbox کیا کرتا ہے، ML زیرو ڈے مال ویئر کیسے پکڑتا ہے، ZTNA اور VPN میں فرق، اور SASE کیا جوڑتا ہے۔Aap apne alfaz mein (teenon zubanon mein se kisi mein) wazahat kar saken: FortiSandbox kya karta hai, ML zero-day malware kaise pakarta hai, ZTNA aur VPN mein farq, aur SASE kya jorta hai.You can explain: what FortiSandbox does, how ML catches zero-day malware, the difference between ZTNA and VPN, and what SASE converges — in your own words in any of the three languages.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ FortiSandbox وہ مال ویئر کیسے پکڑتا ہے جس کی کوئی سگنیچر نہیں ہوتی؟FortiSandbox woh malware kaise pakarta hai jis ki koi signature nahi hoti?How does FortiSandbox catch malware that has no known signature?

FortiSandbox مشکوک فائلز کو الگ ورچوئل ماحول میں چلا کر ان کا رویہ دیکھتا ہے — زیرو ڈے مال ویئر کی کوئی سگنیچر نہیں ہوتی، تو رویہ ہی اسے پکڑنے کا واحد طریقہ ہے۔ پھر ورڈکٹ سب فیبرک ڈیوائسز سے شیئر ہوتا ہے۔FortiSandbox mashkook files ko alag virtual mahol mein chala kar un ka rawaiya dekhta hai — zero-day malware ki koi signature nahi hoti, to rawaiya hi ise pakarne ka wahid tareeqa hai. Phir verdict sab Fabric devices se share hota hai.FortiSandbox detonates suspicious files in an isolated virtual environment and watches their behavior — zero-day malware has no signature, so behavior is the only way to catch it. The verdict is then shared with all Fabric devices.

❓ ZTNA روایتی VPN سے کس طرح مختلف ہے؟ZTNA riwayati VPN se kis tarah mukhtalif hai?How is ZTNA different from a traditional VPN?

ZTNA ہر یوزر کو صرف انہی ایپلی کیشنز تک رسائی دیتا ہے جن کی اسے ضرورت ہے، آئیڈینٹیٹی اور ڈیوائس ہیلتھ چیک کرنے کے بعد — VPN جیسی پوری نیٹ ورک رسائی نہیں۔ یہی زیرو ٹرسٹ کا خیال ہے: کبھی بھروسا نہیں، ہمیشہ ویریفائی، ہر ایپلی کیشن کے لیے۔ZTNA har user ko sirf unhi applications tak rasai deta hai jin ki use zaroorat hai, identity aur device health check karne ke baad — VPN jaisi poori network rasai nahi. Yahi Zero Trust ka khayal hai: kabhi bharosa nahi, hamesha verify, har application ke liye.ZTNA gives each user access only to the specific applications they need, after checking identity and device health — no full network access like a VPN gives. This is the Zero Trust idea: never trust, always verify, per application.