Kaspersky Anti Targeted Attack Platform

Monitoring network traffic events

The application registers events when analyzing network traffic. Network traffic analysis is part of the NDR functionality.

A network traffic event (also referred to as an NDR event) is a record containing information about the detection of certain changes or conditions in network traffic that require the attention of an information security professional. NDR events are registered and sent to the Central Node. The server processes the received events and stores them in the database.

An aggregate event is a special type of event that is registered when a specific sequence of NDR events is received. Aggregate events group NDR events that have some common characteristics or are related to the same process.

The application registers aggregate events in accordance with event correlation rules. An event correlation rule describes the conditions for scanning sequences of events. When a sequence of NDR events is detected that matches the conditions of the rule, the application registers an aggregate event that mentions the name of the triggered rule. Aggregate events are registered with system event type code 8000000001.

Event correlation rules are built into the application and are applied independently of the security policy.

After the application is installed, the original event correlation rules are used. To improve the effectiveness of the rules, Kaspersky regularly updates the databases with rule sets. You can update correlation rules by installing updates.

The Kaspersky Anti Targeted Attack Platform server registers NDR events in accordance with the settings specified for registering event types. You can configure these settings in the Configure event types section.

To reduce the number of frequently repeated NDR events that do not require user attention, you can create allow rules for events. NDR events that match allow rules are not registered. For example, you can use an allow rule to temporarily disable the registration of all events from a specific monitoring point. You can view allow rules for events in the Settings section, Allow rules subsection. The EVT type is specified for such rules.

The application stores NDR events and aggregate events in a database on the Central Node. The total amount of stored records cannot exceed the configured limit. If the amount exceeds the limit, the application automatically deletes the oldest records. However, if a minimum storage duration is configured, the corresponding message is logged in the application message log when deleting records whose age is less than the minimum duration. You can configure the event and incident storage settings.

You can view information about NDR events and aggregate events in the Network traffic events section. This section displays detailed information about NDR events and aggregate events and allows loading information for any period from the server database.

Actions with network traffic events are available to users with the Security officer or Senior security officer role. Users with the Security auditor role can view events.

NDR events are generated if a valid KATA+NDR license key is present. After the license key expires, created events remain available for viewing, but related alerts are not created.

In this section

NDR event scores and severity levels

NDR event registration technologies

NDR event statuses

Table of registered NDR events

Configuring the table of registered events

Viewing events nested inside an aggregate event

Viewing details of an NDR event

Changing the status of an NDR event

Adding markers

Copying NDR events to a text editor

Downloading traffic for events

Creating a directory for exporting events to a network share