Kaspersky Anti Targeted Attack Platform

Loading and replacing user-defined sets of Intrusion Detection rules

You can upload Intrusion Detection rule sets from files into the application. To be uploaded to the application, files with Intrusion Detection rule descriptions must be located in the same folder and have the .rules extension. File names may not contain the following characters: \ / : * ? , " < > |

Intrusion Detection rules uploaded from a file are saved in the application as a user-defined rule set. The name of the rule set is the same as the name of the file from which the rule set was uploaded.

When rule sets are uploaded from files, current user-defined rule sets are deleted from the table and replaced with new rule sets.

Only users with the Senior security officer role can upload user-defined Intrusion Detection rule sets.

To upload and replace user-defined Intrusion Detection rule sets:

  1. In the window of the application web interface, select the Custom rules section, Intrusion detection subsection.
  2. In the toolbar, click the Replace all user-defined rules button.
  3. In the confirmation window, click OK.

    This opens the file upload window.

  4. Select the folder that contains the files that you need and click the button to upload files from this folder.

    The rule set table displays new user-defined rule sets. All rule sets without errors are enabled.

  5. Check the uploaded rule sets for errors.

    Information about the detected errors is displayed in the Rules column. The OK status is displayed if there are no errors. If the rule set contains errors, you can view detailed information about them by clicking Details.

  6. If necessary, enable or disable the rule sets (including the rule sets that have the Errors in some rules status).

User-defined Intrusion Detection rule sets are uploaded.