Kaspersky Anti Targeted Attack Platform

Working with the network interactions map

The network interactions map is a visual display of discovered interactions between devices. You can use the network interactions map to view information about device interactions at various time periods.

To view the network interactions map:

  1. Select the Network map section in the application web interface window.
  2. Go to the Network interactions map tab.

The network interactions map is displayed.

The following objects can be displayed:

  • Nodes. These objects represent the senders and recipients of network packets.
  • Device groups. These objects correspond to groups in the device group tree. Groups contain nodes representing devices included in these groups as well as child groups.
  • Links. These objects represent interactions between nodes.

Nodes and links appear on the network interactions map based on the data obtained from traffic or from Endpoint Agent over a certain period of time. Device groups are displayed continuously.

You can filter nodes and links. By default, the network interactions map displays objects in real time with a defined filtering period of one hour.

Objects with issues are highlighted on the network interactions map. The application considers the following objects to have issues:

  • A node if it has unprocessed events with a score of 4.0 or higher, or if it represents a device with the Unauthorized status.
  • A link if it has to do with events with a score of 4.0 or higher. Only events registered during the given object filtering period are taken into account. The current status of events is not taken into account.
  • A group, if it contains devices with issues, or if nodes in this group have links with issues. Objects taken into account can belong to the group itself or to any of its child groups at any nesting level.

In this section:

Nodes on the network interactions map

Device groups on the network interactions map

Links on the network interactions map

Viewing object details

Zooming the network interactions map

Positioning the network map

Pinning and unpinning nodes and groups

Manually rearranging nodes and groups

Automatically arranging nodes and groups

Searching for nodes on the network interactions map

Filtering objects on the network interactions map

Saving and loading the display settings of the network interactions map