Kaspersky Anti Targeted Attack Platform

Nodes on the network interactions map

Nodes on the network interactions map can have the following types:

  • A device known to the application. A node of this type represents a device that is listed in table of devices.
  • A device unknown to the application. A node of this type represents a device with a unique IP or MAC address that is not listed in the device table. Such a node may appear on the network interactions map, for example, if you use the ping command to send network packets to a non-existent device. Nodes of devices that the application does not recognize are displayed individually if their total number (in accordance with the current filtering settings on the network interactions map) does not exceed 100. If more such devices exist, unknown devices are jointly represented by a single node.

Information displayed on nodes that represent devices known to the application

For nodes that represent devices known to the application, the following information is displayed on the network interactions map at maximum zoom:

  • The specified device name.
  • The icon of the device category.
  • The IP address of the device (if it has no IP address, the MAC address is displayed).
  • Various icons depending on the following conditions:
    • Whether the Router attribute is set for the device
    • Whether the Endpoint Agent is installed on the device (the color of the icon depends on its connection status)
    • Whether the device has the Archived status
  • A thick line on the left border of the node in one of the following colors, depending on the security state of the device:
    • Green for the OK security state
    • Yellow for the Warning security state
    • Red for the Critical security state

If the device has the Unauthorized status or the security state of the device is not OK, the node has a red background.

Information displayed on nodes that represent devices unknown to the application

For nodes that represent devices unknown to the application, the following information is displayed on the network interactions map at maximum zoom:

  • If the node represents a single unknown device, the IP or MAC address of the device is displayed. If the node represents multiple unknown devices (a node that includes more than 100 devices unknown to the application), Unknown devices is displayed.
  • Icon for an unknown device and its status Icon in the form of a computer with a question mark..

Nodes representing devices unknown to the application have a gray background.