Kaspersky Anti Targeted Attack Platform

Links on the network interactions map

Links on the network interactions map are discovered by analyzing network packets in which addresses of senders and recipients can be matched with addresses of nodes.

Each links represents two sides of an interaction. One of the following objects on the network interactions map can be a party of an interaction:

  • Node of one of the following types:
    • A device known to the application.
    • A device unknown to the application.
    • The common node of unknown devices (if the link shows interaction with one or more unknown devices inside this node).
  • A collapsed group if the link shows interaction with one or more devices in this group.

Depending on the scores of events registered while detecting interactions, the link can be displayed a colored line:

  • Gray for an interaction that caused no events to be registered or only events with scores of 0.0–3.9.
  • Red for an interaction has caused events to be registered with a score of 4.0–10.0.

Only events registered during the given object filtering period are taken into account for links. The current status of the events is not taken into account.

The application stores link information in a database at . The total amount of stored records cannot exceed the configured limit. If the amount exceeds the limit, the application automatically deletes 10% of the oldest records. You can set the maximum network interactions map size when configuring the storage settings.