Kaspersky Anti Targeted Attack Platform

About address space subnets

The subnets of address spaces are displayed in the Subnets blocks within address space descriptions.

The application matches the discovered IP addresses against the lists of subnets of address spaces and, depending on whether the IP addresses are found to belong to certain types of subnets, can perform the following actions:

  • Add a device with the discovered IP address to the table of devices and monitor the activity of this device.
  • Display a device with its detected IP address on the network interactions map and the topology map as its corresponding type of node (known device, unknown device, or WAN node).
  • Display the connection on a network interactions map, in which one of the interaction parties is the device with the discovered IP address.
  • Scan the interactions of the device with the discovered IP address according to the configured rules (Interaction Control rules, Intrusion Detection rules, and correlation rules).
  • Ignore the activity of the device with the discovered IP address.

Subnet settings of the address space are displayed in the following columns of the table:

  • Subnet.

    Subnet address in Classless Inter-Domain Routing (CIDR) format: <base address of the subnet>/<number of bits in the mask>. Subnet addresses are displayed as a tree that represents the subnet nesting hierarchy.

  • Type.

    Type of the subnet that stipulates its purpose. The following types are possible:

    • Private, IT – subnet for devices that serve as information technology (IT) resources, such as file servers.
    • Private, DMZ – subnet for devices that reside within a network segment of a demilitarized zone (DMZ), such as servers that handle requests from external networks.
    • Public – subnet that is considered to be an external (global) network for devices in other types of subnets. IP addresses from this subnet are represented on the network interactions map by the WAN node.
    • Link-local – subnet for network interactions within one segment of the local area network (not routed).
  • Range

    The range of IP addresses included in the subnet.

  • Automatically add subnets

    Indicates whether the automatic adding of nested subnets based on information received from EPP applications is enabled or disabled. If this mode is enabled, the application adds nested subnets based on information received from EPP applications.

When viewing the table of subnets, you can use the configuration functionality (by clicking the Gear icon. icon) as well as the filtering, search, and sorting functionality.