Kaspersky Anti Targeted Attack Platform

About address space rules

The rules of address spaces are displayed in the Rules blocks within address space descriptions. Information about rules is displayed in the title bar of the address space and in the table of rules.

Address space rule settings are displayed in the following columns of the table:

  • Source.

    The type of the source of data about address information and the list of selected data sources. The following data source types are possible:

    • Monitoring points – monitoring points selected for the rule.
    • Integration servers – integration servers selected for the rule (the data on address information received from the selected integration servers will satisfy the address space rule).
    • Active polling modules – active polling module connectors selected for the rule (the data on address information received from the selected active polling modules will satisfy the address space rule).

    The data sources must be specified in the address space rules after adding the objects to be used as sources to the application. For example, connectors for the Active poll modules data source must be specified after adding connectors of the Active poll type.

  • OSI model layers

    Selected layers of the OSI (Open Systems Interconnection) network protocol stack for the address space rule. You can configure the rule for addresses of the following layers of the OSI model:

    • Data Link (L2) – MAC addresses.
    • Network (L3) – IP addresses.
    • Data Link and Network (L2 and L3) – MAC addresses and IP addresses.
  • VLAN ID.

    VLAN IDs used for the VLAN technology in accordance with the IEEE 802.1q standard. When used for an address space rule, the VLAN ID may take the following values:

    • Any – VLAN technology is used for network interactions between devices, and any VLAN IDs can be used.
    • Unallowed – VLAN technology is not used for network interactions between devices.
    • Any or not used – VLAN technology is either not used for network interactions between devices, or it is used with any VLAN IDs.
    • Fixed values with a list of VLAN IDs – VLAN technology is used for network interactions between devices, and an address space can include only address information that has one of the listed VLAN IDs.
  • IP addresses

    IP addresses included in the address space. You can specify addresses individually, as ranges, or as a CIDR subnet address.

When viewing the rule table, you can use the configuration functionality (by clicking the Gear icon. icon) as well as the search functionality.