Kaspersky Anti Targeted Attack Platform

Connecting the Sensor component to the Central Node

When the Sensor component is added, a configuration package is generated on the Central Node, containing the certificate and configuration data for the Sensor component. The added component is connected using the web interface of the Sensor component. The web interface of the component lets you upload a configuration package and connect the component in the following ways:

  • Using a communication data package.

    In this case, the configuration package is saved as a file in which the certificate is password-protected. This file is called a communication data package. The communication data package must be uploaded to the web interface of the Sensor component. After uploading the communication data package, the Sensor component automatically connects to the Central Node on which the communication data package was created.

  • Automatically over the network.

    In this case, the configuration package is sent over the network to the specified IP address of the server with the Sensor component. The Sensor processes the configuration package, generates a certificate signing request (CSR) based on it, and sends this request to the Central Node component. After receiving the CSR, the fingerprint of the CSR is displayed in the web interface of Kaspersky Anti Targeted Attack Platform as a sequence of characters. The same fingerprint is displayed at the same time in the web interface of the Sensor component. You must make sure that the fingerprints are identical before terminating the connection.

If the connection between the Central Node and Sensor components is established outside of a trusted medium, to protect the connection from traffic interception, you need to use external cryptographic information protection facilities that support encryption algorithms approved in your country. If the components are connected by a trusted medium, for example, a patch cord within a server rack that precludes third-party access, using external cryptographic information protection facilities is not necessary.

In this section

Connecting the Sensor component using a communication data package

Adding and connecting the Sensor component automatically over the network