Kaspersky Anti Targeted Attack Platform

Enabling or disabling technologies

You can enable or disable technologies for Central Node and Sensor components and monitoring points. However, enabling and disabling technologies for Sensor components and monitoring points is available if technology inheritance is disabled on these objects.

Some technologies include methods that can be enabled or disabled individually. If a technology or method is disabled, the application does not monitor device interactions using the technology or method. However, you can still manage application settings related to disabled technologies or methods (for example, add or edit rules).

The following technologies and methods support enabling and disabling:

  • Asset Management, hereinafter also "AM":
    • Device Activity Detection.
    • Device Information Detection.
    • Network Session Detection.
  • Intrusion Detection, hereinafter also "IDS":
    • Rule-based Intrusion Detection.
    • ARP Spoofing Detection.
    • IP Protocol Anomaly Detection.
    • TCP Protocol Anomaly Detection.
    • Brute-force Attack and Scan Detection.

To change the state of technologies and methods:

  1. Select the Sensor servers section in the window of the application web interface.
  2. Click the card of the relevant component or monitoring point.

    This opens a window with information about the component or monitoring point.

  3. If you want to change the state of technologies and methods for a Sensor component or a monitoring point, set the Inherit Server technologies toggle switch to Disabled.
  4. Use the toggle switches in the left part of the window to enable or disable technologies and/or methods. You can enable or disable all technologies and methods simultaneously by clicking Enable all or Disable all.
  5. After enabling or disabling a technology or method, wait until the changes are applied. The switch does not become available again until the transition to the other state is completed.

The state of technology and methods is changed.

See also

Configuring Device Activity Detection mode