Kaspersky Anti Targeted Attack Platform

Monitoring network sessions

Kaspersky Anti Targeted Attack Platform can scan traffic to detect network sessions that devices create to connect to other devices. The application registers detected network sessions and saves information that can help you analyze network activity of devices and download data about transmitted network packets from traffic dump files. Unlike links on the network interactions map, registered network sessions allow you to obtain more fine-grained information about device interactions, due in part to independent registration of sessions for different ports and protocols that are used for the interactions.

The application detects network sessions if the Network Session Detection method is enabled for the Asset Management technology. Network Session Detection can be performed when analyzing traffic arriving at monitoring points, as well as when receiving information from the Endpoint Agent component.

Each registered network session contains information about the connection between two devices that are parties to the interaction. A network session is characterized by the address information of the parties to the interaction (MAC and/or IP addresses), port numbers, and the application protocol that is used for the connection. The first device in a network session is usually the device that initiated the sending of network packets to the other device.

You can view the full list of protocols detected by Kaspersky Anti Targeted Attack Platform by downloading the file from the link below.

icon_download_file_from_help Protocols detected by Kaspersky Anti Targeted Attack Platform

A network session is considered closed if no network packets have been sent for one minute or if the Network Session Detection technology becomes disabled on the relevant node or monitoring point.

When an exceedingly large number of network sessions is detected, the application applies the following session registration restrictions:

  • The number of registered sessions between two interacting parties using the same application protocol may not exceed 1000 per minute.
  • The total number of registered sessions between the two parties may not exceed 5000 per minute.

The application stores information about network sessions in a database on the Central Node server. The total amount of stored records cannot exceed the configured limit. If the amount exceeds the limit, the application automatically deletes 10% of the oldest records.

In distributed solution

mode, information about network sessions of SCN servers is not displayed on the PCN.

In this section

Network sessions table

Viewing network session details

Downloading network session traffic

Searching network packets

Preconfigured network packet search rules