Kaspersky Anti Targeted Attack Platform

Network sessions table

To view the list of network sessions:

  1. Select the Network map section in the application web interface window.
  2. Go to the Network sessions tab.

The network sessions table is displayed.

The table contains the following information:

  • Status is the status of the network session. A registered network session can have one of the following statuses:
    • Active. This status is assigned when a network session is registered and is retained as long as the devices keep sending network packets within this session.
    • Closed. This status is assigned to a network session if no network packets have been sent for one minute or if the Network Session Detection technology becomes disabled on the relevant node or monitoring point.
  • Side 1 is the MAC and/or IP addresses of one of the sides of the network interaction. The display of MAC and IP addresses can be turned on and off.
  • Side 1 port is the port number of the first side of the interaction.
  • Side 2 is the MAC and/or IP addresses of the other side of the network interaction. The display of MAC and IP addresses can be turned on and off.
  • Side 2 port is the port number of the second side of the interaction.
  • Device 1 is the name of the device known to the application, which corresponds to the address information of the first side of the interaction.
  • Device 2 is the name of the device known to the application, which corresponds to the address information of the second side of the interaction.
  • Transfer protocol is the name of the transport protocol used in the network session.
  • Application protocol is the name of the application layer protocol used in the network session.
  • Current speed is the current data transfer rate for the network session.
  • Average speed is the average data transfer rate for the network session.
  • Total transmitted is the number of bytes transmitted during the network session.
  • Monitoring points lists the names of monitoring points that have received traffic for the network session.
  • Start is the date and time of the first network packet in the network session or the date and time of the beginning of the time period defined by data from an EPP application.
  • Last interaction is the date and time of the last network packet in the network session or the date and time of the end of the time period defined by data from an EPP application (if only one packet was received in the network session, this value is the same as the Start).
  • Number of packets is the number of network packets transmitted during the network session.

When viewing the table of network sessions, you can configure, filter, and sort the network sessions, as well as navigate to related items and export data.