Kaspersky Anti Targeted Attack Platform

Downloading network session traffic

When viewing the table of network sessions, you can download traffic related to the selected network sessions. Traffic is downloaded as a PCAP file. To download only the data you need, you can configure network packet filtering.

The application downloads traffic of network sessions from traffic dump file storages. Traffic can be downloaded from the internal storage that was automatically created as part of the Sensor installation process, as well as an external storage if one is connected.

When downloading network session traffic, consider the following:

  • Traffic can be downloaded only for those network sessions that were registered when analyzing traffic that arrived at the monitoring points. If a network session was registered based on information received from the Endpoint Agent component, you cannot download the traffic of such a session.
  • Traffic dump files are stored in storages temporarily and are automatically deleted as new traffic arrives (the rotation period depends on the amount of traffic and the application storage configuration). You cannot downloading traffic for a network session if the corresponding traffic dump files have already been deleted from storages.

To download network session traffic:

  1. Select the Network map section in the application web interface window.
  2. Go to the Network sessions tab.
  3. Select check boxes next to network sessions whose traffic you want to download.

    You can select a maximum of 100 network sessions.

  4. Click Download traffic.

    The details area is displayed in the right part of the web interface window.

  5. Do the following:
    • If you want to download traffic for a certain period of time, set the bounds using the Period of traffic to download setting.

      By default, the maximum possible period is chosen, starting from the date and time when the earliest network session was established and ending with the date and time when the latest session in the selection ended. If necessary, you can move the bounds within this period or set an empty value for one of the bounds (for example, for the right bound to download new traffic of sessions that have not ended yet).

    • Under Download volume limit, set the maximum amount of traffic to download.

      If the amount of downloaded traffic exceeds the specified limit, the newest traffic is dropped.

    • If necessary, enable filtering under Filtering by monitoring points and specify the monitoring points that got the traffic that you need.

      By default, the monitoring points that got the traffic of selected network sessions are specified.

    • If necessary, enable filtering in the Filtering by address spaces section and specify the address spaces to which the addresses in the network packets of the selected network sessions belong (this section is displayed if additional address spaces are added to the application).

      By default, all address spaces created in the application are specified.

    • If necessary, enable filtering under Filtering using BPF and enter an expression for filtering using the BPF (Berkley Packet Filter) technology by address parameters in network packets of the selected network sessions.

      Example of a filter expression:
      tcp port 102 or tcp port 502

    • If necessary, enable filtering under Filtering using regular expressions and enter a regular expression for filtering by the payload data of network packets of the selected network sessions.

      Example of a filtering expression:
      ^test.+xABxCD

  6. Click Download.
  7. If file generation takes a long time (more than 15 seconds), the file generation operation becomes a background operation. In that case, follow these steps to download the file:
    1. Click the Arrow pointing to a tray icon. button in the application web interface menu.

      This opens the list of background operations.

    2. Wait for the file generation operation to complete.
    3. Click the Download file button.

Your browser saves the downloaded file. Depending on your browser's settings, a window may be displayed on your screen in which you can specify the path and name of the downloaded file.