Kaspersky Anti Targeted Attack Platform

Automatically assigning device status

When monitoring device activity, the application can automatically assign a status to discovered devices based on the obtained MAC and/or IP addresses of such devices. Status is assigned depending on the current asset management mode.

In learning mode, the application assigns the Authorized status to all devices (both new and previously added to the table), except for those devices that have had the Unauthorized status assigned previously.

In monitoring mode, the assigned status depends on whether the device that has exhibited activity is a device that the application knows or does not recognize. In this mode, status is assigned according to the following rules:

  • If the device is new (it was absent from the device table at the time of discovery), this device is assigned the Unauthorized status.
  • If the device is present in the table of devices with the Authorized or Unauthorized status, its status does not change.
  • If a device is present in the table of devices with the Archived status, the device is assigned the Unauthorized status.

By default, if a device with the Authorized status has been inactive for more than 30 days and device information has not changed during this period, such a device is automatically assigned the Archived status. You can disable the automatic assignment of the Archived status when you change the device status manually (for example, to prevent the Authorized status from changing to Unauthorized for a device that rarely connects to the network).

When using connectors of the Cisco Switch type, network access of devices may be automatically restricted after these devices get the Unauthorized status. You need to take into account the specified settings of connectors of this type to prevent blocking necessary devices because of a status change.

Page top
[Topic 175710]