Configuring a network interface to be used by virtual machines for Internet access (the detonation interface)

August 12, 2022

ID 188104

Objects processed by Kaspersky Sandbox may attempt activities on the Internet via the network interface used by virtual machines for Internet access. Kaspersky Sandbox can analyze the behavior of these objects.

If you prohibit Internet access Kaspersky Sandbox uses Internet access emulation to compensate for the lower detection rate due to the lack of Internet access for processed objects.

The network interface to be used by virtual machines for Internet access must be connected to a subnet that does not intersect, in terms of addressing, with the subnet that the management interface is connected to.

If the security policy of your organization denies access to the Internet from computers of local network users, and you have configured Kaspersky Sandbox network interface to be used by virtual machines for Internet access, there is a risk of the following scenario:

A hacker can attach a malware to a random file and initiate a Sandbox scan of this file from the computer of a local network user. This file is then exfiltrated from the local network through the network interface used by virtual machines for Internet access while the file is being scanned by Kaspersky Sandbox.

If virtual machines do not have internet access, Kaspersky Sandbox detection rate may be significantly decreased.

To configure a network interface used for Internet access of processed objects, proceed as follows:

  1. In the Kaspersky Sandbox web interface window, select the Virtual machines section.
  2. Under Internet access interface for virtual machines (detonation interface), from the Network interface list, select the network interface that you want to use for Internet access of processed objects.

    The management network interface cannot be selected from this list of network interfaces.

  3. In the IP address field, enter the IP address that you want to assign to this network interface.
  4. In the Mask field, enter the mask of the network in which you want to use this network interface.
  5. In the Default gateway field, enter the gateway address of the network in which you want to use this network interface.
  6. Click Apply.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.