KICS for Networks analyzes network traffic to monitor suspicious network activity and deviations from normal communication behaviour in an industrial network. For correct functioning, KICS for Networks must receive a copy of network traffic sent from the industrial network switch configured to transmit mirrored network packets to the assigned network port. This technology of network traffic mirroring is called Switched Port Analyzer (SPAN) or Port Mirroring.
Below you can find Port Mirroring configuring examples for some Ethernet switch models, which may be relevant to some infrastructure setups. For configuring other switch models, refer to applicable industrial network equipment documentation.
For Cisco core and distributions switches (2960, 3850, etc.) use the switch command line interface for SPAN session configuration. For that, access the target switch via Ethernet or console port and open the switch management features. Then in configuration mode create a new monitoring session, choose the range of source interfaces for which you would like to have traffic mirrored and analyzed, set the destination interface, and save the configuration.
Example of required commands and actions is shown below:
conf t / — Enter global configuration mode. show monitor session all / — Check existing monitoring sessions no monitor session X / — Remove existing monitoring session (optional) monitor session 1 source interface 1/0 - 1/8 / — Specify new session ID and ports for source monitor session 1 destination interface 1/24 encapsulation replicate / — Specify the session ID and the destination port end / — Return to privileged EXEC mode. show monitor / — Verify the configuration. copy running-config startup-config / — Save the configuration in the configuration file to SPAN settings to be active after switch reboot (optional).
For detailed configuration instructions refer to official Cisco product documentation.
For Cisco Small Business switches (SG-200/300, etc.):
For Hirschmann Industrial Ethernet Switches:
For detailed configuration instructions, refer to official Hirschmann product documentation.
For Siemens SCALANCE Ethernet Switch configuration, connect to the switch web interface and go to Layer 2 → Mirroring.
In the General tab, create a Mirroring Session:
Switch to the Port tab to adjust detailed settings for the session ID.
In the Port tab, configure the Mirrored Port:
For detailed configuration instructions, please refer to official Siemens product documentation.
For Siemens Ruggedcom Ethernet Switch configuration, it is possible to use switch web interface. If it was not configured in a different way, the default IP address for the device is 192.168.0.1/24.
To configure port mirroring:
For detailed configuration instructions, please refer to official Siemens Ruggedcom product documentation, page 58.
Release of antivirus database updates (required to protect your computer/server/mobile device)
Providing technical support over phone / web
Release of patches for the application (addressing detected bugs)
Kaspersky Industrial CyberSecurity for Networks
Please let us know how we can make this website more comfortable for you
Thank you for submitting your feedback. We will review your feedback shortly.
Your feedback will be used for content improvement purposes only. If you need assistance, please contact technical support.
Your suggestions will help improve this article.