Configuring Adaptive Anomaly Control

To configure Adaptive Anomaly Control:

  1. Open Kaspersky Endpoint Security Cloud Management Console.
  2. Select the Security managementSecurity profiles section.

    The Security profiles section contains a list of security profiles configured in Kaspersky Endpoint Security Cloud.

  3. In the list, select the security profile for the devices on which you want to configure Adaptive Anomaly Control.
  4. Click the link with the profile name to open the security profile properties window.

    The security profile properties window displays settings available for all devices.

  5. In the Windows group, select the Management settings section.
  6. Switch the toggle button to Adaptive Anomaly Control is enabled.
  7. Click the Settings link below the Adaptive Anomaly Control is enabled toggle button.

    The Adaptive Anomaly Control component settings page opens.

  8. Enable or disable the required Adaptive Anomaly Control rules:
    • To enable a rule, switch on the toggle button in the Status column.
    • To disable a rule, switch off the toggle button in the Status column.
  9. In the Action column, select the mode of each rule:
    • Notify

      The detections made by this rule are only added to the Event log. No other actions are made.

    • Block

      The feature blocks all actions that are associated with the rule.

    • Smart

      First, you train the rule by selecting whether the detections made by it are actually uncharacteristic behavior or false positives. After the training period ends, the feature allows or blocks further actions according to the training results.

  10. If necessary, change exclusions to the rules.
  11. Click the Save button.

After the security profile is applied, the Adaptive Anomaly Control component is enabled and configured on Windows devices.

Page top