Adaptacyjna kontrola anomalii

for Windows

The Adaptive Anomaly Control component monitors and blocks actions that are not typical of the computers in a company's network. Adaptive Anomaly Control uses a set of rules to track non-typical behavior (for example, the Uruchomienie usługi Microsoft PowerShell przez aplikację Office rule). Reguły są tworzone przez specjalistów z Kaspersky na podstawie typowych scenariuszy szkodliwej aktywności. Możesz skonfigurować sposób, w jaki Adaptacyjna kontrola anomalii obsługuje każdą regułę i na przykład zezwolić na wykonywanie skryptów PowerShell, które automatyzują określone zadania przepływu pracy. Kaspersky Endpoint Security updates the set of rules along with the application databases.

Configuring Adaptive anomaly control consists of the following steps:

  1. Training Adaptive Anomaly Control.

    After you enable Adaptive Anomaly Control, its rules work in training mode. During the training, Adaptive Anomaly Control monitors rule triggering and sends triggering events to the server. Each rule has its own duration of the training mode. The duration of the training mode is set by Kaspersky experts. Normally, the training mode is active for two weeks.

    If a rule is not triggered at all during the training, Adaptive Anomaly Control will consider the actions associated with this rule as non-typical. Kaspersky Endpoint Security will block all actions associated with that rule.

    If the rule is triggered during training, Kaspersky Endpoint Security logs events in the rule triggering report and the Adaptive Anomaly Control detection storage.

  2. Analyzing the rule triggering report.

    The administrator analyzes the rule triggering report or the contents of the Adaptive Anomaly Control detection storage. Then the administrator can select the behavior of Adaptive Anomaly Control when the rule is triggered: either block or allow. The administrator can also continue to monitor how the rule works and extend the duration of the training mode. If the administrator does not take any action, the application will also continue to work in training mode. The training mode term is restarted.

Adaptive Anomaly Control is configured in real time. Adaptive Anomaly Control is configured via the following channels:

Przejdź do góry