Kaspersky Anti Targeted Attack Platform includes two functional blocks:
You can use the full functionality of the program (KATA and KEDR key) or partial functionality (only KATA key or only KEDR key).
Principle of operation of Kaspersky Anti Targeted Attack
Kaspersky Anti Targeted Attack includes the following components:
The components interact as follows:
A Sensor component can also be a mail sensor, which is a server or virtual machine on which the Kaspersky application Kaspersky Secure Mail Gateway (KSMG) or Kaspersky Security for Linux Mail Server (KLMS) is installed.
If any threats are detected, the Central Node server records relevant information in the alert database. You can view the alert table in the Alerts section of the program web interface or by generating an alert report.
Alert information can also be published to a SIEM system that is used in your organization, as well as external systems. Information on Sandbox component alerts can be published in the local reputation database of Kaspersky Private Security Network.
Principle of operation of Kaspersky Endpoint Detection and Response
Kaspersky Endpoint Detection and Response includes the following components:
The Sensor component can be used as a proxy server for outgoing connections from Kaspersky Endpoint Agent.
The components interact as follows:
Kaspersky Endpoint Agent sends information about the following events to the Central Node server:
Kaspersky Endpoint Agent can also integrate with Endpoint Protection Platform (hereinafter also referred to as "EPP") workstation protection programs: Kaspersky Endpoint Security and Kaspersky Security for Windows Server installed on the same computer as Kaspersky Endpoint Agent. In this case, Kaspersky Endpoint Agent also sends information about threats detected by the EPP programs and results of threat processing by these programs to the Central Node server.
The components interact as follows:
The Central Node server processes received data and displays the corresponding events in the program web interface.
As a result of data processing by EPP programs, Detect and Detect processing result events are generated.
Events arriving at the Central Node server are marked by TAA (IOA) rules. As a result of this markup, alerts are generated for events that require user attention.
When the Central Node server is integrated with Kaspersky Endpoint Agent, you can do the following to react to detected threats:
The principle of operation of Kaspersky Anti Targeted Attack Platform is shown in the following picture.
Principle of operation of Kaspersky Anti Targeted Attack Platform
You can configure settings of each Central Node component individually or manage several components in a centralized way in distributed solution mode.
A distributed solution is a two-tier hierarchy of Central Node servers. This structure sets apart a master control server known as the Primary Central Node (PCN) and slave servers known as Secondary Central Nodes (SCN).
The principle of operation of Kaspersky Anti Targeted Attack Platform in distributed solution mode is shown in the following picture.
Principle of operation of Kaspersky Anti Targeted Attack Platform in distributed solution mode