Operating principle of the application

The Kaspersky Anti Targeted Attack Platform application includes two functional units:

You can use the full functionality of the application (KATA+NDR key) as well as partial functionality (only the KATA key).

Principle of operation of Kaspersky Anti Targeted Attack

Kaspersky Anti Targeted Attack includes the following components:

Sensor, Central Node and Sandbox interoperate as follows:

If any threats are detected, the Central Node server records relevant information in the alert database. You can view the alert table in the Alerts section of the application web interface or by generating an alert report.

Alert information can also be published to a SIEM system that is used in your organization, as well as external systems. Information on Sandbox component alerts can be published in the local reputation database of Kaspersky Private Security Network.

The principle of operation of Kaspersky Anti Targeted Attack Platform is shown in the following picture.

kata_standalone_scheme

Principle of operation of Kaspersky Anti Targeted Attack Platform

You can configure settings of each Central Node component individually or manage several components in a centralized way in distributed solution mode.

A distributed solution is a two-tier hierarchy of Central Node servers. This structure sets apart a primary control server known as the Primary Central Node (PCN) and secondary servers known as Secondary Central Nodes (SCN).

The principle of operation of Kaspersky Anti Targeted Attack Platform in distributed solution mode is shown in the following picture.

kata_distributed

Principle of operation of Kaspersky Anti Targeted Attack Platform in distributed solution mode

See also

Kaspersky Anti Targeted Attack Platform Help

About Kaspersky Anti Targeted Attack Platform

Data provision

Application licensing

Architecture of the application

Distributed solution and multitenancy

Sizing Guide

Installing and performing initial configuration of the application

Configuring the sizing settings of the application

Configuring firewall rules

Configuring integration of the Endpoint Agent component with the NDR functional block

Integration with mail sensors

Getting started with the application

Managing accounts of application administrators and users

Authentication using domain accounts

Authentication using OSMP accounts

Participation in Kaspersky Security Network and use of Kaspersky Private Security Network

Managing the Sandbox component through the web interface

Uploading an independently prepared certificate to the Sandbox server

For administrators: Getting started with the application web interface

For security officers: Getting started with the application web interface

Managing user-defined Sandbox rules

Preparing data for GosSOPKA

Sending notifications

Managing logs

Viewing application messages

Configuring the storage duration for system logs and detections of Kaspersky Anti Targeted Attack Platform

Viewing information about files that have sent for scanning to the Kaspersky Anti Targeted Attack Platform

Managing Kaspersky Endpoint Security for Windows

Managing Kaspersky Endpoint Security for Linux

Backing up and restoring data

Upgrading Kaspersky Anti Targeted Attack Platform

Managing application components in the administrator menu

Using the KATA API

Using the NDR API

Sources of information about the application

Contacting the Technical Support Service

Information about third-party code

Trademark notices

Page top