Kaspersky Embedded Systems Security 3.4 for Windows

About Device Control rules

Kaspersky Embedded Systems Security for Windows does not apply allowing rules for MTP-connected mobile devices.

The rules are generated uniquely for each device that is currently connected or has ever been connected to a protected device if the information about this device is stored in the system registry.

The maximum number of the Device Control rules supported by Kaspersky Embedded Systems Security for Windows is 3072.

Device Control rules are described below.

Rule type

Rule type is always allowing. In active mode, the Device Control task blocks access to all controlled device types unless they fall within the scope of at least one Device Control rule.

Triggering criterion and rule usage scope

Device Control rules identify connected devices by Device instance path value. The device instance path is a unique ID that the system assigns to a controlled device when it connects to the protected device.

Kaspersky Embedded Systems Security for Windows controls connection of external CD/DVD drives regardless of the bus used for connection. When mounting such device via USB, operating system registers two path values to the device instance: for the external device and for CD/DVD drive (for example, IDE or SCSI). To connect such devices correctly, allowing rules for each path value to the instance must be set.

Kaspersky Embedded Systems Security for Windows automatically defines the device instance path and parses the value obtained into the following elements:

  • Device manufacturer (VID)
  • Device controller type (PID)
  • Device serial number

You cannot set the device instance path manually. Allowing rule triggering criteria define the rule usage scope. By default, the usage scope of a newly created allowing rule includes the one initial device whose properties Kaspersky Embedded Systems Security for Windows used to generate the rule. You can configure the new rule by using a mask to expand the rule application scope.

Initial device values

Device properties that Kaspersky Embedded Systems Security for Windows used for allowing rule generation and that are displayed in Windows Device Manager for each device connected.

Initial device values contain the following information:

  • Device instance path. Based on this property, Kaspersky Embedded Systems Security for Windows defines rule triggering criteria and fills the following fields: Manufacturer (VID), Controller type (PID), and Serial number in the Rule usage scope block of the Rule properties window.
  • Friendly name. Device clear name that is set in the device properties by its manufacturer.

Kaspersky Embedded Systems Security for Windows automatically defines initial device values when the rule is generating. Later on you can use these values to recognize the device that was used as a base for the rule generating. Initial device values are not available for editing.

User and group access permissions

By default, when a rule is created, Everyone (rw) group is displayed in Access rights for user or user group field, which means full access for all users. You can configure access rights to the device described in a rule for one or several users and groups.

Description

You can add further information for each created Device Control rule in the Description field, such as the connected device name or owner. The description is displayed in the corresponding field, in the Device Control rules window.

The rule ignores the initial device description and values—these only serve the user's reading comfort.