Kaspersky Embedded Systems Security 3.4 for Windows

Expanding Device Control rules usage scope

Each automatically generated Device Control rule allows connecting only one external device. You can manually expand the scope of a Device Control rule by setting a device instance path mask in the rule properties.

Using a device instance path mask reduces the total number of allowing device control rules and simplifies rule processing. However, expanding the scope of Device Control rules can compromise control over connected external devices.

To apply a path mask to a device instance in the Device Control rule properties:

  1. In the Application Console tree, expand the Computer Control node.
  2. Select the Device Control child node.
  3. In the results pane of the Device Control node, click the Device Control rules link.

    The Device Control rules window opens.

  4. In the window that opens, select the rule whose properties you want to apply the device instance path mask to.
  5. Open the Rule properties window by double clicking on a selected device control rule.
  6. In the window that opens, perform the following operations:
    • Select the Use mask check box next to the Manufacturer (VID) field if you want the selected rule to allow connections for all external devices that fit the specified information about device manufacturer.
    • Select the Use mask check boxes next to the Controller type (PID) field if you want the selected rule to allow connections for all external devices that fit the specified information about controller type.
    • Select the Use mask check box next to the Serial number field if you want the selected rule to allow connections for all external devices that match the specified information about the device serial number.

    If the Use mask check box is selected in at least one of the fields, the data from the fields with the selected check box is replaced with the * character and is not considered when the rule is applied.

  7. If necessary, add further rule details in the User or group of users access rights field. For example, specify the devices affected by the rule.
  8. Click the OK button.

The newly configured rule properties will be saved. The rule usage scope will be expanded according to a device instance path mask specified.