Creating rules using the Rule Generator for Device Control task

A local Rule Generator for Device Control task allows automatically adding Device Control rules for external devices connected to the protected computer to the settings of the local Device Control task and generating an XML file with the Device Control rules. After that, you can import the XML file in the Device Control settings, in the Kaspersky Security Center group policy or in the local Device Control task on any protected computer.

To secure the protected device, we recommend finalizing the list of Device Control rules before running the Device Control task in active mode. For this reason, we recommend collecting data on connections from controlled external devices in Device Control Statistics Only mode.

To create device control rules via the Rule Generator for Device Control task:

  1. Enable Device Control Statistics Only mode.
  2. Connect the controlled external devices you want to create Device Control rules for to the protected computer.
  3. In the Application Console tree, expand the Automated rule generators node.
  4. Select the Rule Generator for Device Control child node.
  5. In the results pane of the Properties child node, click the Rule Generator for Device Control link.

    The Task settings window appears.

  6. On the General tab, under Task mode, select a task mode:
    • Consider system data about all external devices that have ever been connected
    • Consider currently connected external devices only
  7. In the After task completes section, specify the actions that must be performed by Kaspersky Embedded Systems Security for Windows upon task completion:
    • Add allowing rules to the list of Device Control rules.
    • Principle of adding.
    • Export allowing rules to file.
    • Add protected device details to file name.
  8. If you have enabled the Export allowing rules to file action, specify the path to the XML file the Device Control rules will be saved to.
  9. Click the OK button in the Task settings window.
  10. In the results pane of the Properties node, click Run link to start the task.

Once the task completes, automatically created device control rules will be saved in the Device Control settings and/or an XML file in the specified folder.

Page top