Kaspersky Embedded Systems Security 3.4 for Windows

Expanding Device Control rules usage scope

Each automatically generated Device Control rule allows connecting only one external device. You can manually expand the scope of a Device Control rule by setting a device instance path mask in the rule properties.

Using a device instance path mask reduces the total number of allowing device control rules and simplifies rule processing. However, expanding the scope of Device Control rules can compromise control over connected external devices.

To apply a path mask to a device instance in the Device Control rule properties:

  1. Go to the Device Control settings in the policy.
  2. On the General tab, click Rules list.

    The Device Control rules window opens.

  3. Double-click the name of the Device Control rule to display its settings.
  4. In the Rule properties window that opens, do the following:
    • Select the Use mask check box next to the Vendor (VID) field if you want the rule to allow connections from all external devices with that Vendor ID.
    • Select the Use mask check box next to the Controller type (PID) field if you want the rule to allow connections from all external devices with that controller type.
    • Select the Use mask check box next to the Serial number field if you want the rule to allow connections from all external devices with that serial number.

    If the Use mask check box is selected in at least one of the fields, the data from the fields with the selected check box is replaced with the * character and is not considered when the rule is applied.

  5. If necessary, add further rule details in the User or group of users access rights field. For example, specify the devices affected by the rule.
  6. Click the OK button.

The newly configured rule properties will be saved. The rule usage scope will be expanded according to a device instance path mask specified.