Kaspersky Embedded Systems Security 3.4 for Windows

Creating rules with the Rule Generator for Device Control local task

A local Rule Generator for Device Control task allows automatically adding Device Control rules for external devices connected to the protected computer to the settings of the local Device Control task and generating an XML file with the Device Control rules. After that, you can import the XML file in the Device Control settings, in the Kaspersky Security Center group policy or in the local Device Control task on any protected computer.

To secure the protected device, we recommend finalizing the list of Device Control rules before running the Device Control task in active mode. For this reason, we recommend collecting data on connections from controlled external devices in Device Control Statistics Only mode.

To set up Device Control rules using a local Rule Generator for Device Control task:

  1. Open the properties of the policy that manages the device you are planning to connect external devices to.
  2. Enable Device Control Statistics Only mode.
  3. Activate the policy.
  4. Connect the controlled external devices you want to create Device Control rules for to the protected computer.
  5. Go to the settings of the local Rule Generator for Device Control task.
  6. Select a task running mode under Mode:
    • Consider system data about all external devices that have ever been connected
    • Consider currently connected external devices only
  7. Under After task completes, specify actions for Kaspersky Embedded Systems Security for Windows to perform upon task completion:
    • .
    • .
    • .
    • .
  8. If you have enabled the Export allowing rules to file action, specify the path to the XML file the Device Control rules will be saved to.
  9. In the Rule Generator for Device Control window, click Save.
  10. In the list of tasks, select the check box next to the configured Rule Generator for Device Control task.
  11. Click Run to start the task.

When the task completes, the automatically generated Device Control rules will be saved in the settings of the local Device Control task and/or to an XML file inside the specified folder.