Please enable JavaScript in your web browser!
Managing the list of blocked network sessions
To add network sessions showing any malicious or encrypting activity to the List of blocked network sessions and block access to network file resources for those sessions, at least one of the following components should be enabled:
Network Threat Protection Behavior Detection Enabling blocking of untrusted hosts in the Kaspersky Security Center Administration Console
In the Kaspersky Security Center Administration Console tree, select the Policies folder. Select the necessary policy and double-click to open the policy properties. In the policy window, select Network activity control → Network Threat Protection settings and click Settings . In the window that opens, select the Network Threat Protection check box. On the General tab, enable the Block mode. Select the Block attacking devices for check box and specify the blocking duration. Save your changes. To configure the blocking of untrusted network sessions for the Behavior Detection component in policy properties:
In the Kaspersky Security Center Administration Console tree, select the Policies folder. Select the necessary policy and double-click to open the policy properties. In the policy window, select Real-Time Computer Protection → Behavior Detection and click Settings . In the window that opens, select the Behavior Detection check box. Go to the Protection of shared folders tab and select the Protect shared folders check box. Select Block connection for and specify the blocking duration. If necessary, specify the protection scopes and exclusions by IP address and mask. Save your changes. Enabling blocking of untrusted hosts in the Kaspersky Security Center Web Console
In the main window of the Web Console, select Assets (Devices) → Policies & profiles . Click the name of the Kaspersky Embedded Systems Security policy.The policy properties window opens.
Select the Application settings tab. Go to Network activity control → Network Threat Protection and click the Configure button. In the window that opens, select the Enable Network Threat Protection check box. Enable the Block mode. Select the Block attacking devices for check box and specify the blocking duration. If necessary, specify exclusions by IP address. Save your changes. To configure the blocking of untrusted network sessions for the Behavior Detection component:
In the main window of the Web Console, select Assets (Devices) → Policies & profiles . Click the name of the Kaspersky Embedded Systems Security policy.The policy properties window opens.
Select the Application settings tab. Go to Real-Time Computer Protection → Behavior Detection and click the Configure button. In the window that opens, select the Enable Behavior Detection check box. Go to the Protection of shared folders tab and select the Enable protection of shared folders against external encryption check box. Select Block connection and specify the blocking duration in the Upon detection of external encryption of shared folders . section. If necessary, specify the protection scopes and exclusions by IP address and mask. Save your changes.
Enabling blocking of untrusted hosts in the Application Console
In the Kaspersky Embedded Systems Security Console tree, select Real-Time Computer Protection → Network Threat Protection . In the results pane of the Network Threat Protection node, click Properties .The Properties : Network Threat Protection window opens.
In the window that opens, select the Network Threat Protection check box. On the General tab, enable the Block mode. Select the Block attacking devices for check box and specify the blocking duration. Save your changes. To configure the blocking of untrusted network sessions for the Behavior Detection component:
In the Kaspersky Embedded Systems Security Console tree, select Real-Time Computer Protection → Anti-Cryptor . In the results pane of the Behavior Detection node, click Properties . In the window that opens, select the Behavior Detection check box. Go to the Protection of shared folders tab and select the Protect shared folders check box. Select Block connection for and specify the blocking duration. If necessary, specify the protection scopes and exclusions by IP address and mask. Save your changes.
Configuring the list of blocked sessions in the Application Console
In the Application Console tree, expand the Storages node. Select the Blocked network sessions child node. In the results pane, click the Properties button. In the window that opens, select the Block attacking devices for check box and specify the blocking duration. To restore access to all blocked network sessions, click Unblock all in the upper part of the window.All network sessions will be removed from the list and unblocked.
To remove network sessions from the list of blocked network sessions, in the list in the results pane, select one or more sessions and click Unblock selected in the upper part of the window.The selected network sessions are unblocked.
Page top