You can configure traffic monitoring of system commands that are transmitted and received by process control devices.
In Kaspersky Industrial CyberSecurity for Networks, system commands include management commands (for example, START PLC) as well as system messages related to the operation of devices or containing packet analysis results (for example, REQUEST NOT FOUND). System commands in Kaspersky Industrial CyberSecurity for Networks are categorized based on the categories listed in the Appendices.
When a monitored system command is detected, Kaspersky Industrial CyberSecurity for Networks registers an event for Command Control technology. The event is registered using the system event type that is assigned the code 4000002602. You can configure the settings for this type of event.
Only users with the Administrator role can configure monitoring of system commands for devices.
To configure monitoring of system commands for a device:
In the Network map section, you can select the device on both the network interactions map and the topology map.
If Process Control settings are not defined for a device, add the settings.
The Edit Process Control settings window appears.
This button is unavailable if not all required values are specified or if there are invalid values in the settings.
Information in the block containing the defined settings is updated in the lower part of the Addresses tab in the details area.
Page top