Configuring Network Activity Scanner for virtual machines

The suspicious network activity detection functionality is available only if you are using the application under an enterprise license.

To configure the Network Activity Scanner settings for protected virtual machines:

  1. In the Kaspersky Security Center Administration Console, open the properties of the policy whose scope includes the relevant virtual machines:
    1. In the console tree, select the folder or administration group in which the policy was created.
    2. In the workspace, select the Policies tab.
    3. Select a policy in the list of policies and double-click the policy to open the Properties: <Policy name> window.
  2. In the policy properties window, in the Network threat protection section, select the Intrusion Prevention subsection.
  3. Select the Monitor virtual machine network activity check box if virtual machine network activity scanner is disabled.
  4. Click the Settings button.

    The Network activity scanner parameters window opens.

  5. Specify the application categories whose signs of network activity should be detected by Kaspersky Security:
    • Adware
    • Other programs

    Kaspersky Security always detects network activity that is typical of such malware as viruses, worms and Trojans in the traffic of protected virtual machines.

  6. If Kaspersky Security detects network activity that you believe is not a sign of an intrusion into the protected infrastructure, you can configure a list of rules that Kaspersky Security will not apply to detect suspicious network activity in the traffic of protected virtual machines.

    To add a network activity detection rule to the list, click the Add button located above the list, and in the string of the list enter the rule ID in the following format: <number>:<number>:<number>.

    You can view information about an applied rule in the text of the event that was sent to Kaspersky Security Center when it detected the suspicious network activity.

  7. In the Network activity scanner parameters window, click OK.
  8. Select an action in the drop-down list Action upon detecting suspicious activity, if the network protection is deployed in standard mode.

    If network protection is deployed in monitoring mode, when Kaspersky Security detects suspicious network activity it performs the Ignore action.

  9. If necessary, change the value of the setting On threat detection, block traffic for N minutes.
  10. If necessary, configure network threat protection exclusion rules that Kaspersky Security will use to exclude traffic of specific IP addresses from scans or apply special actions when processing such traffic.
  11. In the Properties: <Policy name> window, click OK.
Page top