Training Adaptive Anomaly Control

Adaptive Anomaly Control includes a set of rules (behavior patterns). After you enable Adaptive Anomaly Control, its rules work in training mode. During the training, Adaptive Anomaly Control monitors rule triggering and sends triggering events to Kaspersky Security Center. Adaptive Anomaly Control does not block application activity on the computer, but only informs the administrator. You can also manually select the action that is performed when an Adaptive Anomaly Control rule is triggered.

How to view the list of Adaptive Anomaly Control rules in the Administration Console (MMC)

How to view Adaptive Anomaly Control rules in the Web Console and Cloud Console

How to view the list of Adaptive Anomaly Control rules in the application interface

Each rule has its own duration of the training mode. The duration of the training mode is set by Kaspersky experts. Normally, the training mode is active for two weeks.

If, during training, a rule never triggered, Adaptive Anomaly Control considers such behavior atypical and changes the status of the rule to Smart blocking. Subsequently, the application blocks any activity that matches this rule.

If a rule triggers during training, you need to manually configure the action that the application applies to detected activity that matches this rule. If you do not select the action when rule is triggered, Adaptive Anomaly Control continues in training mode.

Page top