Kaspersky Industrial CyberSecurity for Networks

Nodes on the network interactions map

March 22, 2024

ID 176847

Nodes on the network interactions map can be of the following types:

  • A device that is known to the application. This type of node represents a device that is listed in the devices table.
  • A device that is unknown to the application. This type of node represents a device with a unique IP address or MAC address that is not in the devices table. Such a node may appear on the network interactions map, for example, if network packets are sent using the ping command to the address of a non-existent device. Nodes corresponding to unknown devices are displayed individually if their total number does not exceed 100 (according to the current filter settings on the network interactions map). If the number of nodes exceeds this limit, one consolidated node of unknown devices is displayed.
  • WAN. This type of node represents devices of a Wide Area Network with which industrial network devices connect. WAN devices are any devices whose IP addresses belong only to Public subnets known to the application.

Displayed information on nodes representing devices

The following information is displayed for the nodes corresponding to known devices when the network interactions map is maximized:

  • Assigned device name.
  • Device category icon.
  • IP address of the device (If an IP address is not assigned, the MAC address is displayed).
  • Various icons depending on fulfillment of the following conditions:
    • if the router indicator has been set for the device.
    • if an EPP application is installed on the device (the color of the icon depends on the connection state).
    • if the device has the Archived status.
  • The thick line on the left border of a node has one of the following colors depending on the device's security state:
    • Green signifies the OK security state.
    • Yellow signifies the Warning security state.
    • Red signifies the Critical security state.

If a device has the Unauthorized status or has a security state different from the OK state, the node has a red background.

Information displayed on nodes representing unknown devices

The following information is displayed for the nodes corresponding to unknown devices when the network interactions map is maximized:

  • If a node represents one unknown device, the IP address or MAC address of the device is displayed. For a consolidated node of unknown devices (a node that combines more than 100 unknown devices), Unknown devices is displayed.
  • Icon for an unknown device and its status Unknown device node icon.

Nodes representing devices that are unknown to the application have a gray background.

Displayed information on WAN nodes

The following information is displayed for WAN nodes when the network interactions map is maximized:

  • Node name: WAN.
  • WAN node icon.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.