Kaspersky Embedded Systems Security for Linux

Configuring Behavior Detection in the Web Console

In the Web Console, you can configure Behavior Detection settings in the policy properties (Application settings Advanced Threat Protection Behavior Detection).

Behavior Detection component settings

Setting

Description

Behavior Detection enabled / disabled

This toggle button enables or disables the Behavior Detection component.

The check toggle button is switched on by default.

Action on malware activity detection

The action to be performed by Kaspersky Embedded Systems Security upon detecting malicious activity in the operating system:

  • Inform user. Kaspersky Embedded Systems Security does not terminate the process that performs malicious activity; it only records the detection of malicious activity in the event log.
  • Block the application that performs malicious activity (default value). Kaspersky Embedded Systems Security terminates the process that performs malicious activity and logs information about the detected malicious activity.

Exclusions by process

Clicking the Configure exclusions by process link opens the Exclusions by process window. In this window, you can exclude the activity of processes.