Contents
Triggering of rules in Smart Training mode
This section provides information about the detections performed by the Adaptive Anomaly Control rules in Kaspersky Endpoint Security for Windows on client devices.
The rules detect anomalous behavior on client devices and may block it. If the rules work in Smart Training mode, they detect anomalous behavior and send reports about every such occurrence to Kaspersky Security Center Cloud Console Administration Server. This information is stored as a list in the Rule triggers in Smart Training state subfolder of the Repositories folder. You can confirm detections as correct or add them as exclusions, so that this type of behavior is not considered anomalous anymore.
Information about detections is stored in the event log on the Administration Server (along with other events) and in the Adaptive Anomaly Control report.
For more information about Adaptive Anomaly Control, the rules, their modes and statuses, refer to Kaspersky Endpoint Security Help.
Viewing the list of detections performed using Adaptive Anomaly Control rules
To view the list of detections performed by Adaptive Anomaly Control rules:
- In the main menu, go to Operations → Repositories.
- Click the Rule triggers in Smart Training state link.
The list displays the following information about detections performed using Adaptive Anomaly Control rules:
To view properties of each information element:
- In the main menu, go to Operations → Repositories.
- Click the Rule triggers in Smart Training state link.
- In the window that opens, select the object that you want.
- Click the Properties link.
The properties window of the object opens and displays information about the selected element.
You can confirm or add to exclusions any element in the list of detections of Adaptive Anomaly Control rules.
To confirm an element,
Select an element (or several elements) in the list of detections and click the Confirm button.
The status of the element(s) will be changed to Confirming.
Your confirmation will contribute to the statistics used by the rules (for more information, refer to Kaspersky Endpoint Security for Windows documentation).
To add an element as an exclusion,
Select an element (or several elements) in the list of detections and click the Exclude button.
The Add exclusion wizard starts. Follow the instructions of the wizard.
If you reject or confirm an element, it will be excluded from the list of detections after the next synchronization of the client device with the Administration Server, and will no longer appear in the list.
Adding exclusions from the Adaptive Anomaly Control rules
The Add exclusion wizard enables you to add exclusions from the Adaptive Anomaly Control rules for Kaspersky Endpoint Security for Windows.
To start the Add exclusion wizard through the Adaptive Anomaly Control node:
- In the main menu, go to Operations → Repositories → Rule triggers in Smart Training state.
- In the window that opens, select an element (or several elements) in the list of detections, and then click the Exclude button.
You can add up to 1000 exclusions at a time. If you select more elements and try to add them to exclusions, an error message is displayed.
The Add exclusion wizard starts. Proceed through the wizard by using the Next button.