Integration with KICS for Networks and KATA

Kaspersky Industrial CyberSecurity for Networks (hereinafter referred to as "KICS for Networks") is an application designed to protect the industrial enterprise infrastructure from information security threats, and to ensure uninterrupted operation. The application analyzes industrial network traffic to identify deviations in the values of process parameters, detect signs of network attacks, and monitor the operation and current state of network devices.

Kaspersky Anti Targeted Attack (hereinafter referred to as KATA) is an application designed for protection of corporate IT infrastructure and early detection of threats such as zero-day attacks, targeted attacks, and advanced persistent threats.

KICS for Networks or KATA can be integrated with KUMA. After configuring integration, you can perform the following tasks in KUMA:

Unlike KUMA, KICS for Networks and KATA refers to assets as devices.

The integration of KICS for Networks or KATA and KUMA must be configured in both applications:

  1. In KICS for Networks or KATA, you need to create a KUMA connector and save the communication data package of this connector.

    You can configure the integration on the side of KICS for Networks 4.0 or later as well as on the side of KATA 7.0 and later versions. Configuring the integration on either side allows correctly transmitting asset and event information to KUMA.

  2. In KUMA, the communication data package of the connector is used to create a connection to KICS for Networks or KATA.

The integration described in this section applies to importing asset information. KICS for Networks or KATA can also be configured to send events to KUMA. To do so, you need to create a SIEM/Syslog connector in KICS for Networks or KATA, and configure a collector on the KUMA side.

In this section

Configuring integration in KICS for Networks or KATA

Configuring integration in KUMA

Enabling and disabling integration with KICS for Networks or KATA

Changing the data update frequency

Special considerations when importing asset information from KICS for Networks or KATA

Changing the status of a KICS for Networks or KATA asset

Page top