The engine is the set of basic system components supplied to each protected facility
Detects anomalies on the basis of data processing using the ML model
Groups similar anomalies
Handles data exchange between Kaspersky MLAD components
Stores received technological parameter values, ML model predictions, and prediction errors
Routes messages for storage
Used to store all Kaspersky MLAD settings
Ensures the operation of Kaspersky MLAD internal interfaces
Ensures the operation of the Kaspersky MLAD web interface
Stores Kaspersky MLAD functional logs
Sends alerts about anomalies
The neural network model built by Kaspersky or a certified integrator for a specific protected facility. The ML model detects anomalies.
The ML model is not included in the product bundle, and is provided as part of Kaspersky MLAD’s model-building and integration services.
The Kaspersky MLAD bundle includes services for data exchange with external systems. For each protected facility, one of the following connectors must be selected:
KICS Connector
Receives process parameter values from Kaspersky Industrial CyberSecurity for Networks using the secure gRPC protocol
KICS Alert Reporter
Reports detected anomaly events to Kaspersky Industrial CyberSecurity for Networks using the secure gRPC protocol
KICS Configuration Reader
Receives configurations and technological parameter metadata from Kaspersky Industrial CyberSecurity for Networks using the secure gRPC protocol
Receives data from an ICS using the protocol described in the OPC Unified Architecture specification
Receives data from an ICS by sending CSV files with tags through POST requests using the HTTP protocol