KASPERSKY SECURITY NETWORK (KSN) STATEMENT
Kaspersky Security Network Statement (hereinafter "KSN Statement") relates to Kaspersky Endpoint Security for Linux (hereinafter "Software").

All terms used in this KSN Statement have the same meaning defined in the End User License Agreement (EULA) under the clause "Definitions".

KSN Statement along with the End User License Agreement for Software, in particular in the Section "Conditions regarding Data Processing" specifies the conditions, responsibilities and procedures relating to transmission and processing of the data, indicated in the KSN Statement. Carefully read the terms of the KSN Statement, as well as all documents referred to in the KSN Statement, before accepting it.

When the End User activates the using of the KSN, the End User is fully responsible for ensuring that the processing of personal data of Data Subjects is lawful, particularly, within the meaning of Article 6 (1) (a) to (1) (f) of Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") if Data Subject is in the European Union, or applicable laws on confidential information, personal data, data protection, or similar thereto.

Data Protection and Processing
The Rightholder handles the data it receives from the End User under this Statement in accordance with the Rightholder's Privacy Policy published at: https://www.kaspersky.com/products-and-services-privacy-policy.

Purpose of Data Processing
To make it possible to increase the Software's speed of reaction to information and network security threats.
The declared purpose is achieved by:
• determining the reputation of scanned objects;
• identifying information security threats that are new and challenging to detect, and their sources;
• taking prompt measures to increase the protection of the data stored and processed by the End User with the Computer;
• reducing the likelihood of false positives;
• increasing the efficiency of Software components;
• investigating the infection of a user's computer;
• improving the performance of the Rightholder's products;
• receiving reference information about the number of objects with known reputation.

Processed Data
While KSN is enabled, the Rightholder will receive and process the following data automatically: the DNS address of the web service being accessed; the IP address; the IP (IPv4) address of the web service that was accessed; the IP (IPv6) address of the web service that was accessed; the DNS server's IP address; the IP address of the attacker; the MAC address of the source of the network attack; the address of the web service that was accessed during processing (its web address and IP address); the algorithm for evaluating the public key of the certificate; the algorithm for calculating the fingerprint of the digital certificate; the command-line arguments passed to the process at startup; the attributes of the executable file processed; the attributes of the object processed; the bit mask of the DNS request parameters; the bit mask of the parameters of the object processed; the bit mask based on the Data Directories section from the PE file header; the web address of the source of the request to the web service (referer); the web address from which the file corresponding to the process was downloaded; the version of the record in the software database; the version of the software activation code; the version of the update component; the version of the software component; the version of the status confirmation of the software license key; the version of the object processed; the version of the specified compiler; the OS version, OS build number, OS upgrade number, OS edition, extended information on the OS edition, OS kernel version, and OS architecture; the version of the software; the version of the statistics sent; the version of the OS upgrade package; the version of software service revocation list; the version of the OS installed at the User's Computer, and the OS kernel version; the emulator version; the weight of the detected call to the phishing web service ; the external IP address; the timestamp of the software databases; the timestamp of the component (its local version); the timestamp of the upgrade component (its updated version); the timestamp of the root index of the downloaded updates; the timestamp of the root index of the existing updates; the timestamp of the activated record in the antivirus software databases; the time the object is resident in the buffer; the storage time of the object processed; the emulation depth; the internal log data generated by the antivirus software component for the object processed; the license data to identify the group of users within the company that purchased the license by the comment in the license properties; the date and time of certificate issuance; the date and time of release of the software databases; the date and time of the certificate's expiration; the date and time of linking the executable file; the start date and time of receiving statistics; the date and time of detection of third-party software by the activity monitoring component; the end date and time of receiving statistics; the date and time of the first startup of the object processed; the date and time of the object's signing; the date and time of the last modification of the object processed; the date and time of the event; the date and time of confirmation of the status of the software license key; the date and time of creation of the executable file processed; the date and time of creation of the object processed; the license expiration date; user actions with the interface element in the software window; the header of the processed HTTP request; the software's score for the object processed; the value of the Characteristics attribute from the PE file header; the value of the Subsystem attribute from the PE file header; the value of the TARGET filter for the update task; the identifier of the software classification database; the account security identifier (SID); the identifier of the task where the detection occurred; the identifier of the record in the software databases; the identifier of the security zone from the NTFS stream; the identifier of the key from the encryption key store; the software component identifier ; the configuration identifier; the license identifier; the software update identifier; the third-party software update identifier ; the identifier of the operation performed by the software; the identifier of the operation performed by the third-party software; the OS identifier; the identifier of the data packet sent to KSN; the software identifier; the protocol identifier; the system process identifier (PID); the identifier of the regional activation center; the identifier of the parent process (PID) in the system; the identifier of the certificate used to sign the header of the status confirmation of the software's license key; the identifier of the KSN service accessed by the software; the identifier of the activated record in the antivirus software databases; the identifier of the status confirmation of the active license key of the software; the software installation identifier (PCID); the identifier of the account on behalf of which the controlled process was started; the vulnerability identifier; the identifiers of executed commands; the name and settings of the certificate owner; the computer's name on the network (domain name); the name of the object processed; the name of the application of which the object being processed is a part; information on the client using the network protocol (the user agent) ; information on the results of verification of the file signature; information about who signed the object processed; information on software updates; the source of the score for the object processed; the host source; the vulnerability hazard class; the login session key; the encryption algorithm of the login session key; the file catalog code; the error category code; the error code; the error code of the update task; the object type code; the file operation code; the number of requests made to KSN; the number of requests for which answers were found in the local request database; the number of software runs since the last time the file checksum was sent; the number of failed KSN transactions; the number of failed requests due to KSN being disabled in the software settings; the number of failed KSN requests due to routing errors; the number of failed KSN requests due to network issues; the number of failed connections to KSN; the number of new KSN connections; the number of cached KSN connections; the number of sections in the PE file header; the number of successful KSN transactions; the number of successful connections to KSN; the startup command line; the checksum (MD5) of the mask used to block the web service; the checksum (MD5) of the object processed; the checksum (SHA256) of the object processed; the checksum of the software activation code; the checksum of the status confirmation of the software license key; checksum of the object processed; the checksum of the object processed (MD5) ; the checksum of the user name; the checksum of the key file used to activate the software; the local IP address; the local port that was attacked; the location where code was inserted in the process; the HTTP request implementation method; the component name; the name of detected malware or of legitimate software that could be used to harm the device or user data; the software's name; the software vendor's name; the name of the network protocol used in the detected network attack; the name of a created or changed OS service; the names of the packers used to pack the object processed; the name of the certificate issuer; the direction of the network connection; the number of the detected software in the context of the activity monitoring component; the port number; the scope of the IP address; detected file operations performed on the object processed; processed objects or their parts; the processed web address; a description of the processed object specified in its properties; the DNS server response; the fingerprint of the digital certificate of the processed object and hashing algorithm; the full software version; the sequence number of the fragment in the processed object; the access rights of the processed object; KSN's trust marker for the processed object; the marker of the processed object for which the decision for the object was withdrawn; the indication that the detection is performed for debugging; the indication that the processed object is a PE file; the indication that the object is in autostart; the indication that the message is a part of a message set related to one request to the web service; the reason for detection of third-party software by the activity monitoring component; the protocol used to transfer data to KSN; the certificate's public key; the path of the executable file of the parent process; the path of the source object; the path of the object processed; the overlay size from the PE file header; the size of the object processed; the size of the software image; the OS architecture and bit number; the distribution of timed-out KSN requests by execution time; the distribution of failed KSN transactions by execution time; the distribution of failed KSN connections by connection time; the distribution of cancelled KSN requests by execution time; the distribution of successful KSN transactions by execution time; the distribution of successful KSN requests by execution time; the distribution of successful KSN connections by connection time; the OS edition; the result of the actions performed by the software; the result of the operation with the processed object; the result of object verification in KSN; the result of signature verification for the module that is checked for integrity by the software; the result of certificate verification; the properties and checksums of parts of the executable file; properties and checksums of parts of the executable file; the certificate serial number; the network interfaces of the Computer; fragment content in the processed object; the software license status; the software's performance status after update; the confidence level for detecting access to the phishing web service; the technical specifications of the detection technologies used; the update task type; the type of verification task of the executable file that results in sending statistics; the DNS server request type; the checksum type of the processed object; the event type for the statistics packet; the statistics message type; the type of activated record in the antivirus software databases; the type of installed software; the type of account on behalf of which the potentially infected object was executed; the unique identifier of the activity log of the processed object; the unique identifier of the User in the systems of the Rightholder; the unique event identifier; the unique device identifier; the integrity level of the processed object; the data format in a request to the infrastructure of the Rightholder; the format of the processed object; the detection characteristics; the encryption parameters of the data packet sent to KSN; the phishing attack's target; the number of failed installations for the update component; the number of installations for the update component that resulted in an error; the heuristically determined name of the email marketer - the sender of the email message; the entropy of the processed object; the number of cycles of updating and application of antivirus databases; the date and time of the last update and application of antivirus databases; the date and time of release of the software databases; the device identifier; the date and time of the OS startup; the date and time of the activity monitoring component startup; the probability of sending statistics by the activity monitoring component; the code of the event processed by the activity monitoring component longer than the standard processing time; the processing time of the database event by the activity monitoring component which was longer than the standard processing time; the delay time of OS action event processing in the behavior analysis sybsystem; the number of delayed events of the current type in the OS; the maximum allowed time of event processing by the activity monitoring component; the delay time of OS action event processing in the activity monitoring sybsystem; the number of processed events in the OS; the number of processed synchronous events in the OS; the total delay of all events of the current type in the OS; the delay time of OS action event processing in the permanent event storage subsystem; the processing time of the event by the activity monitoring component which was longer than the standard processing time; the total number of events processed by the monitoring activity component with processing time longer than standard; the total delay of all events in the OS; the number of pending synchronous events in the OS; the date and time of receiving an OS action event; the code of the event processed by the activity monitoring component that caused the event queue to overflow; the number of events processed by the activity monitoring component that caused the event queue to overflow; the total number of overflows on the event queue processed by the activity monitoring component; the time difference between the first event in the queue and the current event at the moment of sending the statistics package by the activity monitoring component; the type of event processing that was timed out (klif event/swmon event); the high and low numbers of the trapping filter which performed the trapping and processing by the activity monitoring component and that timed out; the identifier of the trapping processing by the activity monitoring system that timed out; the number of klif events which were timed out at the moment of sending the statistics package by the activity monitoring component; the size of event queue processing by the activity monitoring component that timed out; the number of timed-out events processed by the activity monitoring component which were timed out at the moment of sending the statistics package by the activity monitoring component; the make, model, and architecture of the processor; processor brand, model and architecture; name of the module in which the failure is suspected to have occurred; line number in the script text where the error occurred; error type; nested error that occurred during application operation; source object path; memory stack in the software process at the time of failure; software component identifier; software component version; software module identifier; software module download address; system process identifier (PID); attribute data; description of the processed object specified in its properties; processed object size; error message text.

Also, in order to achieve the declared purpose with respect to preventing false positives, the Rightholder may receive trusted executable and non-executable files or their parts.

When the Software works in a Standard mode, the Rightholder will additionally receive and process the following data: the device ID; Software ID derived from the license; the date and time of the Software installation; type of the installed Software; the date and time of the Software activation; the Software license ID; the ID of the information model used to provide the Software license; the serial number of the Software license key; Software localization; the identifier of the partner organization via which the Software license order was placed; the Software rebranding ID; the name of the Software component; the operating status of the Software component; the Software identifier for which the license is intended; flag indicating whether participation in KSN is enabled, and delay time for sending statistics.
Your Choice to Participate
Providing the above information to the KSN is voluntary. After installing the Software, the End User can at any time enable or disable the use of the KSN in the Software settings as described in the User Manual.
When the End User decides to disable the KSN, the Rightholder will not receive new data. The Rightholder may still process certain data already received under legitimate interest according to point (f) of Article 6 (1) of the EU General Data Protection Regulation (GDPR) for the purposes described in the Privacy Policy at https://www.kaspersky.com/products-and-services-privacy-policy. If the End User wishes to object to such data processing, the End User must inform the Rightholder in the manner specified in the Privacy Policy. For more information about legal bases for data processing and End User's rights and options, the End User may consult the Privacy Policy at https://www.kaspersky.com/products-and-services-privacy-policy.
© 2022 AO Kaspersky Lab