KASPERSKY SECURITY NETWORK (KSN) STATEMENT
Kaspersky Security Network Statement (hereinafter "KSN Statement") relates to Kaspersky Endpoint Security for Linux (hereinafter "Software").

All terms used in this KSN Statement have the same meaning defined in the End User License Agreement (EULA) under the clause "Definitions".

KSN Statement along with the End User License Agreement for Software, in particular in the Section "Conditions regarding Data Processing" specifies the conditions, responsibilities and procedures relating to transmission and processing of the data, indicated in the KSN Statement. Carefully read the terms of the KSN Statement, as well as all documents referred to in the KSN Statement, before accepting it.

When the End User activates the using of the KSN, the End User is fully responsible for ensuring that the processing of personal data of Data Subjects is lawful, particularly, within the meaning of Article 6 (1) (a) to (1) (f) of Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") if Data Subject is in the European Union, or applicable laws on confidential information, personal data, data protection, or similar thereto.

Data Protection and Processing
The Rightholder handles the data it receives from the End User under this Statement in accordance with the Rightholder's Privacy Policy published at: https://www.kaspersky.com/products-and-services-privacy-policy.

Purpose of Data Processing
To make it possible to increase the Software's speed of reaction to information and network security threats.
The declared purpose is achieved by:
• determining the reputation of scanned objects;
• identifying information security threats that are new and challenging to detect, and their sources;
• taking prompt measures to increase the protection of the data stored and processed by the End User with the Computer;
• reducing the likelihood of false positives;
• increasing the efficiency of Software components;
• investigating the infection of a user's computer;
• improving the performance of the Rightholder's products;
• receiving reference information about the number of objects with known reputation.

Processed Data
While KSN is enabled, the Rightholder will receive and process the following data automatically: entropy of the file being processed; heuristically derived name of the email marketer - email message sender; number of update installation error for the updater component; number of failed update installations for the updater component; phishing attack target; encryption characteristics of data package that is being sent to KSN; detect characteristics; format of the object being processed; format of the data in the request to Rightholder's infrastructure; file of the web page being processed; file of the email message being processed; segments of random access memory; integrity level for the object being processed; unique device ID; unique event ID; unique User ID in the Rightholder's systems; unique ID of the activity log for the object being processed; object distinguished name; type of user account under which the potentially malicious object was started; type of license used; type of the installed Software; Software installation type; type of the triggered Software anti-virus databases record; statistics message type; notification type, that triggered the statistic sending; type of the event that was timed out while being processed (klif/swmon); user story type; error type; checksum type for the object being processed; type of DNS query; type of executable file scan task that sends statistics; update task type; technical specifications of the applied detection technologies; text of the error message; event counter; total delay of all OS action events; total delay of all OS action events of the current type; confidence of detecting access to the phishing web service; memory stack of the Software process failure; Software health status after update; status of the license used by the Software; major and minor numbers of the interception filter that caused the interception that was timed out whilebeing processed in System Watcher; system log messages containing information about the error; fragment content of the object being processed; network interfaces list of the computer; certificate serial number; properties and checksums of the parts of the execution file; result of certificate verification; result of the module integrity check; result of status check in KSN of an object being processed; result of action with the object being processed; result of the Software action; OS edition; temporal distribution of successful KSN connections; temporal distribution of successful requests to KSN; temporal distribution of successful KSN transactions; temporal distribution of canceled requests to KSN; temporal distribution of unsuccessful KSN connections; temporal distribution of unsuccessful KSN transactions; temporal distribution of requests to KSN that timed out; operating system bit version; time difference between the first event in the queue and the current event when sending statistics package by System Watcher; queue size of the System Watcher events that were timed out while being processed; application image size; size of the object being processed; path to the object being processed; source file path; full path to parent process file used to launch the process; public key of the certificate; protocol used to exchange data with KSN; reason of detecting software by System Watcher; indicator showing that the message is a part of a bundle of messages belonging to one access to the web service; flag indicating an application which runs automatically at startup; debug detection indicator; attribute of an object being processed, that allowed to recall the false positive decision on the object; trust indicator of the processed object according to KSN; access rights for the object being processed; fragment order in the object being processed; full names of files that were accessed by the object being processed; full version of the Software; data packages of the web traffic being processed; digital certificate thumbprint of the scanned object and hashing algorithm; DNS server response; description of an object being processed as defined in the object properties; total disk space and amount currently used; total number of events that took longer than the standard time to process by System Watcher; web address being processed; objects or its parts being processed; detected file operations with the object being processed; zone index where the endpoint IP address belongs; number of the string in the script where the error has occurred; port number; number of the detected software in the System Watcher context; direction of a network connection; certificate issuer name; names of the packers that packed the object being processed; name of the created/modified OS service; name of network protocol used in the detected network attack; Software vendor name; Software name; name of the detected malware or legitimate software that can be used to damage the user's device or data; Software component name; component name; name and version of the OS; CPU model; http request method; detect location within the web traffic being processed; location where code was injected in process; processor brand; maximum allowed time for processing an event by System Watcher; local port that was attacked; local IP address; checksum of the Software key file; checksum of the user name; checksum of the object being processed; checksum of the user device name (MD5, SHA2-256, SHA1); checksum of the Software license key status confirmation; checksum of the Software activation code; checksum (SHA256) of the object being processed; checksum (MD5) of the object being processed; checksum (MD5) of the mask that blocked the web service; command line; number of update-apply cycles for anti-virus databases; number of devices/accounts covered by the Software license; number of successful KSN connections; number of successful KSN transactions; number of System Monitor events that were timed out when sending statistics package by System Watcher; number of KSN connections taken from the cache; number of waiting synchronous OS action events; number of processed OS action events; number of processed synchronous OS action events; number of new KSN connections; number of unsuccessful KSN connections; number of unsuccessful requests to KSN caused by network problems; number of unsuccessful requests to KSN caused by routing errors; number of unsuccessful requests caused by KSN being disabled in the Software settings; number of unsuccessful KSN transactions; number of software runs since the last time the file checksum was sent; number of requests for which a response was found in the local request database; number of delayed OS action events of the current type; total number of requests to KSN; number of klif events that were timed out when sending statistics package by System Watcher; file operation code; object type code; code of the event that took longer than the standard time to process by System Watcher; error code of the update task; error code; code of the error category; directory code; logon session key; encryption algorithm for the logon session key; vulnerability danger class; host source; source of the object being processed; source of the web-traffic being processed: local host or remote host; source of the decision made for the object being processed; information about Software updates; information on who signed the file being processed; information about file signature check results; information about the client that uses a network protocol (user agent); parent application name; name of the object being processed; name of the module in which the failure probably occurred; computer name on the network (domain name); certificate owner name and settings; performed commands IDs; vulnerability ID; ID of the account under which the controlled process was started; device ID; Software installation ID (PCID); identifier of the active license key status confirmation; ID of the triggered record in the Software's anti-virus databases; email message ID; ID of the KSN service accessed by the Software; ID of the certificate used to sign the header of Software license key status confirmation; parent process system ID (PID); ID of a regional activation center; process system ID (PID); protocol ID; Software ID; ID of the interception that was timed out while being processed in System Watcher; ID of data package that is being sent to KSN; window ID for the application being processed; OS ID; ID of the operation being performed on the third-party software; ID of the operation being performed by the Software; third-party software update ID; Software update ID; Software module ID; license identifier; configuration identifier; Software component ID; ID of the key from the keystore used for encryption; ID of the information model used to provide the Software license; security zone identifier extracted from the NTFS stream; Software database record ID; ID of the task in which detection was performed; user account security identifier (SID); Software categorization base ID; value of the update task TARGET filter; Software verdict on the object being processed; boot sectors of the operating system; header of the http request being processed; user actions with the interface element in the application window; license expiration date; installation date and time for the Software; date and time of creating an object being processed; date and time of creating an executable file being processed; date and time when the Software license key status confirmation was created; event date and time; date and time of the last modification of the object being processed; date and time when the anti-virus databases were last updated and applied; date and time of received event of an action in the OS; data received date and time; date and time of signing the object; time of the first launch of the object being processed; date and time when statistics stopped being received; date and time of detecting software by System Watcher; date and time when statistics started being received; date and time on the user's device; date and time of linking the executable file; date and time when the certificate expires; date and time of the OS launch; date and time of System Watcher start; release date and time of the Software's databases; date and time when the certificate was issued; Software activation date and time; data about the license for identifying a group of users of the company that purchased the license by the comment in the license properties; data of the internal log, generated by the anti-virus Software module for an object being processed; attribute data; emulation depth; storage time for object being processed; event time; object time in the buffer; processing time of the event that took longer than the standard time to process by System Watcher; database processing time of the event that took longer than the standard time to process by System Watcher; processing delay time of the event about OS action in the proactive defense subsystem; processing delay time of the event about OS action in the persistent event storage subsystem; processing delay time of the event about OS action in the behavioral analysis subsystem; timestamp of the triggered record in the Software's anti-virus databases; timestamp of the root index of available updates; timestamp of the root index of updates being downloaded; timestamp of the update component (updated version); timestamp of the component (local version); timestamp of the Software databases; external IP address; nested error occurred during the application operation; weight of the detected access to the phishing web service; emulator version; version of the operating system installed on the user's computer; version of list of revoked Software service's decisions; OS Service Pack version; version of the statistics being sent; 
Software version; OS version; OS build number; OS update number; OS edition; extended information about the OS edition; version of a certain compiler; version of the object being processed; version of the Software license key status confirmation; version of the Software's component; version of the updater component; Software activation code version; Software database record version; probability of sending statistics by System Watcher; web address from which the file that matches the process was downloaded; web address of the source of the web service request (referer); binary mask of the parameters for the object being processed; binary mask of options of the DNS query; file attributes of an object being processed; attributes of executable file being processed; CPU architecture; command line arguments for the process; algorithm for calculating the digital certificate thumbprint; calculation algorithm of public key of the certificate; address for the Software module loading; accessed address of the web service (URL, IP); MAC address of the network attack source; IP address from which the file that matches the process was downloaded; IP address that was accessed by the object being processed; IP address of the attacker; IP address of the DNS server; accessed IPv6 address of the web service; accessed IPv4 address of the web service; IP address; DNS address of the web service being accessed.

Also, in order to achieve the declared purpose with respect to preventing false positives, the Rightholder may receive trusted executable and non-executable files or their parts.

When the Software is used as a part of the Kaspersky Endpoint Detection and Response Expert (on-premise) solution, the Rightholder will additionally receive and process the following data:  user device name; ID of the device that established remote connection to the system; operating system family; the proxy server used; actions performed by the operating system task scheduler tasks; operating system task scheduler tasks start date and time; operating system task scheduler tasks execution result; service ID; operating system task scheduler tasks parameters; information about system log events: event time, name of the log where the event has been detected, type and category of event, name of the event source and event description; number of objects to be transferred; the host to which a connection has been established to transfer objects; object transfer task parameters; object transfer task ID; number of objects transferred; information about user group; volume file system type; HTTP referrer; ID of the indicator of attack (IOA); ID of the MITRE attack tactic; ID of the MITRE attack technique; name of the MITRE attack technique; name of the indicator of attack (IOA); version of the indicator of attack (IOA); unique ID of the logon session; logon session type; data about a third-party application that had caused an error (the application image file name and path, the application image file size and checksum (MD5, SHA256, SHA1), the application process identifier (PID), date and time of the application process image file compiling and creation, application process memory stack and application process memory address where an error had occurred, application uptime before the error had occurred, names, versions and checksums (MD5, SHA256, SHA1) of the application components' files); value of confidence of detecting malware or legitimate software that can be used to damage the computer or user data; sender email address or email address parts being processed; subject of the email message being processed; receiver email address or email address parts being processed; query string; query search area; checksum (SHA1) of an object being processed; date and time of signing the file; capabilities assigned to an object being processed; environment variables assigned to an object being processed; system function type recalled to fork new process; IP addresses or IP addresses checksums of the source and the destination of the network connection being processed; port numbers of the source and the destination of the network connection being processed; open flags for an object being processed; date and time when the process being processed ended; indicator showing that the digital signature of the object being processed is present and valid; error that occurred on the detect processing; type of the object detected by the Software; severity of the window prompting for user action; Software protection component operating mode; current Software settings; ID of controller mode for the USB device; shortened serial number of the hard drive; drive type; controller type of the USB device; volume of outbound traffic; HTTP/HTTPS network request indicators (request URL, open-source library type, request domain name, CND provider, request method, request start time, request packet size, total request duration, status code, response packet size, response content type, request header start time, request header end time, request body start time, request body end time, response header start time, response header end time, response body start time, response body end time, number of redirections, number of DNS resolution failures, total number of DNS resolutions, number of hosts resolved at a time, result of a single resolution, start time of a single resolution, end time of a single resolution, whether the resolution is successful, number of socket connection failures, total number of socket connections, destination address of a single connection, start time of a single connection, end time of a single connection, start time of a single handshake, end time of a single handshake, HTTP type, HTTP version, SSL type, cipher suite type, whether the connection is successful, connection failure information, request exception information and stack information when the response is abnormal).

When the Software works in a Standard mode and in an Endpoint Detection and Response Agent mode, the Rightholder will additionally receive and process the following data on the use of the Software components: Software ID derived from the license; Software activation date; Software license ID; serial number of the Software license key; Software localization; identifier of the partner organization via which the Software license order was placed; Software rebranding ID; operating status of the Software component; ID of the licensed Software; flag indicating whether participation in KSN is enabled; delay of sending the statistics.

Your Choice to Participate
Providing the above information to the KSN is voluntary. After installing the Software, the End User can at any time enable or disable the use of the KSN in the Software settings as described in the User Manual.
When the End User decides to disable the KSN, the Rightholder will not receive new data. The Rightholder may still process certain data already received under legitimate interest according to point (f) of Article 6 (1) of the EU General Data Protection Regulation (GDPR) for the purposes described in the Privacy Policy at https://www.kaspersky.com/products-and-services-privacy-policy. If the End User wishes to object to such data processing, the End User must inform the Rightholder in the manner specified in the Privacy Policy. For more information about legal bases for data processing and End User's rights and options, the End User may consult the Privacy Policy at https://www.kaspersky.com/products-and-services-privacy-policy.

© 2025 AO Kaspersky Lab