Application Catalog

To view applications catalog, open the Administration → Application Control → Applications catalog section.

Application catalog contains information on applications installed on protected stations under Windows OS connected to Dr.Web Server.

The catalog is collecting automatically in the background mode and cannot be changed by the administrator after collecting. Information on each application is sent by Dr.Web Agent to Dr.Web Server once at first activity of this application.

The catalog can be used for the following needs:

Get information on installed applications on the network stations.

Create deny and allow rules. Using of the catalog simplifies the process of the rules creation, since all information on application is filled automatically based on data about the selected known application.

Filling Application Catalog

To activate sending the information for the application catalog from the stations

1.In the Anti-virus network section in the network tree, select station or station group with Application Control installed from which you want to receive information on applications installed.

2.In the control menu, select Windows → Dr.Web Agent if you selected a group, or Dr.Web Agent if you selected a station.

3.On the General tab, set the Track Application Control events flag to track all processes activity at stations detected by Application Control and send events to Dr.Web Server. If there is no connection with Dr.Web Server, events are collected and sent upon connect. If the flag is cleared, only processes blockings can be sent (depending on the settings in the Dr.Web Server configuration).

4.Click Save.

To activate collecting the information for the application catalog at Dr.Web Server

1.Open the Administration → Dr.Web Server configuration section.

2.Go to the Statistics tab and set one of the following options:

Application Control statistics on processes activity to receive and write information on any activity of all processes: either allowed or prohibited to launch by Application Control. Setting this option will enable registration of applications in the catalog, as long as at least one profile is created and assigned, with one or several categories of functional analysis criteria selected.
Before creating the profiles and assigning them to stations of anti-virus network, all applications are allowed to be launched.

Application Control statistics on processes blocking to receive and write information on activity of all processes prohibited to launch by Application Control. For this option, applications will be written to the catalog only after creating profiles by the settings of which application launch will be blocked, and assigning these profiles on stations of anti-virus network.

info

The Application Control statistics on processes activity flag may significantly increase resource intensity of statistics collecting over all anti-virus network.

3.Click Save.

4.Restart Dr.Web Server.

5.After restarting, Dr.Web Server starts collecting statistics according to the specified settings on applications launch received from all stations with Application Control installed.

Creating Rules from Application Catalog

To create a new rule basing on the data from the application catalog

1.In the Application catalog section, select a row with the application for which you want to create the rule for controlling the launch.

2.The table row click opens the window with information on the selected application.

3.Click Create rule.

4.The window for creation of a new rule will be opened. Specify the following settings:

a)In the Profile name drop-down list, select the Application Control profile for which the rule will be created.

b)In the Rule name filed, specify the name of creating rule.

c)For the Rule type option, select the type of creating rule: deny or allow.

d)For the Operation mode option, select the operation mode of the creating rule (corresponds the Switch rule to test mode flag at rule creation in a profile):
If you want to check the rule operation, select the Test option. Applications will not be controlled at stations, but the activity log will be written as for enabled settings. Application launch and block results based on a rule in test mode will be displayed in the Application Control Events section.
With the Active option, the rule operates in active mode and blocks applications at stations by specified rule settings (see also modes of profiles operation).

e)In the Prohibit the launch of applications on the following criteria/Allow the launch of applications on the following criteria section (depending on the rule type selected at step 4c), the fields will be automatically specified in accordance with the applications on the base of which the rule is creating. If necessary, you can edit the settings.

5.Click Save. The rule will be created in the specified profile of the Application Control.