ksn_en

download ksn_en

of 5

Transcript of ksn_en

  • 8/12/2019 ksn_en

    1/5

    Kaspersky Security Network Statement

    A. INTRODUCTION

    Please read this document thoroughly. It provides important information that youshould be acquainted with before continuing to use our services or software. Wereserve the right to modify this Statement at any time by making changes to this page.

    Kaspersky Lab ZAO (further Kaspersky Lab) has created this Statement in order toinform and disclose its data gathering and dissemination practices for Kaspersky Endpoint Security 10 for Windows.

    Kaspersky Lab has a strong commitment to providing superior service to all of our customers and particularly respecting your concerns about Data Processing.

    This Statement contains numerous general and technical details describing the steps we take to respect your Data Processing concerns. Meeting your needs and expectations forms the foundation of everything we do - including protecting your Data.

    The Kaspersky Security Network service allows users of Kaspersky Lab security products from around the world to help facilitate identification and reduce the time it takes to provide protection against new ("in the wild") and complex securi

    ty threats and their sources, intrusion threats, as well as increasing the protection level of information stored and processed by the computer's user. This information contains no personally identifiable information about the user and is utilized by Kaspersky Lab for no other purposes but to enhance its security products and to further advance solutions against malicious threats and viruses.

    By participating in Kaspersky Security Network, you and the other users of Kaspersky Lab security products from around the world contribute significantly to a safer Internet environment.

    Legal Issues (if applicable)

    Kaspersky Security Network may be subject to the laws of several jurisdictions b

    ecause its services may be used in different jurisdictions, including the UnitedStates of America. Kaspersky Lab shall disclose information without your permission when required by law, or in good-faith belief that such action is necessaryto investigate or protect against harmful activities to Kaspersky Lab guests, visitors, associates, property or to others. As mentioned above, laws related todata and information processed by Kaspersky Security Network may vary by country.

    Kaspersky Security Network shall duly inform the users concerned when initiallyprocessing the above-mentioned information of any sharing of such information and shall allow these Internet users to opt in (in the EU Member States and othercountries requiring opt-in procedures) or opt out (for all other countries) online from the commercial use of this data and/or the transmission of this data to

    third parties.

    Kaspersky Lab may be required by law enforcement or judicial authorities to provide some information to appropriate governmental authorities. If requested by law enforcement or judicial authorities, we shall provide this information upon receipt of the appropriate documentation. Kaspersky Lab may also provide information to law enforcement to protect its property and the health and safety of individuals as permitted by statute.

    B. RECEIVED INFORMATION

  • 8/12/2019 ksn_en

    2/5

    * Date of installation and activation of the software, the full version of the software, including the information about the installed updates, software localization;

    * Information about your computer software, including operating system and service packs installed, kernel objects, drivers, services, Internet Explorer extensions, printing extensions, Windows Explorer extensions, downloaded program files,active setup elements, control panel applets, host and registry records, browser types and e-mail clients that are generally not personally identifiable;

    * Information about your computer hardware, including the hash sum of the HDD serial number;

    * Data related to the software updates that are used to fix errors in or to change the functionality of the software installed on the users computers, in additionto the data about the return codes received after installing the software updates.

    * Information about the status of your computer's antivirus protection includinginformation about the Anti-virus database used by the Software, the statisticaldata about updates and connections with Rightholders services; task ID and ID of the software components that perform the scans;

    * Information about files downloaded by the user (URL and IP address, attributes, file size, information about process that initiated download, digital signature of a file, URL, where the detection occurred, the number of scripts on the page in which the load was detected, information about completed http-requests andresponses to them );

    * Information about applications and their modules run by the user including MD5hash sums, size, attributes, date created, information about PE headers, compression utilities used information, code of the account that is running the process, command line options, information about files names and their modules

    * Information about all of the potentially harmful objects and actions, including the name of the detected object and the full path to the object on the compute

    r checksum processed files (MD5), the date and time of detection, URL-address and IP-address from where it was downloaded, the name and size of infected files and their paths, the packer, file type code, the ID file format, a list of the malware activities and decisions of the Software and the User on them, the ID of antivirus database used for detection, the name of the threat detected by the classification system of Kaspersky Lab, a checksum (MD5), the name and attributes of the executable file of the application, which has used an infected message ora link, impersonated host IP-address (IPv4 and IPv6) blocked object, the entropyof the file, startup attribute, timestamp of the first detection in the system,information about the file and its associated operating system objects before and after the action on the file (moving, copying, restoration), the number of launches of the file since the last sending of statistics;

    * Information about scanned objects, including the assigned trust group, and / or from which the file is moved, the reason for which the file is placed in thiscategory;

    * Information about vulnerabilities, including the ID of the vulnerability in the database of vulnerabilities, vulnerability danger level and detection status;

    * information on the implementation of emulation of an executable file, including the version of the emulator component, the depth of emulation, the statisticsand the characteristics vectors acquired during emulation of the scanned object,

  • 8/12/2019 ksn_en

    3/5

    the real and the virtual size of the scanned section of the object and the number of sections, the number of unique logical blocks in the file and the frequency of repeat of such blocks;

    * IP-address of the attacking computer, the port number on which the attack wasdirected, IP protocol identifier, target of attack (the name of the organization, web-site), the ID type of transmitted and received packets, the flag of the reaction to the attack;

    * service information of the software, including the compiler version, silent detect flag (a special verdict on the scanned object), the version of the statistics data set, the identifier of the conditions for the statistics gathered, and an indication whether the software works in interactive mode.

    * The Kaspersky Security Network service may process and submit whole files, which might be used by criminals to harm your computer and/or their parts, to Kaspersky Lab for additional examination;Additionally, for the purposes of the prevention and investigation of incidentsoccurred, executable and non-executable trusted files can be sent, as well as reports on the activities of the application, memory pages and boot sectors of theoperating system

    In order to increase the level of support and monitoring of the defined level of

    software protection, the User agrees to provide the following information aboutthe results of testing software operability after applying of updates:

    - The result of the update installation, including any error codes that occurredduring the installation process;- Information about any currently installed anti-virus databases;- Duration since the installation of last update;- Identifier of the executed self-test script and the completion status of the test;- CPU usage data;- The number of active streams and streams in standby state;- Memory usage data (Private Bytes, Non-Paged Pool);- The number of product dumps and system dumps (BSOD) since installing the softw

    are and since the last update, including the identifier of the product module wherein the crash occurred, as well as the production process crash stack;- The version of the installed software, including the version of the Nagent component;- The set of installed software components, including the version of the installed encryption module and the status of each component;- The operating system version, including the installed system updates.

    Securing the Transmission and Storage of Data

    Kaspersky Lab is committed to protecting the security of the information it processes. The information processed is stored on computer servers with limited andcontrolled access. Kaspersky Lab operates secure data networks protected by indu

    stry-standard firewall and password protection systems. Kaspersky Lab uses a wide range of security technologies and procedures to protect information from threats such as unauthorized access, use, or disclosure. Our security policies are periodically reviewed and enhanced as necessary, and only authorized individualshave access to the data that we process. Kaspersky Lab takes steps to ensure that your information is treated securely and in accordance with this Statement. Unfortunately, no data transmission can be guaranteed secure. As a result, while we strive to protect your data, we cannot guarantee the security of any data youtransmit to us or from our products or services, including without limitation Kaspersky Security Network, and you use all these services at your own risk.

  • 8/12/2019 ksn_en

    4/5

    We treat the data we process as confidential information; it is, accordingly, subject to our security procedures and corporate policies regarding protection anduse of confidential information. All Kaspersky Lab employees are aware of our security policies. Your data is only accessible to those employees who need it inorder to perform their jobs. Any stored data will not be associated with any personally identifiable information. Kaspersky Lab does not combine the data stored by Kaspersky Security Network with any data, contact lists, or subscription information that is processed by Kaspersky Lab for promotional or other purposes.

    C. USE OF THE PROCESSED DATA

    Kaspersky Lab processes the data in order to analyze and identify the source ofpotential security risks, and to improve the ability of Kaspersky Lab's productsto detect malicious behavior, fraudulent websites, crimeware, and other types of Internet security threats to provide the best possible level of protection toKaspersky Lab customers in the future.

    Disclosure of Information to Third Parties

    Kaspersky Lab may disclose any of the information processed if asked to do so bya law enforcement official as required or permitted by law, in response to a subpoena or other legal process or if we believe in good faith that we are required to do so in order to comply with applicable law, regulation, subpoena, or othe

    r legal process or enforceable government request. Kaspersky Lab may also disclose information when we have reason to believe that disclosing this information is necessary to identify, contact or bring legal action against someone who may be violating this Statement, the terms of your agreements with the Kaspersky Labor to protect the safety of our users and the public or under confidentiality and licensing agreements with certain third parties which assist us in developing,operating and maintaining the Kaspersky Security Network. In order to promote awareness, detection and prevention of Internet security risks, Kaspersky Lab mayshare certain information with research organizations and other security software vendors. Kaspersky Lab may also make use of statistics derived from the information processed to track and publish reports on security risk trends.

    D. DATA PROCESSING - RELATED INQUIRIES AND COMPLAINTS

    Kaspersky Lab takes and addresses its users' Data Processing concerns with utmost respect and attention. If you believe that there was an instance of non-compliance with this Statement with regard to your information or data, or you have other related inquiries or concerns, you may write or contact Kaspersky Lab by email: [email protected].

    In your message, please describe in as much detail as possible the nature of your inquiry. We will investigate your inquiry or complaint promptly.

    CHOICES AVAILABLE TO YOU

    In case of refusal to participate in KSN the above data is not transmitted. The

    data is processed and stored in a restricted and protected partition on the user's computer. This data cannot be restored after uninstallation. If you agree toparticipate in KSN, the data is transferred to Kaspersky Lab for the above purposes.

    The resulting information is protected by Kaspersky Lab in accordance with statutory requirements and applicable rules of Kaspersky Lab.Kaspersky Lab uses the information only in anonymous form and in the form of aggregate statistics data. These general statistics are generated automatically from the source of the information and do not contain personal data and other confi

  • 8/12/2019 ksn_en

    5/5

    dential information. Initial information received is stored in an encrypted formand is destroyed upon accumulation (twice a year). General statistics are keptindefinitely.

    Participation in Kaspersky Security Network is optional. You can activate and deactivate the Kaspersky Security Network service at any time by altering the Feedback settings on your Kaspersky Lab product's option's tab. Please note, however, if you choose to deactivate the Kaspersky Security Network service, we may notbe able to provide you with some of the services dependent upon the processingof this data.

    We also reserve the right to send infrequent alert messages to users to inform them of specific changes that may impact their ability to use our services that they have previously signed up for. We also reserve the right to contact you if compelled to do so as part of a legal proceeding or if there has been a violationof any applicable licensing, warranty or purchase agreements.

    Kaspersky Lab is retaining these rights because in limited cases we feel that wemay need the right to contact you as a matter of law or regarding matters thatmay be important to you. These rights do not allow us to contact you to market new or existing services if you have asked us not to do so, and issuance of thesetypes of communications is rare.

    (c) 2013 Kaspersky Lab ZAO. All Rights Reserved.