Kaspersky, like any other AV blocks connections to malicious domains. When Kaspersky analyses samples, it uses static and dynamic analysis to extract URLs and domains. They also use other methods to discover malicious sites and potentially, some third party feeds.
In addition, Kaspersky uses behavioural analysis (like all AVs), static and dynamic malware analysis, heuristics and virtually any protection method known has been deployed by Kaspersky. Their Application Control (IDS) is bespoke.
Kaspersky has a very light implementation of IPS — it is not a full blown deep packet inspection method that constantly scans the traffic for signs of attacks.
Kaspersky
is not some sort of a miracle in the cybersecurity world and is vulnerable to the following:
- Users disabling Kaspersky protection methods thinking the detection is just another detection on cracks.
- When software has been executed knowingly by happy clickers and people looking to save money on apps, this opens risks. Kaspersky, like all AVs performs behavioural monitoring in asynchronous mode. It is possible that whilst Kaspersky captures and scans the behaviour, a sophisticated and quick “Smash and Grab” attack already exfiltrates credentials, and only then Kaspersky reacts.
- The network protection relies on the domains either being too new (which would be the case when domain generation algorithms are used) or being old and known malicious. But it’s possible that attackers can create domains, leave them dormant to mature and at one point launch an attack. The domain is neither new nor it is known malicious.
- Even if Kaspersky had full blown IPS based on signatures (or IPS has been deployed for example on the router) this method is rather reactive, relies mostly on signatures and traffic patterns. Whilst it is a nice to have feature, it’s not a panacea that will completely block attackers.
In Essence, Kaspersky needs to be combined with good habits.