Kaspersky Unified Monitoring and Analysis Platform

NCIRCC integration

In the KUMA web interface, you can create a connection to the National Computer Incident Response & Coordination Center Incidents (hereinafter referred to as "NCIRCC"). This will let you export incidents registered by KUMA to NCIRCC. Integration is configured under SettingsNCIRCC in the KUMA web interface. All fields that you fill out in the settings section are automatically sent to the NCIRCC data submission form.

Data in KUMA and NCIRCC is synchronized every 5-10 minutes.

To create a connection to NCIRCC:

  1. In the KUMA web interface, open SettingsNCIRCC.
  2. In the URL field, enter the URL for accessing NCIRCC.
  3. Under Token, create or select an existing secret with the API token that was issued to your organization for a connection to NCIRCC:
    • If you already have a secret, you can select it from the drop-down list.
    • If you want to create a new secret:
      1. Click the plus () icon and specify the following settings:
        • Name (required)—unique name of the resource you are creating. The name must contain 1 to 128 Unicode characters.
        • Token (required)—token that was issued to your organization for a connection to NCIRCC.
        • Description—service description: up to 256 Unicode characters.
      2. Click Save.

      The secret containing the token for connecting to NCIRCC will be created. It is saved under ResourcesSecrets and is owned by the main tenant.

    You can change the selected secret by clicking the pencil () icon.

  4. In the Company scope drop-down list, select the required value.
  5. In the Company name field, specify the name of the company for which you are configuring the integration.
  6. In the Location drop-down list, specify the location of your company.
  7. In the Root CA section of settings, create or select an existing secret:
    • If you already have a secret, you can select it from the drop-down list.
    • If you want to create a new secret:
      1. Click the plus () icon and specify the following settings:
        • Name (required)—unique name of the resource you are creating. The name must contain 1 to 128 Unicode characters.
        • Type (required)—the type of secret.
        • Certificate file—click Upload certificate file and select the certificate of the intermediate certification authority that is downloaded and installed on the KUMA Core server.

          Download and install the certificate of the intermediate certification authority.

          To install and trust the certificate of the intermediate certification authority on the KUMA Core server:

          1. Follow the NCIRCC account link. For example, https://lk.cert.gov.ru.
          2. Right-click to call up the View site details context menu to the left of the link in the address bar.
            • If you are using an encrypted connection, in the context menu, select Connection is secure and in the drop-down list under Certificate is valid, click the Show certificate link.
            • If you are using an unencrypted connection, in the menu, click Certificate details.

            Depending on your browser, the position of the menu and the order of items may differ.

          3. In the displayed Certificate Viewer window, under Issued By, in the Common Name (CN) field you can find the name of the certificate that you need. For example, GlobalSign GCC R6 AlphaSSL CA 2023.

            Remember the name of the certificate because you will need to download it at the next step.

          4. Click the https://support.globalsign.com/ca-certificates/intermediate-certificates/alphassl-intermediate-certificates link, find the certificate from step 3, and click "View as BASE64".
          5. Paste the displayed certificate strings into a file and add the file with the certificate strings as the secret in KUMA.
          6. After installing the certificate, restart the KUMA Core server.

          As a result, the certificate is installed and you can proceed with configuring the integration.

        • Description—service description: up to 256 Unicode characters.
      2. Click Save.

      The secret with the certificate of the intermediate certification authority is created. It is saved under ResourcesSecrets and is owned by the main tenant.

    You can change the selected secret by clicking the pencil () icon.

  8. If necessary, under Proxy, create or select an existing proxy server that must be used when connecting to NCIRCC.
  9. Click Save.

KUMA is now integrated with NCIRCC. Now you can export incidents to it. You can click the Test connection button to make sure that a connection with NCIRCC is established.

You can use the Disabled check box to enable or disable integration.

Possible errors

If the https://lk.cert.gov.ru/api/v2/incidents? x509: certificate signed by unknown authority error is returned when you configure integration with NCIRCC, download and install the certificate of the intermediate certification authority on the KUMA Core server.

To install and trust the certificate of the intermediate certification authority on the KUMA Core server:

  1. Follow the NCIRCC account link. For example, https://lk.cert.gov.ru.
  2. Right-click to call up the View site details context menu to the left of the link in the address bar.
    • If you are using an encrypted connection, in the context menu, select Connection is secure and in the drop-down list under Certificate is valid, click the Show certificate link.
    • If you are using an unencrypted connection, in the menu, click Certificate details.

    Depending on your browser, the position of the menu and the order of items may differ.

  3. In the displayed Certificate Viewer window, under Issued By, in the Common Name (CN) field you can find the name of the certificate that you need. For example, GlobalSign GCC R6 AlphaSSL CA 2023.

    Remember the name of the certificate because you will need to download it at the next step.

  4. Click the https://support.globalsign.com/ca-certificates/intermediate-certificates/alphassl-intermediate-certificates link, find the certificate from step 3, and click "View as BASE64".
  5. Paste the displayed certificate strings into a file and add the file with the certificate strings as the secret in KUMA.
  6. After installing the certificate, restart the KUMA Core server.

As a result, the certificate is installed and you can proceed with configuring the integration.

See also:

Interaction with NCIRCC

Page top
[Topic 221777]