Top
Systemwalker Desktop Keeper User's Guide for Administrator
FUJITSU Software

6.1 Operation Patterns

The operation patterns when performing an emergency procedure for a client are described below.

Operation pattern 1: The administrator performs an emergency procedure

Performing an emergency procedure

Description

  1. The administrator issues an emergency procedure request to a client (CT) where a security risk was detected.

  2. The procedure below is performed for the client (CT):

    • The emergency procedure settings policy is applied

    • The network is disabled

    • A notification that a security risk has been detected is displayed

  3. The administrator is notified by email that the emergency procedure request to the client (CT) has been completed.

Canceling an emergency procedure

Description

  1. The administrator generates the emergency procedure cancellation code.

  2. The administrator contacts the client (CT) user with the emergency procedure cancellation code.

  3. The client (CT) user cancels the emergency procedure.

  4. The Management Server is notified that the emergency procedure was canceled for the client (CT).

  5. The administrator is notified by email that the emergency procedure was canceled for the client (CT).

Operation pattern 2: A malware infection is detected by the detection product (the network is blocked by the detection product)

Performing an emergency procedure

Description

  1. The detection product detects malware.

  2. The network is blocked by the detection product.

  3. The detection product notifies the Systemwalker Desktop Keeper Management Server that malware has been detected.

  4. The administrator is notified by email that malware has been detected.

  5. The administrator instructs the client (CT) user to perform the emergency procedure.

  6. The client (CT) user performs the emergency procedure for the target client (CT).

    The procedure below is performed for the target client (CT):

    • The emergency procedure settings policy is applied

    • The network is disabled

    • A notification that a security risk has been detected is displayed

Detection product canceling the network blockage

Description

  1. The network administrator (detection product administrator) is requested to cancel the network blockage.

  2. The network blockage is canceled using the detection product console.

  3. The network blockage is canceled for the target client (CT).

Canceling an emergency procedure

Description

  1. The administrator generates the emergency procedure cancellation code.

  2. The administrator contacts the client (CT) user with the emergency procedure cancellation code.

  3. The client (CT) user cancels the emergency procedure.

  4. The Management Server is notified that the emergency procedure was canceled for the client (CT).

  5. The administrator is notified by email that the emergency procedure was canceled for the client (CT).

Operation pattern 3: A malware infection is detected by the detection product (the network is not blocked by the detection product)

Performing an emergency procedure

Description

  1. The detection product detects malware.

  2. The detection product notifies the Systemwalker Desktop Keeper Management Server that malware has been detected.

  3. The procedure below is performed for the target client (CT):

    • The emergency procedure settings policy is applied

    • The network is disabled

    • A notification that a security risk has been detected is displayed

  4. The administrator is notified by email that the emergency procedure request to the client (CT) has been completed.

Canceling an emergency procedure

Description

  1. The administrator generates the emergency procedure cancellation code.

  2. The administrator contacts the client (CT) user with the emergency procedure cancellation code.

  3. The client (CT) user cancels the emergency procedure.

  4. The Management Server is notified that the emergency procedure was canceled for the client (CT).

  5. The administrator is notified by email that the emergency procedure was canceled for the client (CT).