Detecting and Handling Abnormal AKs/SKs in an OBS Bucket
Scenarios
You can use DSC credential leakage detection to check whether there are plaintext AKs in OBS data, and whether OBS data is accessed by abnormal AKs. You need to check abnormal AKs and alarm events, and promptly confirm and handle leaked AKs and risky behaviors involving abnormal AK access to OBS data, to prevent AK leakage and abuse, which may cause unauthorized access to and leakage of OBS data.
Solution Architecture
This section describes how to use DSC credential leakage detection by simulating a scenario where a plaintext AK is detected in an OBS bucket and an alarm is reported when a leaked AK is used to access public read files in OBS. It also describes how to detect and handle AK leakage and abnormal AK access alarms in OBS buckets to improve OBS data security.

Perform the following steps to report and handle an alarm when an abnormal AK accesses OBS data:
- Creating an OBS bucket and uploading files: Create an OBS bucket and upload example files, including a file that stores the AK information.
- Authorizing access to OBS buckets and interconnecting with DSC: OBS data can be accessed only when OBS buckets are authorized to interconnect with DSC.
- Creating a credential leakage detection task: Ensure that DSC can detect AK leakage and abnormal access to OBS buckets.
- Viewing and handling AK leakage risk events: DSC detects AK leakage and generates a risk event, helping you view event details and handle the event in a timely manner.
Prerequisites
- You have purchased DSC professional edition and enabled credential leakage detection.
- You have enabled OBS.
- An IAM user with AccessKey ID and AccessKey Secret configured is available to simulate AK leakage and abnormal access.
For details, see Creating a User and Assigning Permissions.
Step 1: Create an OBS Bucket and Upload Files
Creating an OBS Bucket
- Go to the OBS console, and choose Buckets from the navigation pane on the left.
- Click Create Bucket in the upper right corner.
- On the Create Bucket page, set the parameters below, retain default settings for other parameters, and click Create Now.
Set Region to that of the purchased DSC, disable Block Public Access, and set Bucket Policy to Public Read.
For details about how to create an OBS bucket, see Creating an OBS Bucket.
Uploading Files to an OBS Bucket
- Create a test.txt file, enter the AK and SK of the prepared IAM user, and save the file.
accessKey: DSCxxxxxxxxxxxxxxxxxxxxx accessSecret: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Click the OBS bucket name in the bucket list on the OBS Console.
- On the Objects page, click Upload Object.
- Click Add File, select the test.txt file created in 1, click Open, and wait until the file is uploaded. Retain default settings for other parameters and click OK.
Step 2: Authorize Access to the OBS Bucket and Interconnect with DSC
- Log in to the DSC console.
- Choose . In the upper left corner of the displayed page, click Modify next to Cloud Asset Authorization. The Authorize Access to Cloud Assets page is displayed.
- On the displayed page, enable OBS asset authorization.
- Return to the Asset Management page, and click OBS under OBS. The OBS asset list is displayed.
- Click Add User-built Bucket in the upper left corner. In the displayed dialog box, select the OBS buckets to be added.
- Click OK. If the added OBS bucket is displayed in the list, the adding is successful.
Step 3: Create a Credential Leakage Detection Task
- On the DSC console, choose from the navigation pane.
- Enable credential leakage detection. In addition, create a service agency with the Security Administrator role to query the user AK list and user list.
- In the Inspection Tasks tab, click Create Task in the upper left corner.
- Enter a task name, set Data Source to OBS, select the created OBS bucket, retain default settings for other parameters, and click OK.
Step 4: View and Handle an AK Leakage Event
- On the DSC console, choose from the navigation pane.
- In the Credential Leakage tab, view Total AK Leakages and OBS Leakages under AK Leakage Statistics (Last 30 Days).
- In the Inspection Tasks tab, view the assets whose AKs are leaked under the current account.
- Disable the AKs of the current master account and its IAM users. For details, see Disabling an Access Key.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot