Function Overview
- ALL
- Host Security Service (HSS)
- Server Asset Fingerprints
- Container Asset Fingerprints
- Baseline Inspection
- Vulnerability Management
- Container Image Security
- Application Protection
- Intrusion Detection
- Free Scan
- Isolation and Removal
- Ransomware Prevention
- File Isolation
- File Integrity Monitoring (FIM)
- Customized Security Policies
- Static and Dynamic Web Tamper Protection (WTP)
- Privileged Processes
- Two-factor Authentication (2FA)
- SSH Login IP Whitelist
- Common Login Location/IP
- Alarm Whitelist
- Alarm Notification
- Server Group
- Security Report Subscription
- Batch Installing Agents
- Container Security Response
- Container Firewall
- Application Process Control
- Container Cluster Protection
- Virus Scan
- Account Management
- Dynamic Port Honeypot
- Container Audit
- Monthly Operation Summary
-
Host Security Service (HSS)
-
Host Security Service (HSS) is designed to protect server workloads in hybrid clouds and multi-cloud data centers. It provides host security functions, Container Guard Service (CGS), and Web Tamper Protection (WTP).
Available in all regions.
-
-
Server Asset Fingerprints
-
HSS can collect server asset fingerprints, including information about ports, processes, web applications, web services, web frameworks, and auto-started items. You can centrally check server asset information and detect risky assets in a timely manner based on the server fingerprints.
Available in all regions.
-
-
Container Asset Fingerprints
-
HSS can collect container asset fingerprints, including container clusters, services, workloads, accounts, ports, and processes. You can centrally check container asset information and detect risky assets in a timely manner based on the container fingerprints.
Available in all regions.
-
-
Baseline Inspection
-
HSS proactively checks weak password complexity policies and other unsafe settings, and provides suggestions for fixing detected risks.
Available in all regions.
-
-
Vulnerability Management
-
HSS detects Linux, Windows, Web-CMS, and application vulnerabilities and provides a vulnerability overview, including host vulnerability detection details, vulnerability statistics, vulnerability type distribution, top 5 vulnerabilities, and top 5 risky servers, helping you learn host vulnerabilities in real time.
Available in all regions.
-
-
Container Image Security
-
HSS scans the images that are running or displayed in your image list, and provides suggestions on how to fix vulnerabilities and malicious files.
Available in all regions.
-
-
Application Protection
-
HSS protects running applications. You simply need to add probes to applications, without having to modify application files.
So far, only Java applications on Linux servers can be protected.
Available in all regions.
-
-
Intrusion Detection
-
HSS reports alarms on 13 types of intrusions, including brute-force attacks, process exceptions, web shells, abnormal logins, and malicious processes. You can learn all these events on the HSS console and eliminate security risks in your assets in a timely manner.
HSS displays alarm and event statistics and their summary all on one page. You can have a quick overview of alarms, including the numbers of servers with alarms, handled alarms, unhandled alarms, blocked IP addresses, and isolated files.
The Events page displays the alarm events generated in the past 30 days. You can manually clear, ignore, whitelist, or isolate and kill alarmed items.Available in all regions.
-
-
Free Scan
-
HSS provides free health check for ECSs that are not protected by HSS, and for the CCE clusters where free health check is enabled. HSS generates security reports on the risks in servers and containers.
Available in all regions.
-
-
Isolation and Removal
-
HSS uses advanced AI and machine learning technologies and integrates a range of antivirus engines to detect and kill malicious programs on your servers.
If you enable Isolate and Kill Malicious Programs, HSS will automatically isolate and kill identified malicious programs, such as web shells, Trojans, and worms, removing security risks.
If you do not enable it, HSS will generate alarms on suspicious programs but will not handle them. You can choose Intrusions > Events, click Malicious program (cloud scan), and isolate and kill alarmed programs.Available in all regions.
-
-
Ransomware Prevention
-
HSS can detect new files and running processes in real time, control risks in new files, dynamically generate bait files for proactive defense, accurately identify ransomware, and periodically back up servers based on user-defined policies.
Available in all regions.
-
-
File Isolation
-
HSS can isolate detected threat files. Files that have been isolated are displayed on a slide-out panel on the Server Alarms page. You can click Isolated Files on the upper right corner to check them, and can recover isolated files anytime.
Available in all regions.
-
-
File Integrity Monitoring (FIM)
-
FIM checks the files in your OSs, applications, and other components for tampering, helping you meet PCI-DSS requirements. FIM compares files with their versions in the previous scan to check whether files have been modified, and whether the modifications are suspicious.
FIM checks the integrity of Linux files and manages operations on them, including:
- Create and delete files
- Modify files (changes in file size, ACLs, and content hashes)Available in all regions.
-
-
Customized Security Policies
-
HSS provides flexible policy management capabilities. Users can customize security detection rules as required to meet host security requirements in different application scenarios.
Available in all regions.
-
-
Available only in WTP edition
-
Static WTP monitors website directories in real time, backs up files, and restores tampered files using the backup, protecting websites from Trojans, malicious links, and tampering.
You can add the Windows and Linux processes you trust to the whitelist. Whitelisted processes will not be blocked by WTP functions.
Dynamic WTP protects your data while Tomcat is running, detecting dynamic data tampering in databases.Available in all regions.
-
-
Available only in WTP edition
-
After WTP is enabled, the content in the protected directories is read-only. To allow certain processes to modify files in the directories, you can add them to the privileged process list.
Only the modification made by privileged processes can take effect. Modifications made by other processes will be automatically rolled back.
Exercise caution when adding privileged processes. Do not let untrustworthy processes access your protected directories.Available in all regions.
-
-
Two-factor Authentication (2FA)
-
2FA requires users to provide verification codes before they log in. The codes will be sent to their mobile phones or email boxes.
You have to choose an SMN topic when you log in to an ECS where 2FA is enabled. The topic specifies the recipients of verification codes, and HSS will authenticate login users accordingly.Available in all regions.
-
-
SSH Login IP Whitelist
-
The SSH login whitelist controls SSH access to servers, effectively preventing account cracking.
After you configure an SSH login IP address whitelist, SSH logins will be allowed only from whitelisted IP addresses.
- Before enabling this function, ensure that all IP addresses that need to initiate SSH logins are added to the whitelist. Otherwise, you cannot remotely log in to your server using SSH. If your service needs to access a server, but not necessarily via SSH, you do not need to add its IP address to the whitelist.
- Exercise caution when adding an IP address to the whitelist. This will make HSS no longer restrict access from this IP address to your servers.Available in all regions.
-
-
Common Login Location/IP
-
After you configure common login locations and IP addresses, HSS will generate alarms on the logins from other login locations or IP addresses. A server can be added to multiple login locations.
Available in all regions.
-
-
Alarm Whitelist
-
To reduce false alarms, import events to and export events from the whitelist. Whitelisted events will not trigger alarms.
Available in all regions.
-
-
Alarm Notification
-
After alarm notification is enabled, you can receive alarm notifications sent by HSS to learn about security risks in your servers and web pages. Without this function, you have to log in to the management console to view alarms.
Alarm notification settings are effective only for the current region. To receive notifications from another region, switch to that region and configure alarm notification.Available in all regions.
-
-
Server Group
-
You can create a server group and add servers to it. You can check the numbers of servers, unsafe servers, and unprotected servers in a group.
Available in all regions.
-
-
Security Report Subscription
-
You can subscribe to daily, weekly, monthly, and custom reports, which are stored for six months. The reports show your server security trends and key security events and risks.
Available in all regions.
-
-
Batch Installing Agents
-
After creating a batch agent installation task, the system will install the agents automatically. You can enable protection for the target servers after the agents are installed successfully.
Available in all regions.
-
-
Container Security Response
-
You can isolate, suspend, kill, and restore containers with medium or higher security risks to prevent them from affecting secure containers.
Available in all regions.
-
-
Container Firewall
-
The HSS container firewall controls and intercepts network traffic inside and outside a container cluster to prevent malicious access and attacks.
Available in all regions.
-
-
Application Process Control
-
HSS can control different types of application processes on servers. Suspicious and trusted processes are allowed to run, and alarms are generated for malicious processes.
Available in all regions.
-
-
Container Cluster Protection
-
HSS can check for non-compliance baseline issues, vulnerabilities, and malicious files when a container image is started and report alarms on or block container startup that has not been unauthorized or may incur high risks. You can configure container cluster protection policies to block images with vulnerabilities, malicious files, non-compliant baselines, or other threats, hardening cluster security.
Available in all regions.
-
-
Virus Scan
-
The function uses the virus detection engine to scan virus files on the server. The scanned file types include executable files, compressed files, script files, documents, images, and audio and video files. You can perform quick scan and full-disk scan on the server as required. You can also customize scan tasks and handle detected virus files in a timely manner to enhance the virus defense capability of the service system.
Available in all regions.
-
-
Account Management
-
HSS can collect statistics on the servers and risks under your organization member accounts. If your account is managed by an organization, you can view the number of servers under all the member accounts in the organization, as well as the number of vulnerabilities, baselines, and alarms of the servers.
Available in all regions.
-
-
Dynamic Port Honeypot
-
The dynamic port honeypot function is a deception trap. It uses a real port as a bait port to induce attackers to access the network. In the horizontal penetration scenario, the function can effectively detect attackers' scanning, identify faulty servers, and protect real resources of the user.
Available in all regions.
-
-
Container Audit
-
Keep track of the operations and activities in your container clusters, gaining insight into every phase of the container lifecycle, including creating, starting, stopping, and destroying containers; as well as the communication and transmission between containers. Find and handle security problems through audit and analysis in a timely manner, ensuring the security and stability of container clusters.
Available in all regions.
-
-
Monthly Operation Summary
-
On the first day of each month, HSS generates a security operations summary report for last month. You can learn the asset security status and security configurations, analyze past security operations, and harden configurations and improve O&M efficiency accordingly.
Available in all regions.
-
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot