- What's New
- Function Overview
- Product Bulletin
- Technology Poster
- Service Overview
- Billing
- Getting Started
-
User Guide
- Using IAM to Grant Access to HSS
- Accessing HSS
- Checking the Dashboard
- Asset Management
- Risk Management
- Server Protection
- Container Protection
- Detection and Response
- Security Operations
- Installation and Configuration on Servers
-
Installation and Configuration on Containers
- Installing an Agent in a Cluster
- Installing the Agent on an Independent Container Node
- Modifying Cluster Agent Installation Information
- Managing Cluster Agents
- Viewing the Cluster Node List and Permission List
- Managing Agents on Independent Nodes
- Connecting to a Third-party Image Repository
- CI/CD Image Access Configuration
- Account Management
- Plug-in Settings
- Authorization
- Monitoring and Auditing
- Enterprise Project Management
-
Best Practices
- HSS Best Practices You May Need
-
Suggestions on How to Fix Official Disclosed Vulnerabilities Provided by HSS
- Git Credential Disclosure Vulnerability (CVE-2020-5260)
- SaltStack Remote Command Execution Vulnerabilities (CVE-2020-11651 and CVE-2020-11652)
- OpenSSL High-risk Vulnerability (CVE-2020-1967)
- Adobe Font Manager Library Remote Code Execution Vulnerability (CVE-2020-1020/CVE-2020-0938)
- Windows Kernel Elevation of Privilege Vulnerability (CVE-2020-1027)
- Windows CryptoAPI Spoofing Vulnerability (CVE-2020-0601)
- Third-Party Servers Accessing HSS Through a Direct Connect and Proxy Servers
- Connecting Third-Party Servers to HSS Through Direct Connect and VPC Endpoint
- Installing the HSS Agent Using CBH
- Using HSS to Improve Server Login Security
- Using HSS and CBR to Defend Against Ransomware
- Combining WAF and HSS to Improve Web Page Tampering Protection
- Using HSS to Scan for and Fix Vulnerabilities
- Using HSS to Prevent Weak Passwords
- Using HSS to Scan for Trojans
- Using HSS to Handle Mining Attacks
- Using HSS to Monitor the Integrity of Linux Server Files
- Using the Whitelist to Reduce False Alarms
- HSS Security Best Practices
-
API Reference
- Before You Start
- Calling APIs
-
API Description
-
Asset Management
- Collecting Asset Statistics, Including Accounts, Ports, and Processes
- Querying the Account List
- Querying Open Port Statistics
- Displaying Details About a Port
- Querying the Process List
- Querying the Software List
- Querying Automatic Startup Item Information
- Querying the Server List of an Account
- Querying the Open Port List of a Single Server
- Querying the Server List of the Software
- Querying the Service List of Auto-Started Items
- Obtaining the Account Change History
- Obtaining the Historical Change Records of Software Information
- Obtaining the Historical Change Records of Auto-started Items
- Asset Fingerprints - Process - Server List
- Asset Fingerprints - Port - Server List
- Querying the Server List of a Specified Middleware
- Querying the Middleware List
- Querying the Status of a Global Asset Scan Task
- Creating a Global Asset Scan Task
- Asset management-asset fingerprint-the server list of the kernel module
- Asset management-asset fingerprint-the server list of the web framework
- Asset management-asset fingerprint-the server list of the Web site
- Querying the Asset Fingerprint Collection Status of a Single Server
- Collecting Asset Fingerprints of a Single Server
- Asset Management - Asset Fingerprint - Kernel Module Tree on the Left
- Asset Management - Asset Fingerprint - Web Framework Navigation Tree on the Left
- Asset Management - Asset Fingerprint - Web Site Navigation Tree on the Left
- Asset Management - Asset Fingerprint - WebAppAndService Name Navigation Tree on the Left
- Asset Management - Asset Fingerprint - WebAppAndService Asset Information on the Right
-
Ransomware Prevention
- Querying the Backup Vault List
- Querying the Ransomware Protection Server List 2.0
- Adding a Protection Policy
- Deleting a Protection Policy
- Querying the Backup and Restoration Task List
- Querying Information About a Backup Policy
- Querying the Backup Policy Bound to HSS Protection Vault
- Modifying the Backup Policy Bound to Vault
- Disabling Ransomware Prevention
- Enabling Ransomware Prevention
- Querying the Protection Policy List of Ransomware
- Modifying Ransomware Protection Policies
- Querying the Servers Protected Against Ransomware
- Baseline check
- Baseline policy
- Quota Management
-
Container Management
- Querying Basic Container Information List
- Querying the Container Node List
- Querying the List of Commands Running in a Container
- Creating a Container Export Task
- Querying the Container Log List
- Querying the Protection Overview Data of a Container Node
- Changing Protection Status
- Querying the Kubernetes Cluster List
- Querying Container Details
- Querying Kubernetes Endpoint Details
- Querying the Kubernetes Endpoint List
- Querying the Basic Pod Information List
- Synchronizing Cluster Information
- Querying Kubernetes Service Details
- Querying the Kubernetes Service List
- Querying Pod Details
- Event Management
- Intrusion Detection
- Server Management
-
Container Image
- Querying the Mirror Configuration Check Report
- Querying the Check Item List of a Specified Security Configuration Item of an Image
- Querying the List of Image Security Configuration Detection Results
- Scanning Images in the Image Repository in Batches
- Querying the Local Image List
- Querying the Image List in the SWR Image Repository
- Synchronizing the Image List from SWR
- CVE Information Corresponding to the Vulnerability
- Querying Image Vulnerability Information
- Querying Container Image Operation Logs
- Querying the Container Image List
- Policy Management
- Vulnerability management
- Web Tamper Protection
- Tag Management
-
Virus Scan
- This API is used to query the list of servers available for virus scan.
- Deleting a Custom Scan Policy
- Creating a Custom Scan Policy
- Querying a Custom Scan Policy List
- Editing a Custom Scan Policy
- Exporting the Virus Scan Result List
- This API is used to handle virus scan results.
- Querying the Virus Scan Result List
- Querying Virus Scan Statistics
- Creating a Virus Scan Task
- Viewing the Virus Scan Task List
- Querying the Status of the Pay-per-use Billing Switch for Virus Scan
-
Application Protection
- Querying the Application Protection Event List
- Querying the Protection Policy List
- Querying Protection Policy Details
- Querying the Detection Rule List
- Querying Java Applications of a Protected Server
- Querying the List of Protected Servers
- Protection Data Statistics
- Querying the Status of Application Protection
- Deleting a Protection Policy
- Adding a Protection Policy
- Modifying a Protection Policy
- Enable/Disable application protection and update the protection port.
-
Whitelist Management
- Querying the Alarm Whitelist
- Querying the Login Whitelist
- Adding a Login Whitelist
- Deleting Whitelisted Login Items
- Querying the System User Whitelist
- Adding an Item to the System User Whitelist
- Modifying System User Whitelist
- Removing an Item from the System User Whitelist
- Deleting an Alarm Whitelist
-
Container Installation and Configuration
- Deleting a Cluster Daemonset
- Updating a Cluster Daemonset
- Obtaining Cluster Daemonset Information
- Creating a Cluster Daemonset
- Querying a Multi-cloud Cluster
- Creating a Multi-cloud Cluster
- Synchronizing the Access Status of a Multi-cloud Cluster
- Deleting a Multi-cloud Cluster
- Updating a Multi-cloud Cluster
- Obtaining the Agent Installation Script of a Multi-Cloud Cluster
- Parsing the Configuration File of a Multi-cloud Cluster
- Obtaining the Image Upload Command of a Multi-Cloud Cluster
- Obtaining the Deployment Template
-
Dynamic Port Honeypot
- Switching the Dynamic Port Honeypot Policy of a Server
- Disabling the Dynamic Port Honeypot Policy of a Server
- Viewing a Dynamic Port Honeypot Policy
- Editing Dynamic Port Honeypot Policy
- Viewing Dynamic Port Honeypot Policy Details
- Deleting a Dynamic Port Honeypot Policy
- Adding a Dynamic Port Honeypot Policy
- Installation and Configuration
-
Cluster Management
- Obtaining Cluster Configurations
- Creating a CCE Integrated Protection Configuration
- Querying the Number of Cluster Assets
- Obtaining Some Prompt Information
- Synchronizing Cluster Protection Events
- Querying the Cluster Component Protection Policy Templates
- Querying a Cluster Component Protection Policy Template
- Querying the Audit Log List of the Kubernetes Cluster
- Querying the Kubernetes Cluster Event List
- Uninstalling daemonset in batches
- Upgrading Cluster Daemonset in Batches
- Obtaining Container Cluster Risk Information in Batches
- Cluster risks
- Server Installation and Configuration
- Common module
- IAC risks
- Common service modules
-
Vulnerability Management
- Querying the Vulnerability List
- Exporting Information About Vulnerabilities and Their Affected Servers
- Querying the Servers Affected by a Vulnerability
- Changing the Status of a Vulnerability
- Querying Vulnerability Information About a Server
- Creating a Vulnerability Scan Task
- Querying a Vulnerability Scan Policy
- Modifying a Vulnerability Scan Policy
- Querying the Vulnerability Scan Tasks
- Querying the List of Servers Corresponding to a Vulnerability Scan Task
- Querying Vulnerability Management Statistics
- Ransomware Protection
- Security Operations
-
Cluster Protection
- Querying Cluster Protection Information
- Obtaining the List of Default Cluster Protection Policies
- Obtaining Alarm Events in All Clusters
- Modifying the Alarm Status
- Cluster Protection Overview
- Deleting a Cluster Protection Policy
- Obtaining the Cluster Protection Policies
- Creating a Cluster Protection Policy
- Modifying a Cluster Protection Policy
- Viewing Details About a Specified Policies
- Obtaining All the Protection Items of a Cluster
- Performing Operations on Cluster Protection
-
Baseline Management
- Ignoring, Unignoring, Repairing, or Verifying the Failed Configuration Check Items
- Querying the Report of a Check Item in a Security Configuration Check
- Querying the Password Complexity Policy Detection Report
- Querying the Checklist of a Security Configuration Item
- Querying the Check Result of a Security Configuration Item
- Querying the List of Affected Servers of a Security Configuration Item
- Querying the Result List of Server Security Configuration Check
- Querying the Weak Password Detection Result List
- Ignoring or Unignoring Servers that Fail the Password Complexity Check
- Querying Manual Baseline Scan Results
- Querying the Baseline Whitelist
- Added baseline whitelists.
- Deleting a Baseline Whitelist
- Modifying the Baseline Whitelist
- Querying the Baseline Whitelist
- Container Assets
-
Container Network Isolation Information
- Querying Clusters Protected by Container Security
- Querying the Network Information of a Container Cluster
- Querying the List of Container Cluster Network Policies
- Delete The Container Cluster Network Configuration Policy
- Container Cluster Network Update Configuration Policy
- Configuration Policy for Adding a Network to a Container Cluster
- Synchronizing the Latest Container Network Policies from a Cluster
- Synchronizing the latest data of a container cluster
- Synchronizing the Latest Data of Network Nodes in a Cluster
- Cluster Network Policy Overview
- Obtaining Namespaces in a Cluster
- Querying the Node List of a Container Cluster VPC Network
- Synchronizing the Latest Security Group Policies in a Cluster
- Querying the Security Group Policies Configured for Clusters Using Cloud Native Network Mode 2.0
- Creating a Security Group Policy
- Updating a Security Group Policy
- Deleting a Security Group Policy
- Querying All Security Groups in an Enterprise Project
- Querying the Workloads in a Namespace in a Cluster
- ProjectConfigs
-
Asset Management
- Appendixes
- SDK Reference
-
FAQs
-
About HSS
- What Is Host Security?
- What Is Container Security?
- What Is Web Tamper Protection?
- What Are the Relationships Between Images, Containers, and Applications?
- How Do I Use HSS?
- Can HSS Protect Local IDC Servers?
- Is HSS in Conflict with Any Other Security Software?
- What Are the Differences Between HSS and WAF?
- Can HSS Be Used Across Accounts?
- What Is the HSS Agent?
- Can HSS Be Used Across Clouds?
- Does HSS Support Version Upgrade?
- Can HSS Automatically Detect and Remove Viruses?
-
Agent
- Do I Need to Install the HSS Agent After Purchasing HSS?
- Is the Agent in Conflict with Any Other Security Software?
- How Do I Uninstall the Agent?
- What Should I Do If Agent Installation Failed?
- How Do I Fix an Abnormal Agent?
- What Is the Default Agent Installation Path?
- How Many CPU, Memory, and Disk Resources Are Occupied When the Agent Is Running?
- Do Different HSS Editions Share the Same Agent?
- How Do I View Servers Where No Agents Have Been Installed?
- How Do I Upgrade the Agent?
- What Do I Do If the HSS Upgrade Fails?
- What Resources Will Be Accessed by the Agent After It Is Installed on a Server?
- How Do I Use Images to Install Agents in Batches?
- What Do I Do If I Cannot Access the Download Link of the Windows Or Linux Agent?
- What Do I Do If Agent Upgrade Fails and the Message "File replacement failed" Is Displayed?
- What Can I Do If Agents Failed to Be Installed in Batches and a Message Is Displayed Indicating that the Network Is Disconnected?
- How Do I Verify the Connection Between My Server and the HSS Server?
- Protection
-
Vulnerability Management
- How Do I Fix Vulnerabilities?
- What Do I Do If an Alarm Still Exists After I Fixed a Vulnerability?
- Why a Server Displayed in Vulnerability Information Does Not Exist?
- Do I Need to Restart a Server After Its Vulnerabilities Are Fixed?
- Can I Check the Vulnerability and Baseline Fix History on HSS?
- What Do I Do If Vulnerability Fix Failed?
- Why Can't I Select a Server During Manual Vulnerability Scanning or Batch Vulnerability Fixing?
- What Do I Do If a Vulnerability Scan Failed?
- Do I Need to Subscribe to Ubuntu Pro to Fix Ubuntu Vulnerabilities?
-
Detection & Response
- How Do I View and Handle HSS Alarm Notifications?
- What Do I Do If My Servers Are Subjected to a Mining Attack?
- Why a Process Is Still Isolated After It Was Whitelisted?
- Why an Attack Is Not Detected by HSS?
- Can I Unblock an IP Address Blocked by HSS, and How?
- Why a Blocked IP Address Is Automatically Unblocked?
- How Often Is Malware Scan and Removal?
- How Often Are the HSS Virus Database and Vulnerability Database Updated?
- What Do I Do If an IP Address Is Blocked by HSS?
- How Do I Defend Against Ransomware Attacks?
- Why Can't I Receive Alarms After the HSS Is Upgraded?
- How Do I Add High-risk Command Execution Alarms to the Whitelist?
- Why Doesn't HSS Generate Alarms for Some Web Shell Files?
- Abnormal Logins
-
Brute-force Attack Defense
- How Does HSS Intercept Brute Force Attacks?
- How Do I Handle a Brute-force Attack Alarm?
- How Do I Defend Against Brute-force Attacks?
- How Do I Unblock an IP Address?
- What Do I Do If HSS Frequently Reports Brute-force Alarms?
- What Do I Do If a Huawei Cloud IP Address Trigger a Brute-force Attack Alarm?
- What Do I Do If the Port in Brute-force Attack Records Is Not Updated?
-
Baseline Inspection
- Why Are Weak Password Alarms Generated After the Weak Password Detection Policy Is Disabled?
- How Do I Install a PAM and Set a Proper Password Complexity Policy in a Linux OS?
- How Do I Set a Proper Password Complexity Policy in a Windows OS?
- How Do I Handle Unsafe Settings?
- How Do I View Configuration Check Reports?
- How Do I Handle a Weak Password Alarm?
- How Do I Set a Secure Password?
- Web Tamper Protection
-
Container Security
- How Do I Disable Node Protection?
- How Do I Switch from CGS to HSS?
- How Do I Enable Node Protection?
- How Do I Enable the API Server Audit for an On-Premises Kubernetes Container?
- What Do I Do If the Container Cluster Protection Plug-in Fails to Be Uninstalled?
- What Do I Do If the Cluster Connection Component (ANP-Agent) Failed to Be Deployed?
- What Do I Do If Cluster Permissions Are Abnormal?
- Failed to Upload the Image to the Private Image Repository
- What Do I Do If I Failed to Enable Protection for a CCE Cluster?
- What Do I Do If a Repository Image Scan Failed?
- Ransomware Prevention
- Region and AZ
-
Security Configurations
- How Do I Clear the SSH Login IP Address Whitelist Configured in HSS?
- What Can I Do If I Cannot Remotely Log In to a Server via SSH?
- How Do I Use 2FA?
- What Do I Do If I Cannot Enable 2FA?
- Why Can't I Receive a Verification Code After 2FA Is Enabled?
- Why Does My Login Fail After I Enable 2FA?
- How Do I Add a Mobile Number or Email Address for 2FA?
- Do I Use a Fixed Verification Code for 2FA?
- Will I Be Billed for Alarm Notifications and SMS?
- How Do I Modify Alarm Notification Recipients?
- Why No Topics Are Available for Me to Choose When I Configure Alarm Notifications?
- Can I Disable HSS Alarm Notifications?
- How Do I Modify Alarm Notification Items?
- How Do I Disable the SELinux Firewall?
-
Protection Quota
- How Do I Extend the Validity Period of HSS Quotas?
- How Do I Filter Unprotected Servers?
- Why Can't I Find the Servers I Purchased on the Console?
- What Do I Do If My Quotas Are Insufficient and I Failed to Enable Protection?
- How Do I Allocate My Quota?
- If I Change the OS of a Protected Server, Does It Affect My HSS Quota?
- Why Doesn't an HSS Edition Take Effect After Purchase?
- How Do I Change the Protection Quota Edition Bound to a Server?
- Can I Bind a Server to an HSS Quota If They Are in Different Enterprise Projects?
- When an ECS or CCE Cluster Node Is Deleted, Will They Be Unbound from Their Protection Quotas?
-
Others
- How Do I Use the Windows Remote Desktop Connection Tool to Connect to a Windows Server?
- How Do I Check HSS Log Files?
- How Do I Enable Logging for Login Failures?
- Why Can't I View All Projects in the Enterprise Project Drop-down List?
- How Do I Enable or Disable the Agent Self-protection Policy?
- What Do I Do If Windows Self-Protection Cannot Be Disabled?
- Why Is a Deleted ECS Still Displayed in the HSS Server List?
-
About HSS
- Videos
-
More Documents
-
User Guide (Ankara Region)
- Introduction
- Enabling HSS
- Server Security Dashboard
- Asset Management
- Risk Prevention
- Prevention
- Intrusion Detection
- Security Operations
- Security Report
- Installation & Configuration
- Permissions Management
-
FAQs
-
About HSS
- What Is HSS?
- What Is Container Security Service?
- What Is Web Tamper Protection?
- What Are the Relationships Between Images, Containers, and Applications?
- How Do I Use HSS?
- Can HSS Protect Local IDC Servers?
- Is HSS in Conflict with Any Other Security Software?
- What Are the Differences Between HSS and WAF?
- What Is the HSS Agent?
-
Agent FAQs
- Is the Agent in Conflict with Any Other Security Software?
- How Do I Install the Agent?
- How Do I Uninstall the Agent?
- What Should I Do If Agent Installation Failed?
- How Do I Fix an Abnormal Agent?
- What Is the Default Agent Installation Path?
- How Many CPU and Memory Resources Are Occupied by the Agent When It Performs Scans?
- Do WTP and HSS Use the Same Agent?
- How Do I View Servers Where No Agents Have Been Installed?
-
Brute-force Attack Defense
- How Does HSS Intercept Brute Force Attacks?
- How Do I Handle a Brute-force Attack Alarm?
- How Do I Defend Against Brute-force Attacks?
- How Do I Do If the Account Cracking Prevention Function Does Not Take Effect on Some Linux Accounts?
- How Do I Unblock an IP Address?
- What Do I Do If HSS Frequently Reports Brute-force Alarms?
- What Do I Do If My Remote Server Port Is Not Updated in Brute-force Attack Records?
- Weak Passwords and Unsafe Accounts
-
Intrusions
- What Do I Do If My Servers Are Subjected to a Mining Attack?
- Why a Process Is Still Isolated After It Was Whitelisted?
- What Do I Do If a Mining Process Is Detected on a Server?
- Why Some Attacks on Servers Are Not Detected?
- Can I Unblock an IP Address Blocked by HSS, and How?
- Why a Blocked IP Address Is Automatically Unblocked?
- How Often Does HSS Detect, Isolate, and Kill Malicious Programs?
- What Do I Do If an IP Address Is Blocked by HSS?
- How Do I Defend Against Ransomware Attacks?
- Abnormal Logins
- Unsafe Settings
- Vulnerability Management
-
Web Tamper Protection
- Why Do I Need to Add a Protected Directory?
- How Do I Modify a Protected Directory?
- What Should I Do If WTP Cannot Be Enabled?
- How Do I Modify a File After WTP Is Enabled?
- What Can I Do If I Enabled Dynamic WTP But Its Status Is Enabled but not in effect?
- What Are the Differences Between the Web Tamper Protection Functions of HSS and WAF?
- Container Guard Service
- Ransomware Protection
-
Security Configurations
- How Do I Clear the SSH Login IP Address Whitelist Configured in HSS?
- What Can I Do If I Cannot Remotely Log In to a Server via SSH?
- How Do I Use 2FA?
- What Do I Do If I Cannot Enable 2FA?
- Why Can't I Receive a Verification Code After 2FA Is Enabled?
- Why Does My Login Fail After I Enable 2FA?
- How Do I Add a Mobile Phone Number or Email Address for Receiving 2FA Verification Notifications?
- If I Choose to Use Verification Code for 2FA, How Do I Get the Code?
- How Do I Disable the SELinux Firewall?
- Quotas
-
Others
- How Do I Use the Windows Remote Desktop Connection Tool to Connect to a Server?
- How Do I Check HSS Log Files?
- How Do I Enable Logging for Login Failures?
- How Do I Clear an Alarm on Critical File Changes?
- Is HSS Available as Offline Software?
- How Do I Enable HSS Self-Protection?
- What Do I Do If HSS Self-Protection Cannot Be Disabled?
-
About HSS
- Change History
-
User Guide (ME-Abu Dhabi Region)
- Introduction
- Enabling HSS
- Server Security Dashboard
- Asset Management
- Risk Prevention
-
Prevention
- Application Protection
- WTP
- Ransomware Prevention
- File Integrity Monitoring
-
Container Firewalls
- Container Firewall Overview
- Creating a Policy (for a Cluster Using the Container Tunnel Network Model)
- Creating a Policy (for a Cluster Using the VPC Network Model)
- Managing Policies (for a Cluster Using the Container Tunnel Network Model)
- Managing Policies (for a Cluster Using the VPC Network Model)
- Intrusion Detection
- Security Operations
- Security Report
- Installation & Configuration
- Audit
- Permissions Management
- Manually Upgrading HSS
-
FAQs
- About HSS
-
Agent FAQs
- Is the Agent in Conflict with Any Other Security Software?
- How Do I Uninstall the Agent?
- What Should I Do If Agent Installation Failed?
- How Do I Fix an Abnormal Agent?
- What Is the Default Agent Installation Path?
- How Many CPU and Memory Resources Are Occupied by the Agent When It Performs Scans?
- Do WTP and HSS Use the Same Agent?
- How Do I View Servers Where No Agents Have Been Installed?
- What Can I Do If the Agent Status Is Still "Not installed" After Installation?
- What Do I Do If the HSS Upgrade Fails?
-
Brute-force Attack Defense
- How Does HSS Intercept Brute Force Attacks?
- How Do I Handle a Brute-force Attack Alarm?
- How Do I Defend Against Brute-force Attacks?
- What Do I Do If the Account Cracking Prevention Function Does Not Take Effect on Some Accounts for Linux Servers?
- How Do I Unblock an IP Address?
- What Do I Do If HSS Frequently Reports Brute-force Alarms?
- What Do I Do If My Remote Server Port Is Not Updated in Brute-force Attack Records?
- Weak Passwords and Unsafe Accounts
-
Intrusions
- What Do I Do If My Servers Are Subjected to a Mining Attack?
- Why a Process Is Still Isolated After It Was Whitelisted?
- What Do I Do If a Mining Process Is Detected on a Server?
- Why Some Attacks on Servers Are Not Detected?
- Can I Unblock an IP Address Blocked by HSS, and How?
- Why a Blocked IP Address Is Automatically Unblocked?
- How Often Does HSS Detect, Isolate, and Kill Malicious Programs?
- What Do I Do If an IP Address Is Blocked by HSS?
- How Do I Defend Against Ransomware Attacks?
- Abnormal Logins
- Unsafe Settings
- Vulnerability Management
-
Web Tamper Protection
- Why Do I Need to Add a Protected Directory?
- How Do I Modify a Protected Directory?
- What Should I Do If WTP Cannot Be Enabled?
- How Do I Modify a File After WTP Is Enabled?
- What Can I Do If I Enabled Dynamic WTP But Its Status Is Enabled but not in effect?
- What Are the Differences Between the Web Tamper Protection Functions of HSS and WAF?
- Container Guard Service
-
Security Configurations
- What Can I Do If I Cannot Remotely Log In to a Server via SSH?
- How Do I Use 2FA?
- Why Can't I Receive a Verification Code After 2FA Is Enabled?
- Why Does My Login Fail After I Enable 2FA?
- How Do I Add a Mobile Phone Number or Email Address for Receiving 2FA Verification Notifications?
- How Do I Disable the SELinux Firewall?
- Others
- Change History
-
User Guide (Paris)
- Introduction
- Enabling HSS
- Server Security Dashboard
-
Asset Management
- Asset Management
- Server Fingerprints
- Container Fingerprints
- Server Management
- Container Management
- Risk Prevention
-
Prevention
- WTP
- Ransomware Prevention
- File Integrity Monitoring
-
Container Firewalls
- Container Firewall Overview
- Creating a Policy (for a Cluster Using the Container Tunnel Network Model)
- Creating a Policy (for a Cluster Using the VPC Network Model)
- Managing Policies (for a Cluster Using the Container Tunnel Network Model)
- Managing Policies (for a Cluster Using the VPC Network Model)
- Intrusion Detection
- Security Operations
- Security Report
- Installation & Configuration
- Audit
- Permissions Management
- Manually Upgrading HSS
-
FAQs
- About HSS
-
Agent FAQs
- Is the Agent in Conflict with Any Other Security Software?
- How Do I Uninstall the Agent?
- What Should I Do If Agent Installation Failed?
- How Do I Fix an Abnormal Agent?
- What Is the Default Agent Installation Path?
- How Many CPU and Memory Resources Are Occupied by the Agent When It Performs Scans?
- Do WTP and HSS Use the Same Agent?
- How Do I View Servers Where No Agents Have Been Installed?
- What Can I Do If the Agent Status Is Still "Not installed" After Installation?
- What Addresses Do ECSs Access After the Agent Is Installed?
-
Brute-force Attack Defense
- How Does HSS Intercept Brute Force Attacks?
- How Do I Handle a Brute-force Attack Alarm?
- How Do I Defend Against Brute-force Attacks?
- What Do I Do If the Account Cracking Prevention Function Does Not Take Effect on Some Accounts for Linux Servers?
- How Do I Unblock an IP Address?
- What Do I Do If HSS Frequently Reports Brute-force Alarms?
- What Do I Do If My Remote Server Port Is Not Updated in Brute-force Attack Records?
- Weak Passwords and Unsafe Accounts
-
Intrusions
- What Do I Do If My Servers Are Subjected to a Mining Attack?
- Why a Process Is Still Isolated After It Was Whitelisted?
- What Do I Do If a Mining Process Is Detected on a Server?
- Why Some Attacks on Servers Are Not Detected?
- Can I Unblock an IP Address Blocked by HSS, and How?
- Why a Blocked IP Address Is Automatically Unblocked?
- How Often Does HSS Detect, Isolate, and Kill Malicious Programs?
- What Do I Do If an IP Address Is Blocked by HSS?
- How Do I Defend Against Ransomware Attacks?
- Abnormal Logins
- Unsafe Settings
-
Vulnerability Management
- How Do I Fix Vulnerabilities?
- What Do I Do If an Alarm Still Exists After I Fixed a Vulnerability?
- Why a Server Displayed in Vulnerability Information Does Not Exist?
- Do I Need to Restart a Server After Fixing its Vulnerabilities?
- Can I Check the Vulnerability and Baseline Fix History on HSS?
- What Do I Do If Vulnerability Fix Failed?
- Why Can't I Select a Server During Manual Vulnerability Scanning or Batch Vulnerability Fixing?
-
Web Tamper Protection
- Why Do I Need to Add a Protected Directory?
- How Do I Modify a Protected Directory?
- What Should I Do If WTP Cannot Be Enabled?
- How Do I Modify a File After WTP Is Enabled?
- What Can I Do If I Enabled Dynamic WTP But Its Status Is Enabled but not in effect?
- What Are the Differences Between the Web Tamper Protection Functions of HSS and WAF?
- Container Guard Service
-
Security Configurations
- How Do I Clear the SSH Login IP Address Whitelist Configured in HSS?
- What Can I Do If I Cannot Remotely Log In to a Server via SSH?
- How Do I Use 2FA?
- What Do I Do If I Cannot Enable 2FA?
- Why Can't I Receive a Verification Code After 2FA Is Enabled?
- Why Does My Login Fail After I Enable 2FA?
- How Do I Add a Mobile Phone Number or Email Address for Receiving 2FA Verification Notifications?
- If I Choose to Use Verification Code for 2FA, How Do I Get the Code?
- How Do I Modify Alarm Notification Recipients?
- Why No Topics Are Available for Me to Choose When I Configure Alarm Notifications?
- Can I Disable HSS Alarm Notifications?
- How Do I Modify Alarm Notification Items?
- How Do I Disable the SELinux Firewall?
-
Others
- How Do I Use the Windows Remote Desktop Connection Tool to Connect to a Server?
- How Do I Check HSS Log Files?
- How Do I Enable Logging for Login Failures?
- How Do I Clear an Alarm on Critical File Changes?
- Is HSS Available as Offline Software?
- Why Is a Deleted ECS Still Displayed in the HSS Server List?
- Change History
-
User Guide (Ankara Region)
- General Reference
Show all
Function Overview
- ALL
- Host Security Service (HSS)
- Server Asset Fingerprints
- Container Asset Fingerprints
- Baseline Inspection
- Vulnerability Management
- Container Image Security
- Application Protection
- Intrusion Detection
- Free Scan
- Isolation and Removal
- Ransomware Prevention
- File Isolation
- File Integrity Monitoring (FIM)
- Customized Security Policies
- Static and Dynamic Web Tamper Protection (WTP)
- Two-factor Authentication (2FA)
- SSH Login IP Whitelist
- Common Login Location/IP
- Alarm Whitelist
- Alarm Notification
- Server Group
- Security Report Subscription
- Batch Installing Agents
- Container Security Response
- Container Firewall
- Application Process Control
- Container Cluster Protection
- Virus Scan
- Account Management
- Dynamic Port Honeypot
- Container Audit
- Monthly Operation Summary
-
Host Security Service (HSS)
-
Host Security Service (HSS) is designed to protect server workloads in hybrid clouds and multi-cloud data centers. It provides host security functions, Container Guard Service (CGS), and Web Tamper Protection (WTP).
Available in all regions.
-
-
Server Asset Fingerprints
-
HSS can collect server asset fingerprints, including information about ports, processes, web applications, web services, web frameworks, and auto-started items. You can centrally check server asset information and detect risky assets in a timely manner based on the server fingerprints.
Available in all regions.
-
-
Container Asset Fingerprints
-
HSS can collect container asset fingerprints, including container clusters, services, workloads, accounts, ports, and processes. You can centrally check container asset information and detect risky assets in a timely manner based on the container fingerprints.
Available in all regions.
-
-
Baseline Inspection
-
HSS proactively checks weak password complexity policies and other unsafe settings, and provides suggestions for fixing detected risks.
Available in all regions.
-
-
Vulnerability Management
-
HSS detects Linux, Windows, Web-CMS, and application vulnerabilities and provides a vulnerability overview, including host vulnerability detection details, vulnerability statistics, vulnerability type distribution, top 5 vulnerabilities, and top 5 risky servers, helping you learn host vulnerabilities in real time.
Available in all regions.
-
-
Container Image Security
-
HSS scans the images that are running or displayed in your image list, and provides suggestions on how to fix vulnerabilities and malicious files.
Available in all regions.
-
-
Application Protection
-
HSS protects running applications. You simply need to add probes to applications, without having to modify application files.
So far, only Java applications on Linux servers can be protected.
Available in all regions.
-
-
Intrusion Detection
-
HSS reports alarms on 13 types of intrusions, including brute-force attacks, process exceptions, web shells, abnormal logins, and malicious processes. You can learn all these events on the HSS console and eliminate security risks in your assets in a timely manner.
HSS displays alarm and event statistics and their summary all on one page. You can have a quick overview of alarms, including the numbers of servers with alarms, handled alarms, unhandled alarms, blocked IP addresses, and isolated files.
The Events page displays the alarm events generated in the past 30 days. You can manually clear, ignore, whitelist, or isolate and kill alarmed items.Available in all regions.
-
-
Free Scan
-
HSS provides free health check for ECSs that are not protected by HSS, and for the CCE clusters where free health check is enabled. HSS generates security reports on the risks in servers and containers.
Available in all regions.
-
-
Isolation and Removal
-
HSS uses advanced AI and machine learning technologies and integrates a range of antivirus engines to detect and kill malicious programs on your servers.
If you enable Isolate and Kill Malicious Programs, HSS will automatically isolate and kill identified malicious programs, such as web shells, Trojans, and worms, removing security risks.
If you do not enable it, HSS will generate alarms on suspicious programs but will not handle them. You can choose Intrusions > Events, click Malicious program (cloud scan), and isolate and kill alarmed programs.Available in all regions.
-
-
Ransomware Prevention
-
HSS can detect new files and running processes in real time, control risks in new files, dynamically generate bait files for proactive defense, accurately identify ransomware, and periodically back up servers based on user-defined policies.
Available in all regions.
-
-
File Isolation
-
HSS can isolate detected threat files. Files that have been isolated are displayed on a slide-out panel on the Server Alarms page. You can click Isolated Files on the upper right corner to check them, and can recover isolated files anytime.
Available in all regions.
-
-
File Integrity Monitoring (FIM)
-
FIM checks the files in your OSs, applications, and other components for tampering, helping you meet PCI-DSS requirements. FIM compares files with their versions in the previous scan to check whether files have been modified, and whether the modifications are suspicious.
FIM checks the integrity of Linux files and manages operations on them, including:
- Create and delete files
- Modify files (changes in file size, ACLs, and content hashes)Available in all regions.
-
-
Customized Security Policies
-
HSS provides flexible policy management capabilities. Users can customize security detection rules as required to meet host security requirements in different application scenarios.
Available in all regions.
-
-
Available only in WTP edition
-
Static WTP monitors website directories in real time, backs up files, and restores tampered files using the backup, protecting websites from Trojans, malicious links, and tampering.
You can add the Windows and Linux processes you trust to the whitelist. Whitelisted processes will not be blocked by WTP functions.
Dynamic WTP protects your data while Tomcat is running, detecting dynamic data tampering in databases.Available in all regions.
-
-
Two-factor Authentication (2FA)
-
2FA requires users to provide verification codes before they log in. The codes will be sent to their mobile phones or email boxes.
You have to choose an SMN topic when you log in to an ECS where 2FA is enabled. The topic specifies the recipients of verification codes, and HSS will authenticate login users accordingly.Available in all regions.
-
-
SSH Login IP Whitelist
-
The SSH login whitelist controls SSH access to servers, effectively preventing account cracking.
After you configure an SSH login IP address whitelist, SSH logins will be allowed only from whitelisted IP addresses.
- Before enabling this function, ensure that all IP addresses that need to initiate SSH logins are added to the whitelist. Otherwise, you cannot remotely log in to your server using SSH. If your service needs to access a server, but not necessarily via SSH, you do not need to add its IP address to the whitelist.
- Exercise caution when adding an IP address to the whitelist. This will make HSS no longer restrict access from this IP address to your servers.Available in all regions.
-
-
Common Login Location/IP
-
After you configure common login locations and IP addresses, HSS will generate alarms on the logins from other login locations or IP addresses. A server can be added to multiple login locations.
Available in all regions.
-
-
Alarm Whitelist
-
To reduce false alarms, import events to and export events from the whitelist. Whitelisted events will not trigger alarms.
Available in all regions.
-
-
Alarm Notification
-
After alarm notification is enabled, you can receive alarm notifications sent by HSS to learn about security risks in your servers and web pages. Without this function, you have to log in to the management console to view alarms.
Alarm notification settings are effective only for the current region. To receive notifications from another region, switch to that region and configure alarm notification.Available in all regions.
-
-
Server Group
-
You can create a server group and add servers to it. You can check the numbers of servers, unsafe servers, and unprotected servers in a group.
Available in all regions.
-
-
Security Report Subscription
-
You can subscribe to daily, weekly, monthly, and custom reports, which are stored for six months. The reports show your server security trends and key security events and risks.
Available in all regions.
-
-
Batch Installing Agents
-
After creating a batch agent installation task, the system will install the agents automatically. You can enable protection for the target servers after the agents are installed successfully.
Available in all regions.
-
-
Container Security Response
-
You can isolate, suspend, kill, and restore containers with medium or higher security risks to prevent them from affecting secure containers.
Available in all regions.
-
-
Container Firewall
-
The HSS container firewall controls and intercepts network traffic inside and outside a container cluster to prevent malicious access and attacks.
Available in all regions.
-
-
Application Process Control
-
HSS can control different types of application processes on servers. Suspicious and trusted processes are allowed to run, and alarms are generated for malicious processes.
Available in all regions.
-
-
Container Cluster Protection
-
HSS can check for non-compliance baseline issues, vulnerabilities, and malicious files when a container image is started and report alarms on or block container startup that has not been unauthorized or may incur high risks. You can configure container cluster protection policies to block images with vulnerabilities, malicious files, non-compliant baselines, or other threats, hardening cluster security.
Available in all regions.
-
-
Virus Scan
-
The function uses the virus detection engine to scan virus files on the server. The scanned file types include executable files, compressed files, script files, documents, images, and audio and video files. You can perform quick scan and full-disk scan on the server as required. You can also customize scan tasks and handle detected virus files in a timely manner to enhance the virus defense capability of the service system.
Available in all regions.
-
-
Account Management
-
HSS can collect statistics on the servers and risks under your organization member accounts. If your account is managed by an organization, you can view the number of servers under all the member accounts in the organization, as well as the number of vulnerabilities, baselines, and alarms of the servers.
Available in all regions.
-
-
Dynamic Port Honeypot
-
The dynamic port honeypot function is a deception trap. It uses a real port as a bait port to induce attackers to access the network. In the horizontal penetration scenario, the function can effectively detect attackers' scanning, identify faulty servers, and protect real resources of the user.
Available in all regions.
-
-
Container Audit
-
Keep track of the operations and activities in your container clusters, gaining insight into every phase of the container lifecycle, including creating, starting, stopping, and destroying containers; as well as the communication and transmission between containers. Find and handle security problems through audit and analysis in a timely manner, ensuring the security and stability of container clusters.
Available in all regions.
-
-
Monthly Operation Summary
-
On the first day of each month, HSS generates a security operations summary report for last month. You can learn the asset security status and security configurations, analyze past security operations, and harden configurations and improve O&M efficiency accordingly.
Available in all regions.
-
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot