Functions
Based on cloud native security, SecMaster provides a comprehensive closed-loop security response process that contains log collection, intelligent analysis, situation awareness, orchestration, and response, helping you protect cloud security.
This topic introduces SecMaster editions and their function differences.
Security Overview
The Security Overview page gives you a comprehensive view of your asset security posture together with other linked cloud security services to centrally display security assessment findings.
Function Module |
Description |
---|---|
Security Overview |
|
Workspace Management
Workspaces are top-level workbenches in SecMaster. A single workspace can be bound to common projects, to support workspace operation modes in different application scenarios.
Purchased Resources
Purchased Resources centrally displays the resources purchased by the current account, making it easier for you to manage them in one place.
Function Module |
Description |
---|---|
Purchased Resources |
You can view resources purchased by the current account on the Purchased Resources page and manage them centrally. |
Security Situation
You can view the security overview on the large screen in real time and periodically subscribe to security operation reports to know the core security indicators.
Function Module |
Description |
---|---|
Situation Overview |
|
Large Screen |
SecMaster leverages AI to analyze and classify massive cloud security data and then displays real-time results on a large screen. In a simple, intuitive, and efficient way, you will learn of what risks your cloud environment are facing and how secure your cloud environment is.
NOTE:
The large screen function needs to be applied for separately. |
Security Reports |
You can generate analysis reports and periodically send them to specified recipients by email. In this way, all recipients can learn about the security status of your assets in a timely manner. |
Task Center |
All tasks that need to be processed are displayed centrally. |
Resource Manager
Resource Manager supports centralized management of assets on the cloud and assets outside the cloud and displays their security status in real time.
Function Module |
Description |
Basic |
Standard |
Professional |
---|---|---|---|---|
Resource Manager |
SecMaster can synchronize the security statistics of all resources. So that you can check the name, service, and security status of a resource to quickly locate security risks. |
× |
√ |
√ |
Function Module |
Description |
---|---|
Resource Manager |
SecMaster can synchronize the security statistics of all resources. So that you can check the name, service, and security status of a resource to quickly locate security risks. |
Risk Prevention
Risk prevention provides baseline check and vulnerability management functions to help you check cloud security configurations in accordance with many security standards. You will know where vulnerabilities are located in the entire environment.
Function Module |
Description |
---|---|
Baseline Inspection |
SecMaster can scan cloud baseline configurations to find out unsafe settings, report alerts for incidents, and offer hardening suggestions to you. |
Vulnerabilities |
SecMaster automatically synchronizes vulnerability scan result from Host Security Service (HSS), displays vulnerability scan details by category, and provides vulnerability fixing suggestions. |
Security Policies |
SecMaster supports centralized management of defense and emergency policies. |
Threat Operations
Threat operation provides various threat detection models to help you detect threats from massive security logs and generate alerts; provides various security response playbooks to help you automatically analyze and handle alerts, and automatically harden security defense and security configurations.
Function Module |
Description |
---|---|
Incidents |
SecMaster centrally displays incident details and allows you to manually or automatically convert alerts into incidents. |
Alerts |
This module provides unified data class (security operations objects) management and built-in alert reporting standards. Alerts of other cloud services such as HSS, WAF, and DDoS Mitigation are integrated and centrally displayed. |
Indicators |
This module provides unified data class (security operation objects) management and built-in threat intelligence indicator library. Security indicators from other cloud services can be accessed, and custom rules for extracting indicators are supported. |
Intelligent Modeling |
Models are supported to scan log data in pipelines. If SecMaster detects data that hits the trigger in a model, SecMaster generates an alert. |
Security Analysis |
NOTE:
You need to apply for the security analysis function separately. |
Security Orchestration
Security Orchestration supports playbook management, process management, data class management (security entity objects), and asset connection management. You can also customize playbooks and processes.
Security Orchestration allows you to flexibly orchestrate security response playbooks through drag-and-drop according to your service requirements. You can also flexibly extend and define security operation objects and interfaces.
Function Module |
Description |
---|---|
Objects |
This module helps centrally manage operation objects such as data classes, data class types, and categorical mappings. |
Playbooks |
This module supports full lifecycle management of playbooks, workflows, asset connections, and instances. |
Layouts |
This module provides a visualized low-code development platform. In this module, you can create custom layout of pages for security analysis reports, alert management, incident management, vulnerability management, baseline management, and threat indicator library management.
NOTE:
You need to separately apply for the security orchestration function in the value-added package. |
Plugins |
Plug-ins used in the security orchestration process can be managed centrally. |
Data Collection
Collects varied log data in multiple modes. After data is collected, historical data analysis and comparison, data association analysis, and unknown threat discovery can be quickly implemented.
Function Module |
Description |
---|---|
Data Collection (Collections and Components) |
Logstash is used to collect varied log data in multiple modes. After data is collected, historical data analysis and comparison, data association analysis, and unknown threat discovery can be quickly implemented. |
Data Integration
Integrates security ecosystem products for associated operations or data interconnection. After the integration, you can search for and analyze all collected logs.
Function Module |
Description |
---|---|
Data Integration |
SecMaster provides a preset log collection system. You can enable access to logs of other cloud services in just a few clicks. You can search and analyze all collected logs in SecMaster. |
Directory Customization
You can customize directories as needed.
Function Module |
Description |
---|---|
Directory Customization |
You can view in-use directories and change their layouts. |
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot