Auditing and Generating Alarms for OBS Operation Risks
Scenarios
OBS uses server-side encryption to encrypt stored static data. To prevent encryption rules from being deleted by mistake, thereby causing data leakage, you can use DSC to monitor OBS data activities, monitor and record encryption rule changes in OBS buckets in real time, and display the monitoring results on the abnormal event handling page. You can handle the abnormal events as required.
Solution Architecture
In this example, server-side encryption is enabled for an OBS bucket. After this configuration is deleted, an alarm is reported in real time. The security administrator can view the current operation logs in a timely manner to check whether the account and source IP address for deleting server-side encryption are normal and handle the issue.
To complete data risk auditing and alarming, perform the following steps:
- Creating an OBS bucket: Create an OBS bucket and enable server-side encryption.
- Authorizing access to the OBS bucket and interconnecting with DSC: Authorize DSC to access the OBS bucket. Ensure that DSC can audit the OBS bucket logs.
- Creating an OBS sensitive data identification task: Create a sensitive data identification task on DSC to identify sensitive data in the OBS bucket and classify the data.
- Enabling OBS audit: Establish a data collection link between DSC and OBS. In this way, DSC can collect activity logs of OBS and files. After an audit rule is triggered, an alarm is reported to DSC.
- Viewing and handling OBS audit risk items: Analyze alarm event logs to determine whether the current operation poses a threat to the OBS data security, and handle the issue promptly.
Prerequisites
- You have purchased DSC.
- You have enabled OBS.
Step 1: Create an OBS Bucket
- Go to the OBS console, and choose Buckets from the navigation pane on the left.
- Click Create Bucket in the upper right corner.
- On the Create Bucket page, set the parameters below, retain default settings for other parameters, and click Create Now.
- Region: Select the region where DSC is purchased.
- Storage Class: Select Standard.
- Block Public Access: Enable this function.
- Server-Side Encryption: Enable this function.
For details about how to create an OBS bucket, see Creating an OBS Bucket.
Step 2: Authorize Access to the OBS Bucket and Interconnect with DSC
- Log in to the DSC console.
- Choose . In the upper left corner of the displayed page, click Modify next to Cloud Asset Authorization. The Authorize Access to Cloud Assets page is displayed.
- On the displayed page, enable OBS asset authorization.
- Return to the Asset Management page, and click OBS under OBS. The OBS asset list is displayed.
- Click Add User-built Bucket in the upper left corner. In the displayed dialog box, select the OBS buckets to be added.
- Click OK. If the added OBS bucket is displayed in the list, the adding is successful.
Step 3: Create an OBS Sensitive Data Identification Task
OBS auditing depends on the sensitive data identification result. Therefore, you need to create a sensitive data identification task before performing OBS auditing.
- In the navigation pane on the left, choose Classification and Grading > Tasks.
- Click Create Task in the upper left corner.
- On the Create Task page, set the following parameters and retain default settings for other parameters.
- Task Name: Enter a custom task name.
- Data Source: Select the name of the OBS bucket to be audited.
- Retain default settings for parameters under Rule Match.
- Click OK. A message is displayed indicating successful task creation.
After the task is created, the scanning automatically starts. You can view the task progress in the Status column.
Step 4: Enable OBS Audit
After OBS audit is enabled, you will be charged for reading and writing logs using the logging function of OBS. For details about the fees, see Requests.
- In the navigation pane on the left, choose .
- Click . The OBS asset list page is displayed.
- Locate the OBS asset and click Enable Audit in the Operation column. In the displayed dialog box, click OK.
Step 5: View and Handle OBS Audit Risk Items
- In the navigation pane on the left, choose Data Audit > OBS Security Audit.
- In the upper right corner of the list, select a time range. It can be Last 30 minutes, Last 3 hours, Last 24 hours, Last 7 days, or Last 30 days, or a custom period. You can filter events by type or status. For details, see Table 1.
Table 1 Parameters of detected risky behaviors Parameter
Description
User ID
ID of a resource owner
Event Type
DSC classifies abnormal events into the following three types:- Unauthorized data access
- Access sensitive files without granted permissions.
- Download sensitive files.
- Abnormal data operations
- Update sensitive files.
- Append data to sensitive files.
- Delete sensitive files.
- Copy sensitive files.
- Abnormal data management
- When a bucket is added, the system detects that the bucket is a public read or a public read/write bucket.
- When a bucket is added, the system detects that the access/ACL access permissions of a private bucket are granted for anonymous users or registered user groups.
- The policy of a bucket containing sensitive files is changed or deleted.
- The ACL of a bucket containing sensitive files is changed or deleted.
- The cross-region replication configuration of a bucket containing sensitive files is modified or deleted.
- The ACL of a sensitive file is modified or deleted.
Event Name
Event that causes an exception
Alarm Time
Time when an exception occurs
Status
Status description is as follows:
- Unhandled: indicates that an abnormal event is not handled.
- Confirmed Violation: indicates that a handled abnormal event causes an exception.
- Confirmed Non-violation: indicates that a handled abnormal event does not cause any exceptions.
- Unauthorized data access
- Locate an abnormal event and click View Details in the Operation column to view the event details.
- In the Operation column of the abnormal event, click Handle to handle the event. The handling method is as follows:
- If you select This event is a violation., the event is confirmed as a violation. If the event is not handled, DSC will continue to report alarms.
- If you select This event is not a violation., the event is confirmed as normal and does not need to be handled.
After an abnormal event is set as a non-violation, DSC will no longer report alarms for the event, and the event will not be displayed in the abnormal event list.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot