Cloud security community
1. Evolution and challenges of the shared responsibility model
In the early days of cloud computing, companies faced security challenges that were different from those in traditional IT. These challenges included data migration and permission management. To establish a common understanding of cloud security between companies and cloud service providers, the shared responsibility model was created. This model defines the responsibilities of the cloud service provider and the user for infrastructure, platforms, applications, and data. It became the foundation for cloud security practices.
Under this framework, Alibaba Cloud is responsible for the security of its data centers, physical facilities, cloud platform, and basic products. Customers are responsible for the security of their own assets, such as their data, application configurations, and access permissions. This clear division of responsibilities promoted the standardized development of cloud security.
However, as digitalization expands across industries, companies are moving more of their operations to the cloud. This increases business complexity and makes security challenges more dynamic and widespread. Many companies, especially small and medium-sized enterprises (SMEs), do not invest sufficiently in network security. They lack dedicated security staff and often neglect to review their configurations. This leads to avoidable issues such as weak passwords, misconfigured policies, and large attack surfaces, which results in frequent security risks.
Given this reality, simply defining responsibilities is no longer enough to address new threats. Cloud platforms must now consider how to help customers manage their security risks more effectively.
2. Introduction and development of the "cloud security community"
On September 20, 2024, Alibaba Cloud introduced the "cloud security community" concept at the Apsara Conference in Hangzhou. This was part of the release of the Alibaba Cloud Security Whitepaper (2024 Edition). This concept is not just a continuation of the shared responsibility model, but an active upgrade.
The core goal of this concept is to "jointly protect the security of customer assets on the cloud." The platform and its customers are no longer just parties with divided responsibilities. Instead, they form a security community that collaborates on defense.
Alibaba Cloud continues to strengthen the security of its infrastructure, cloud platform, and products to fulfill its primary responsibility of providing a "secure cloud." At the same time, it actively extends its service boundaries to address the "last mile" of security implementation. This refers to security blind spots caused by improper configuration, a lack of capability, or limited resources on the customer's side.
To achieve this, Alibaba Cloud strengthens collaborative governance through four key initiatives:
Improve native security levels: Embed security capabilities into default product configurations to reduce user configuration risks.
Offer inclusive security capabilities: Provide out-of-the-box basic protection to help customers establish a security baseline as soon as they migrate to the cloud.
Strengthen proactive service response: Proactively send alerts for important events and provide 24/7 collaborative defense and response.
Promote security best practices: Continuously share security knowledge and create systematic content to promote best practices.
The "cloud security community" is not about one-way empowerment, but collaborative governance. The platform enhances its support capabilities, and customers actively participate in governance. By working together, both parties build an open, trusted, and sustainable security ecosystem on the cloud.
This marks a new stage in cloud security, moving from "separate responsibilities" to "shared protection." It also provides a more forward-looking and practical solution for enterprise security in the digital age.
3. Key measures for practicing the security community
Improve native security levels
In the traditional shared responsibility model, users must configure alerting policies, enable detection features, and manage access permissions on their own. The effectiveness of protection is highly dependent on user actions and security awareness.
To lower the barrier to entry, Alibaba Cloud improves native security at the product design level by embedding security best practices into default configurations. By analyzing the root causes of common security events, Alibaba Cloud identifies frequently insecure configurations. During resource creation or modification, it guides users to make safer choices in the following ways:
Risk prompts: Provide real-time reminders of potential risks on the configuration interface, such as weak passwords or excessive permissions. This helps users identify and correct issues promptly.
Default selection: Enable key protection features, such as MFA, by default. This reduces the impact of credential leaks.
Operation confirmation: Insert a security confirmation step for risky operations. This ensures users are fully aware of the risks and helps prevent security incidents caused by mistakes.
These mechanisms are now implemented in key scenarios such as account security and network configuration. They make security features easier to use, more automated, and more proactive.
Open and inclusive security capabilities
Alibaba Cloud offers core security capabilities, including threat detection and basic protection, as an inclusive package to help customers establish an initial line of defense.
Threat detection for core scenarios: The Introduction to Security Center Free Edition provides continuous threat detection for key resources. This includes account permissions, host operations, and cloud product configurations. It automatically discovers common configuration errors, sensitive information leaks, and abnormal logon behavior. It also provides real-time monitoring and alerting for high-frequency threats such as mining programs and brute-force attacks. This helps users detect anomalies in the early stages of an attack.
Default protection with integrated basic features: The description of free security protection benefits for ECS is available for ECS users. The protection package integrates features such as vulnerability patching, configuration compliance checks, host antivirus, and automatic backups. After you attach an instance, you can enable virus scanning and proactive defense mechanisms without additional activation or payment. This provides protection from the moment of activation and strengthens the baseline for cloud security.
Strengthen proactive service response
For important security events, Alibaba Cloud leverages its extensive security experience to provide proactive emergency response capabilities. When high-risk behavior is detected, Alibaba Cloud proactively triggers alerts and protection measures. It also provides standardized response paths to help customers shorten their response times and reduce potential impact.
Intelligent detection to continuously improve threat detection capabilities: The threat detection engine is continuously optimized for high-risk scenarios such as AccessKey (AK) abuse and ransomware. It integrates multi-dimensional behavior analytics to more accurately detect abnormal activities. This helps customers focus on the security events that truly require attention.
Automatic protection to provide restrictive protection in high-risk scenarios: When the system confirms a clear threat, it proactively applies temporary restrictions to related calls or services, such as restrictive protection for AccessKeys. This gives customers time to respond and provides basic protection during the critical window when a threat could spread.
Multi-channel notifications for timely threat delivery: Threat information is promptly pushed to customers and relevant contacts through multiple channels, such as text messages, internal messages, and voice calls, to ensure that critical alerts are not missed and improve the coverage and timeliness of information delivery.
Rapid response with standardized handling paths: A 24/7 security emergency response center is available. Customers can obtain expert support by submitting a security ticket. A one-click response feature is also provided. It allows users to quickly remediate common threats, such as malicious processes, and simplifies the emergency response workflow.
Promote security best practices
Security is not just about technology. It is also a habit and an awareness that must be continuously cultivated. The root cause of many security events is not a lack of technology, but a lack of awareness or improper operations. To help customers improve their cloud security awareness and practical skills, Alibaba Cloud continuously promotes security knowledge and helps make security a daily habit through systematic content and regular operational activities.
Create a one-stop security center: Alibaba Cloud launched the "Cloud Security Guide" channel. This channel gathers various resources such as documents, video courses, and emergency response toolkits that cover core security scenarios. This helps users quickly find the information they need and learn on demand.
Provide scenario-based security knowledge: By focusing on high-frequency threat scenarios and real-world attack and defense cases, Alibaba Cloud provides security alerts and trend reports that are both professional and practical. This approach makes security knowledge easy to understand, learn, and apply.
Organize security learning and practice activities: Alibaba Cloud regularly launches security practice activities for small and medium-sized enterprises and developers. These activities encourage users to learn security knowledge, perform security assessments, and remediate security issues themselves. This helps move security from "knowing" to "doing."