Security management and operations
As your business grows and evolves, your security posture constantly changes. During this process, hackers continuously scan for vulnerabilities and weaknesses to launch attacks. Therefore, you should make security management and operations a daily priority. This includes monitoring for anomalies, addressing security risks, strengthening security defenses, and responding to security events.
1. Receive and process security notifications
The first step in security operations is to ensure that you can effectively receive and process security alerts from Alibaba Cloud. When Alibaba Cloud detects a security risk in your cloud environment, it sends you an alert notification. If you do not subscribe to these messages, or if you receive them but ignore the risks, the vulnerability may persist and lead to serious consequences. It is very important to assign dedicated personnel to receive and promptly handle security alerts.
Assign dedicated on-call security personnel
In the Alibaba Cloud Management Console, go to Account Contacts. You can set a dedicated security contact and phone number for your security, operations and maintenance (O&M), or developer team. Because security attacks and risk events often occur at night or in the early morning, you should arrange for technical staff to be on call 24 hours a day, if possible. This helps ensure that you do not miss important security alerts.
Subscribe to and receive security messages
In the Alibaba Cloud Message Center, you can subscribe to different types of messages through various notification channels as needed. Ensure that your security contacts subscribe to all security-related message types. These include Account Security Alerts, Alibaba Cloud Security Notifications, Illegal Content Notifications, and Apsara Stack Security Notifications.
Handle security alerts promptly
After you receive a security risk notification, address it as soon as possible based on the content and recommended actions in the notification. Actions may include fixing security vulnerabilities or changing account passwords. The sooner you act, the smaller the impact will be.
If you are unsure how to proceed after receiving a notification, you can submit a ticket on the Alibaba Cloud official website. Security engineers provide 24/7 technical support.
2. Monitor cloud resources for anomalies
In addition to the security alerts mentioned above, Alibaba Cloud recommends that you proactively configure monitoring policies. Security Center provides a rich set of predefined alert rules for free. You can also use other cloud products, such as ActionTrail, Simple Log Service (SLS), and CloudMonitor (CMS), to set up alert rules for abnormal changes in your cloud resources. This ensures that you can detect and respond to potential threats in a timely manner.
Use Security Center to detect security threats
After you authorize and enable Security Center, you can use its Detection and Response feature for free. It includes over 250 threat detection models to detect security risks in your system, such as abnormal process behavior, web shells, malware, and unusual logons. It also provides specific reasons for alerts and recommended actions.
Security Center also provides a data overview that shows the current security alert status and defense status. This helps security operations personnel track statistics and perform follow-up actions.
After you upgrade to the Enterprise or Ultimate Edition, you can also use automated attack tracing. This feature analyzes attack events and creates an event chain diagram of the attacker's intrusion. This helps you locate the cause of the intrusion and develop an emergency strategy in the shortest possible time.
Use ActionTrail to configure key actions and receive alerts and analysis through SLS
You can create a trail in ActionTrail for common events, such as:
Many failed logon attempts
Activity outside of business hours
Access from unknown IP addresses
Risky operations, such as modifying security group rules or deleting key resources
After recording these key operations, you can deliver the logs to Simple Log Service (SLS). You can then receive SLS alerts and periodically analyze the logs to find specific patterns or abnormal activities.
Use CloudMonitor (CMS) to set alerts and responses for abnormal cloud resource operations
You can use CloudMonitor to detect abnormal network traffic. Set alerts for traffic that is higher than normal levels to ensure a prompt response.
Abnormally high CPU or memory usage may indicate unauthorized processes or resource-intensive attacks.
You can also detect changes in security group rules and logon activity through CMS monitoring.
3. Fix security issues promptly
Fix cloud platform configuration issues
Cloud platform configuration issues are security risks caused by incorrect cloud product configurations, such as incorrect permission assignments and improper network access controls. Data shows that 40% of security incidents in the cloud are caused by misconfigured cloud products. Therefore, cloud platform configuration issues are a key security concern.
You can use the cloud platform configuration check feature in Security Center to find these security risks. The Free Edition of Security Center provides basic check rules. You can also upgrade to a paid edition for more comprehensive checks. Alternatively, you can use Cloud Config to perform checks based on specific best practices, security compliance requirements, or custom rules.
Establish a vulnerability management process
A complete vulnerability management process helps enterprises better manage security risks. You can manage product and application vulnerabilities as follows:
1) Monitor and identify: Continuously monitor official announcements from sources such as the Alibaba Cloud Vulnerability Database and security notifications from Alibaba Cloud internal messages. You can also use vulnerability scan tools, such as Security Center, to regularly scan systems, network devices, and applications to promptly discover known security vulnerabilities. Security Center supports free detection of important emergency vulnerabilities after you grant authorization in the console.
2) Assess risks: Assess the risks of discovered vulnerabilities. Consider factors such as their severity, scope of impact, and difficulty of exploitation to determine priorities. Prioritize high-risk and easily exploitable vulnerabilities.
3) Fix vulnerabilities: Obtain and verify official patches or fixes, and create a detailed deployment plan. Before deploying in a production environment, test the patch's compatibility and impact in a staging environment. This ensures that the patch deployment does not introduce new problems.
You can also use the vulnerability management feature in Security Center. It helps you discover and identify security vulnerabilities in operating systems, web content management systems, and applications. It lets you assess the priority and risk of vulnerabilities and supports one-click fixes for some vulnerabilities, which can greatly simplify the management process.
Upgrade regularly and avoid using outdated versions
Older product versions may contain known security vulnerabilities that attackers can easily exploit.
Maintain an update policy: Create and follow a policy to regularly update software and operating system versions. Avoid using outdated versions for long periods. New versions usually include security improvements, performance optimizations, and new features.
Evaluate update content: Before you apply any update, carefully read the version update log. Understand the security vulnerabilities fixed, new features added, and possible compatibility issues. Assess the impact of the update on your existing systems.
Plan for backups and rollbacks: Before you perform any major version update, create comprehensive data and system backups. Develop a rollback plan to quickly restore to the previous state if the update fails or causes problems.
4. Establish security protection for cloud resources
After you complete the preceding security operations, some critical applications or data may still be vulnerable to attacks. From a protection standpoint, you can use security tools or products to effectively defend against risks when you are maliciously attacked or breached.
1. Host-layer protection
Host protection refers to security measures for your servers, such as ECS instances, to prevent unauthorized access, malware infections, data breaches, service interruptions, and other security threats. You can use the host protection feature to protect cloud servers, ECS instances, and containers from viruses, trojans, and vulnerabilities.
For Alibaba Cloud ECS instances, you can typically choose to automatically install the Security Agent when you create an instance.
For non-Alibaba Cloud environments (such as Huawei Cloud, Tencent Cloud, or AWS) or physical servers, you can download and manually install the Security Agent.
After you install the agent, you can set alert rules. When a threat is detected, the system sends an alert. After you receive a notification, promptly check the security status of the host. You can take appropriate response measures based on the recommendations from Security Center, such as isolating, repairing, or deleting malware.
2. Application-layer protection
Cloud-based applications, such as websites and web applications, are susceptible to attacks that exploit their security vulnerabilities. We recommend that you use Alibaba Cloud Web Application Firewall (WAF). WAF is positioned between your web application and the Internet to filter and monitor HTTP/HTTPS traffic and prevent web attacks, such as SQL injection, cross-site scripting (XSS), and file upload vulnerabilities.
To use WAF, you can add the websites that you want to protect and configure protection rules in the WAF console. These rules include default protection, IP blacklist, URL whitelist, precise protection, malicious web crawlers, and CC attack prevention. After you enable protection, regularly check WAF attack reports and protection statistics.
3. Network-layer protection
When data packets are transmitted at the network layer, you can configure traffic rules using security groups, network ACLs, and Cloud Firewall to restrict abnormal communication links. Alibaba Cloud also provides defense tools against network attacks to help you better respond to attacks.
1) You can use the intrusion prevention feature of Cloud Firewall. It actively detects and intercepts malicious traffic in real time, including hacker attacks, exploits, brute-force attacks, worms, mining programs, backdoor trojans, and DoS attacks. This prevents unauthorized access to your services, data breaches, and damage or breakdown of your business systems and applications.
2) You can use a DDoS service for traffic scrubbing. It cleanses large volumes of attack traffic in a short period and forwards the clean traffic to your server. The basic DDoS service has a traffic threshold that varies by host type. Note that when attack traffic exceeds this threshold, a blackhole is triggered. Alibaba Cloud will temporarily block all inbound Internet traffic to the host. If you have high availability requirements for your host, you can use Anti-DDoS Pro and Anti-DDoS Premium. These products are not limited by traffic thresholds and are designed to handle more complex and larger-scale attacks.
5. Build emergency response capabilities
Even after you complete the preceding configurations and deployments, sudden security risk events can still occur. Therefore, if conditions permit, you should establish a security risk emergency response capability. Prepare plans and conduct drills in advance to respond effectively when a real risk occurs.
Develop a plan: Assess potential risks based on the characteristics of your cloud business. Common risk types include network attacks, data breaches, viruses, and ransomware. Develop specific emergency strategies based on your security protection measures and business importance.
Respond to events: When a risk occurs, quickly confirm the nature and scope of the anomaly. Assess the importance of the affected assets and applications. If necessary, isolate the affected systems or resources to prevent the problem from spreading. If a security event such as a web shell, virus, or trojan occurs, you can find details and suggestions in the corresponding alert in Security Center under Detection and Response - Security Alerts. Then, you can perform a one-click isolation or address it manually.
Recover and review: Execute the recovery plan. This may include restarting services, switching to backup resources, or restoring data. If data is deleted, tampered with, or encrypted for ransom, you can restore it from an ECS image or a backup from the anti-ransomware feature in Security Center. Analyze the root cause of the event and evaluate the effectiveness of the emergency response. Based on the review, update the emergency plan and related procedures. Promptly address the vulnerabilities involved in the security event to prevent it from happening again.
Train and drill: Regularly train the emergency response team to ensure that relevant personnel are familiar with the emergency plan and operating procedures. Conduct regular emergency drills to test the effectiveness of the plan and improve the team's emergency response capabilities.