Vulnerability prevention
The Vulnerability Prevention page displays network-exploitable vulnerabilities that are automatically detected by Security Center and synchronized to Cloud Firewall. This feature helps defend against attacks that target these vulnerabilities. You can enable Cloud Firewall and configure intrusion prevention (IPS) rules to prevent their exploitation and protect your assets from compromise. This topic describes the types of vulnerabilities that Cloud Firewall can protect against and explains how to use the Vulnerability Prevention feature.
Supported vulnerability types
-
Cloud Firewall synchronizes only network scan-based vulnerabilities. For the complete list of supported vulnerability types, refer to the console.
-
If an asset has no vulnerabilities or has not been attacked, Cloud Firewall does not display vulnerability protection data for that asset.
Cloud Firewall synchronizes some types of vulnerabilities detected by Security Center and displays them on the Vulnerability Prevention page. If a protected asset is at risk from a vulnerability, Cloud Firewall can analyze the exploit behavior in attack traffic and take protective action.
If you use the Enterprise Edition or Ultimate Edition of Cloud Firewall, you can view the vulnerabilities that Cloud Firewall can defend against in the section. For more information, see IPS Configuration.
Limitations
-
The Vulnerability Prevention feature is available for the pay-as-you-go and subscription editions of Cloud Firewall. This feature is not available in the Free Edition.
-
The Vulnerability Prevention feature supports automatic but not manual vulnerability detection.
NoteIf you need to manually scan for vulnerabilities in real time, go to the Vulnerabilities page in the Security Center console. For more information, see Scan for vulnerabilities.
-
For Server Load Balancer (SLB) instances in a classic network, only threat intelligence-based blocking is supported.
-
The Cloud Firewall intrusion prevention system (IPS) module cannot inspect traffic that is encrypted with TLS or SSL. Therefore, it cannot detect or protect against threats in this type of traffic.
Prerequisites
On the page, set the Threat Engine Mode to Block Mode.
If you do not set the Threat Engine Mode to Block Mode, the protection status for all vulnerabilities on the Vulnerability Prevention page is Alert Only. This means Cloud Firewall generates alerts and logs for attacks that exploit these vulnerabilities, but does not block them. For more information about threat engine modes, see Threat Engine Mode.
Procedure
-
Log on to the Cloud Firewall console.
-
In the left-side navigation pane, choose .
-
On the Vulnerability Prevention page, review the vulnerability attack detection results for your assets.
The Vulnerability Prevention page displays vulnerability detection results from the last day, last 7 days, or last month.
The top of the page displays three statistical panels: At-risk Assets Protected, Vulnerabilities Protected, and Vulnerability Attacks Protected. Below these panels, you can filter the list by Vulnerability Category, Attack Type, Risk Level, and Protection Status, or use the date selector and search box. The table shows attack records with columns for Attack Risk Level, Attack Time, Vulnerability Name/CVE ID/Attack Type, Number of Vulnerable Assets, Number of Attacks, Protection Status, and Actions.
-
Hover over the
icon in the Internet ECS with Vulnerabilities column to view the IP addresses of affected servers. Click the number in the Number of Vulnerable Assets column to view information about the affected assets, such as instance name/ID, IP address, and asset type, in a pop-up panel. In the Actions column, click Enable Protection to start blocking attacks for a vulnerability that is in Alert Only status, or click Details to view detailed information about the attack. -
Attacks: The number of times your assets have been attacked by exploiting the vulnerability.
-
Protection Status: Indicates how Cloud Firewall handles attacks that exploit the vulnerability. The following protection statuses are supported:
Blocked: Cloud Firewall blocks attacks that exploit the vulnerability.
Alert Only: Cloud Firewall generates alerts for attacks that exploit the vulnerability but does not block them.
Partial Protection: Cloud Firewall protects some, but not all, servers affected by the vulnerability.
-
Details: Click Details to open the Vulnerability and Protection Details page and view detailed information, including the vulnerability name, risk level, CVE ID, and affected assets.
-
-
On the Vulnerability Prevention page, locate a vulnerability with a status of Alert Only and click Enable Protection in the Actions column.
Clicking Enable Protection has two possible outcomes. If the Internet Border Firewall is not yet enabled for an affected server, this action enables it. If the firewall is already enabled, this action changes the Threat Engine Mode to Block Mode on the IPS Configuration page. The status update may take 1 to 2 minutes to complete.
NoteAfter you enable vulnerability protection, existing access control policies remain in effect on assets for which the firewall is newly enabled. You must create policies on the Inbound tab of the Internet Firewall page to allow traffic on the required public-facing ports of these assets.
Related documents
-
The prevention configuration feature allows you to set the Threat Engine Mode and configure threat intelligence, basic protection, intelligent defense, and virtual patching to more accurately identify and block intrusion risks. For more information, see IPS Configuration.
-
The intrusion prevention (IPS) capability can proactively detect and block malicious traffic in real time, including exploit attempts, brute-force attacks, worms, mining programs, backdoors, trojans, and DoS attacks. This protects your cloud infrastructure. For more information, see IPS capabilities and Intrusion prevention.