Data security monitoring and auditing
Monitor and audit data-plane operations to detect threats early and support post-event audits.
Data security monitoring and auditing tracks data-plane activities such as access to databases and Object Storage Service (OSS).
It enables proactive risk detection and post-event audits. The following table describes key cloud data security monitoring dimensions:
|
Dimension |
Feature |
Description |
|
Abnormal data flow |
Sensitive data download from an abnormal geographic location |
May indicate account compromise by an external attacker, leading to data breach. |
|
Sensitive data download from an abnormal device |
May indicate account compromise or use of a non-work device. |
|
|
Sensitive data download at an abnormal time |
May indicate account compromise or off-hours data access. |
|
|
First-time download of sensitive data |
May indicate misconfigured permissions, risking data leakage. |
|
|
Download of a rarely used sensitive table |
May indicate misconfigured permissions, risking data leakage. |
|
|
Abnormal file download volume |
May indicate attacker access or malicious data backup. |
|
|
Sensitive data download from a rarely used bucket |
May indicate misconfigured permissions, risking data leakage. |
|
|
Abnormal data download volume |
May indicate attacker access or malicious data backup. |
|
|
Download from a rarely used sensitive database (by IP) |
An IP accessing a rarely used database may indicate account compromise and data breach. |
|
|
Too many IPs downloading sensitive data |
May indicate account compromise and data breach. |
|
|
Abnormally frequent sensitive data downloads |
May indicate account compromise and data breach. |
|
|
Sensitive data download from an abnormal Referer |
May indicate account compromise and data breach. |
|
|
Abnormal SQL statement execution |
May indicate account compromise or a new business operation by an employee. |
|
|
Abnormal behavior |
Abnormal logon time |
May indicate account compromise or off-hours data access. |
|
Abnormal logon device |
May indicate account compromise or use of a non-office device. |
|
|
Abnormal logon location |
May indicate account compromise and potential data breach. |
|
|
Repeated access to non-existent files |
May indicate an external attack attempt. |
|
|
Repeated unauthorized file access attempts |
May indicate an external attack attempt. |
|
|
Consecutive incorrect logon passwords |
May indicate a weak-password guessing attack. |
|
|
Sensitive data download from a malicious source (threat intelligence) |
May indicate an attempted or successful attack. |
|
|
Abnormal configuration |
Protection not set for a sensitive MaxCompute project |
Without the Protection identity set, data outflow controls are not enforced. |
|
Label Security not set for a sensitive MaxCompute project |
Without Label Security, access to sensitive data cannot be controlled. |
|
|
Sensitive OSS bucket set to public |
A public bucket exposes sensitive data to anyone with API access. |
|
|
RDS IP whitelist allows public access |
A 0.0.0.0/0 whitelist entry allows unrestricted connections and enables brute-force attacks. |
Enable audit services for your data stores to analyze security risks and trace incidents. Audit logs must meet applicable regulations — for example, classified protection schemes require 180-day log retention.