Data security monitoring and auditing

Updated at:
Copy as MD

Monitor and audit data-plane operations to detect threats early and support post-event audits.

Data security monitoring and auditing tracks data-plane activities such as access to databases and Object Storage Service (OSS).

It enables proactive risk detection and post-event audits. The following table describes key cloud data security monitoring dimensions:

Dimension

Feature

Description

Abnormal data flow

Sensitive data download from an abnormal geographic location

May indicate account compromise by an external attacker, leading to data breach.

Sensitive data download from an abnormal device

May indicate account compromise or use of a non-work device.

Sensitive data download at an abnormal time

May indicate account compromise or off-hours data access.

First-time download of sensitive data

May indicate misconfigured permissions, risking data leakage.

Download of a rarely used sensitive table

May indicate misconfigured permissions, risking data leakage.

Abnormal file download volume

May indicate attacker access or malicious data backup.

Sensitive data download from a rarely used bucket

May indicate misconfigured permissions, risking data leakage.

Abnormal data download volume

May indicate attacker access or malicious data backup.

Download from a rarely used sensitive database (by IP)

An IP accessing a rarely used database may indicate account compromise and data breach.

Too many IPs downloading sensitive data

May indicate account compromise and data breach.

Abnormally frequent sensitive data downloads

May indicate account compromise and data breach.

Sensitive data download from an abnormal Referer

May indicate account compromise and data breach.

Abnormal SQL statement execution

May indicate account compromise or a new business operation by an employee.

Abnormal behavior

Abnormal logon time

May indicate account compromise or off-hours data access.

Abnormal logon device

May indicate account compromise or use of a non-office device.

Abnormal logon location

May indicate account compromise and potential data breach.

Repeated access to non-existent files

May indicate an external attack attempt.

Repeated unauthorized file access attempts

May indicate an external attack attempt.

Consecutive incorrect logon passwords

May indicate a weak-password guessing attack.

Sensitive data download from a malicious source (threat intelligence)

May indicate an attempted or successful attack.

Abnormal configuration

Protection not set for a sensitive MaxCompute project

Without the Protection identity set, data outflow controls are not enforced.

Label Security not set for a sensitive MaxCompute project

Without Label Security, access to sensitive data cannot be controlled.

Sensitive OSS bucket set to public

A public bucket exposes sensitive data to anyone with API access.

RDS IP whitelist allows public access

A 0.0.0.0/0 whitelist entry allows unrestricted connections and enables brute-force attacks.

Enable audit services for your data stores to analyze security risks and trace incidents. Audit logs must meet applicable regulations — for example, classified protection schemes require 180-day log retention.