End-to-end protection for database applications with SASE

Updated at:

This topic describes how to use Alibaba Cloud SASE to provide end-to-end protection for your database applications.

Use cases

  • You want to restrict database access only to corporate devices.

  • You want to audit and block file exfiltration from databases to local devices.

Alibaba Cloud SASE

SASE, Alibaba Cloud's one-stop office security platform, allows enterprises to quickly build a security system with features like Zero Trust Network Access (ZTNA), data leak prevention, and internet access management, without costly hardware investments. By integrating database applications into this zero-trust framework, you can control access to database applications, audit file exfiltration, and block it when necessary. This provides end-to-end protection for your database-related data.

image

Procedure

Step 1: Activate an SASE instance

SASE offers a 7-day free trial. For more information, see Activate SASE. For more information about billing, see Billing overview for Alibaba Cloud SASE.

Step 2: Configure an identity source

An identity provider (IdP) authenticates your employees. SASE supports both third-party and self-managed identity providers (IdPs), including LDAP, DingTalk, WeCom, Lark, IDaaS, and custom IdPs. If your business uses multiple IdPs, you can configure all of them and enable them to use the SASE service with different identity providers.

This topic uses a custom identity source as an example to help you quickly validate the feature.

  1. Log on to the Alibaba Cloud SASE console.

  2. In the left-side navigation pane, choose Identity Authentication > Identity Access.

  3. On the Identity synchronization tab, find Custom IdP and click Edit in the Actions column. Follow the wizard to configure the custom identity source. For more information, see Connect to a custom identity source.

Step 3: Configure a user group

When you configure a policy, you must specify the user group to which the policy applies.

  1. In the left-side navigation pane, choose Identity Authentication > Identity Access.

  2. On the User Group Management tab, click Create User Group.

  3. In the Create User Group panel, configure information for the user group, such as Organizational Structure, Account Name, Email Address, and Mobile Phone Number. Then, click OK. For more information, see Manage user groups.

Step 4: Enable network connectivity

  1. In the left-side navigation pane, choose Private Access > Network Settings.

  2. On the Network Settings page, on the Services on Alibaba Cloud > CEN Instance tab, view the network resources synchronized by SASE.

  3. Find the target CEN instance or an associated VPC instance, and turn on the Network Connection switch.

  4. In the Network Connection dialog box, select Enable Network Connection for All Cloud Applications or Custom Connection to Cloud Applications.

    image

    • Enable Network Connection for All Cloud Applications: If you select this option, SASE automatically establishes connections for all cloud-native applications. For non-cloud-native applications, you can configure ACL rules to establish connections. New cloud-native applications in this VPC are also connected by default.

      Note

      Currently, only some cloud-native applications are supported. You can find the supported application types on the Services on Alibaba Cloud > Cloud-native Application tab under Application Type.

    • Custom Connection to Cloud Applications:

      • Select Custom Connection to Cloud Applications and click OK.

      • In the Custom Connection to Cloud Applications panel, select the cloud-native applications that you want to connect and click OK.

Step 5: Create a zero-trust policy

  1. In the left-side navigation pane, choose Private Access > Access Control.

  2. On the Zero Trust Policies tab, click Create Policy.

  3. In the Create Policy panel, configure the policy to allow the specified user group to access the RDS application, and then click OK.

    Set Policy name to a descriptive name, such as cloud-native-app-zero-trust-policy. Set Priority to 1. The valid range is 1 to 43. In the Selected applications section, add the target application.

Step 6: Verify the configuration

  1. Open the SASE app that you installed.

  2. Enter the enterprise verification ID and click OK.

    You can log on to the Secure Access Service Edge console. In the navigation pane on the left, on the Settings page, obtain the Enterprise Authentication Identifier.

  3. Log on by using the initial username and password that you received by email or text message.

  4. Click Connect to Private Network.

  5. Try to access the RDS application. If you can access it, the configuration is successful.

Step 7: Configure a data leak prevention policy in SASE

In SASE, you can configure file control policies to audit and block file exfiltration. This includes sharing files exported from a database through cloud storage, instant messaging, or USB devices. If a risk is detected, SASE can issue a warning or block the action. For more information, see Protect data security by detecting file exfiltration.