Access Alibaba Cloud assets

Updated at:

After you activate Security Center, cloud service assets in your Alibaba Cloud account are automatically synchronized, and no manual access operation is required. However, an asset appearing in the list does not mean it is already protected. You must install the agent on servers, confirm the protection edition, and configure the agent protection mode before the servers enter detection and protection flows such as alerts, vulnerabilities, and baseline checks. This topic describes the complete getting-started path from asset access to active protection and where each step is located in the console.

Before you begin

The AliyunServiceRoleForSas and AliyunServiceRoleForSasCspm service-linked roles are authorized. Security Center uses this authorization to read the cloud service assets and configurations in the current account. Asset synchronization runs automatically after the authorization is complete, and no further manual trigger is required.

Note

If you have not completed the authorization, follow the on-screen instructions to complete it the first time you open the relevant asset page.

Supported alibaba cloud Assets

  • Host assets: Elastic Compute Service (ECS) instances and Simple Application Server instances.

  • Container assets: Container Registry and Container Service for Kubernetes.

  • Other cloud services: Object Storage Service (OSS), Server Load Balancer (SLB), Anti-DDoS, Web Application Firewall, and ApsaraDB RDS. For the full list, see Compatible server assets and cloud services.

Host assets

Alibaba Cloud host assets are automatically synchronized by Security Center. You do not need to manually add instances or provide any access information. Security Center periodically synchronizes Alibaba Cloud host assets. New servers may not immediately appear in the asset list due to synchronization latency. To manually synchronize the latest assets, perform the following steps:

  1. Access the Security Center console - Asset Center - Host Assets. At the top of the left side of the page, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  2. On the Host page, Server tab, click Synchronize Assets.

  3. Set the search condition to Cloud Service Provider and select Alibaba Cloud. The system automatically queries the Alibaba Cloud host assets in the current account.

Cloud services

Alibaba Cloud cloud service information is periodically synchronized by Security Center. You do not need to manually add instances or provide any access information. You can also manually synchronize assets by performing the following steps:

  1. Access the Security Center console - Asset Center - Asset Overview. At the top of the left side of the page, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  2. On the Cloud Product tab, click Synchronize Assets.

    Note

    Security Center retrieves the latest cloud service information and refreshes the server list.

  3. Set the search condition to Service Provider and select Alibaba Cloud. The system automatically queries the Alibaba Cloud cloud services that are activated in the current account.

Container assets

To discover Alibaba Cloud container assets, you must first install the agent on the servers where the target clusters reside and bind a protection edition or protection level. Security Center then periodically synchronizes the assets automatically. You do not need to manually add instances or provide any access information. You can also manually synchronize assets.

Important

To access container assets, you must purchase the Ultimate edition of Security Center or enable Host and Container Security pay-as-you-go.

  1. Bind a protection edition or protection level:

    1. Access the Security Center console - Asset Center - Host Assets. At the top of the left side of the page, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

    2. In the Remaining Quota area, click Manage.

    3. On the Quota Management dialog, in the Bind Quota list area, select a protection edition in the Target Version column for the target server.

      • Subscription instance: Ultimate

      • Pay-as-you-go instance: Full Protection for Hosts and Containers.

  2. Wait for asset synchronization: After you bind a protection edition or protection level, Security Center periodically synchronizes assets automatically. You can also manually synchronize assets by performing the following steps:

    1. Access the Security Center console - Asset Center - Container Assets. At the top of the left side of the page, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

    2. Click Synchronize Assets.

Next steps: Install the agent

Automatic synchronization of Alibaba Cloud cloud services solves the problem of "assets being discovered". Capabilities such as intrusion detection, vulnerability scanning, and baseline checks on servers depend on the agent to collect data. Therefore, you must install the agent on servers. The Security Center agent is a lightweight security proxy deployed on servers. It reports data and receives detection instructions only after it is installed and registered. For more information, see Install the agent.

Note

When you purchase an ECS instance, if you select the Free Security Hardening option, the system automatically installs the Security Center agent when the ECS instance is created.

Install from the console

  1. Log on to the Security Center console.

  2. In the left-side navigation pane, choose System Configuration > Feature Settings. In the upper-left corner of the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.

  3. On the Agent > Agent Not Installed tab, find the server where you want to install the agent, and click Install Agent in the Actions column.

    Note

    You can also select multiple servers and click Install to install the agent in batches.

Use an installation command

  1. Log on to Security Center console.

  2. In the left-side navigation pane, choose System Configuration > Feature Settings. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  3. On the Agent > Installation Command tab, copy the installation command that corresponds to the operating system of the server.

  4. Log on to the server and run the installation command with administrator or root permissions.