Detection scope
Security Center collaborates with the cloud protection center through the agent installed on your servers to provide security alerting, vulnerability management, malware detection, baseline checks, and network defense alerting. This topic describes the scope of server information collected by each feature, as well as the supported vulnerability types and security alert types.
If the collected server information changes, Alibaba Cloud will publish the update on the official website in advance. If you do not agree to the changes made by Alibaba Cloud, you have the right to stop using Alibaba Cloud Security Center and uninstall the agent from your servers as described in Uninstall the Security Center agent. If you continue to use Alibaba Cloud Security Center, you are deemed to accept the relevant changes made by Alibaba Cloud.
Suspicious files
Security Center provides malicious file detection. After detecting a suspicious file, the system uploads the file information (including but not limited to the file path, MD5 value, and creation time) to the cloud protection center for final verification. After confirming the file as malicious, Security Center sends you a security alert notification.
Suspicious processes
Security Center provides malicious process detection. After detecting a suspicious process, the system uploads the process information (including but not limited to the process name, startup parameters, file path, and start time) to the cloud protection center for final verification. After confirming the process as malicious, Security Center sends you a security alert notification.
Account information
Security Center provides logon audit, suspicious account alerting, and brute-force attack prevention. The system periodically collects and uploads account information (including but not limited to usernames and user permissions) and logon information (including but not limited to logon usernames and logon IPs) from your servers. If an unusual logon event occurs, Security Center sends you a security alert notification.
Suspicious network connections
Security Center provides suspicious network connection detection. After detecting a suspicious network connection, the system uploads the connection information (including but not limited to source IP, source port, destination IP, and destination port) to the cloud protection center for final verification. After confirming the connection as suspicious, Security Center sends you a security alert notification.
Server assets
Security Center provides asset management. The system periodically collects server asset information (including but not limited to installed software, listening ports, and running websites) and displays all assets on the Security Center console Asset Center page.
Container image security
Security Center provides image security scanning. The system periodically scans containers for vulnerabilities and malicious files, and displays all detected vulnerabilities and malicious file information on the Security Center console page.
Container runtime security
Security Center provides container runtime threat detection to detect in real time whether running containers have threats such as virus files, malicious programs, internal intrusions, container escapes, and high-risk operations. If a security risk is detected during container runtime, Security Center sends you a security alert notification.
Supported vulnerability types
Linux Software Vulnerability, Windows System Vulnerability, Application Vulnerability, Urgent Vulnerability.
Application Vulnerability and Urgent Vulnerability do not support one-click fixing from the console. You must log on to the server and manually fix the vulnerabilities based on the remediation suggestions provided in the vulnerability details.
Supported security alert types
|
Type |
Description |
|
Network Defense Alert (formerly attack analysis) |
If you enable rules in Malicious Behavior Defense for Hosts under the Network Threat Prevention category and Brute-force Attack Protection for Hosts, Security Center automatically blocks detected attacks based on these protection rules and generates a Network Defense Alert. For more information, see Network Defense Alert (formerly attack analysis). Important
|
|
Precise Defense |
The Malicious Host Behavior Prevention feature generates Precise Defense alerts based on your enabled defense rules. For more information about Malicious Host Behavior Prevention, see Host protection settings. |
|
Suspicious Process Behavior |
Detects unusual process behavior, such as running suspicious command sequences, starting from an abnormal path, process injection, and unauthorized changes to system files or configurations. |
|
Webshell |
Detects webshell backdoor files on the server, or malicious code injected into non-program files, such as logs and images. |
|
Unusual Logon |
Detects logons that do not comply with preset policies, successful brute-force attacks, and logon attempts from known malicious IP addresses or backdoor accounts. |
|
Malware |
Detects various types of malware running or present on the host, including viruses, trojans, ransomware, mining programs, and hacking tools. |
|
Cloud Service Threat Detection |
Detects the theft and abuse of cloud platform identity credentials, such as an AccessKey, as well as unusual configurations and permission probing on cloud resources. |
|
Unusual Network Connection |
Detects various suspicious network behaviors on the server, such as port scanning, connections to malicious sources, and a reverse shell. These behaviors are typical signs of attack reconnaissance, remote control, and lateral movement. Note
This feature does not detect encrypted HTTPS traffic. |
|
Malicious Script |
Detects when a malicious or suspicious script file is executed on the server. This indicates an attacker has compromised the system and is running malicious commands. |
|
Persistent Webshell |
Detects persistence mechanisms used to maintain long-term control, such as creating auto-start items, memory-resident backdoors, hidden processes, and exploiting advanced system features. |
|
Sensitive File Tampering |
Detects tampering with core system files and configurations (such as shared library preload files). Such tampering includes modifying, replacing, or moving files to achieve persistence or bypass security detection. |
|
Container cluster anomaly |
Detects complex, multi-stage attacks in container clusters. These attacks can include using a service account for privilege escalation (such as creating unusual tokens or binding to high-privilege roles), lateral movement (such as entering a container to execute commands or accessing Kubelet), and information theft (such as enumerating Secrets). |
|
Suspicious Account |
Detects the creation or use of a suspicious account in the system. |
|
Webshell detection (local scan) |
Analyzes file behavior to identify and score suspicious files. |
|
EXP |
Detects attacks that use known vulnerabilities in the operating system or applications to achieve remote code execution, privilege escalation, or container escape. |
|
Abnormal network traffic |
Identifies past and ongoing attacks by analyzing network traffic and correlating it with host behavior. |
|
Container Escape Prevention |
In Proactive Defense for Containers, after you create a Container Escape Prevention rule, if a process inside a container attempts an operation that violates the rule (such as accessing a sensitive path on the host or attempting privilege escalation), the defense module blocks the operation and generates a security alert. |
|
Proactive Defense for Containers |
Proactive Defense for Containers provides two core runtime security capabilities and generates security alerts for all detected risky behaviors:
|
|
Risk Image Blocking |
In Proactive Defense for Containers, after you create a Risky Image Blocking rule, Security Center performs real-time security checks on images used to create cluster resources (such as a Pod). If an image matches the rule, the system automatically alerts, blocks, or allows its use and generates a security alert. |
|
Trusted Exception |
Monitors the status of an ECS trusted instance and reports any anomalies. |
|
Others |
Unexpected offline status of the Security Center client, DDoS flood attack, and more. |