Other Configurations

Updated at:

Security Center allows you to configure the global log filtering and access control features on the Other Configurations tab. This topic describes the features that you can configure on the Other Configurations tab and how to configure the features.

Global Log Filter

Security Center provides global log filtering capabilities to ensure security protection, make effective use of log storage space, and improve your operational efficiency.

How it works

The global log filtering feature filters the logs of the Security Center agent based on the following two dimensions.

  • Filtering based on specific fields and aggregated over time

    Specific fields that are used for data collection, such as the cmdline (command line), username (user name), and pcmdline (parent process command line) fields, are combined in a specific order into a key. Events that have the same key are aggregated and filtered within a unit of time, and the number of occurrences of events that have the same feature is counted. If the number of occurrences does not exceed the specified threshold, the events are reported as normal. If the number of occurrences exceeds the threshold, the events are filtered out.

  • Filtering based on process chains

    The process chains of collected events are normalized, and the features of the events are extracted as filtering keys. Within a filtering period, the number of occurrences of events that have the same feature is counted. If the number of occurrences does not exceed the specified threshold, the events are reported as normal. If the number of occurrences exceeds the threshold, the events are filtered out.

Prerequisites

The log analysis service is enabled. For more information, see Enable log analysis.

Note

If you have not enabled the log analysis service, the Global Log Filter feature is not displayed in the console.

Enable global log filtering

  1. Log on to Security Center console.In the left-side navigation pane, choose System Configuration > Feature Settings. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  2. On the Settings tab, open the Other Configurations subtab, and in the Global Log Filter section, turn on the Log Filter switch.

Access control

You can use the Alibaba Cloud Resource Access Management (RAM) service to create and manage RAM users, such as employees, systems, and applications, and control the operation permissions of the RAM users on resources. If your enterprise has scenarios in which multiple users collaboratively operate on resources, RAM allows you to avoid sharing the keys of your cloud account with other users and assign each user only the minimum required permissions on demand. This reduces the information security risks of your enterprise.

Note

If your enterprise has scenarios in which multiple users collaboratively operate on cloud resources, to prevent excessive unnecessary permissions from being granted to enterprise users and posing major risks to the security of your enterprise assets, we recommend that you regularly go to the RAM console to check the permissions granted to enterprise users. When you set permissions for enterprise users, we recommend that you follow the principle of least privilege.

  1. Log on to Security Center console.In the left-side navigation pane, choose System Configuration > Feature Settings. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  2. On the Settings tab, open the Other Configurations subtab, and in the Access Control section, view the entries to the ActionTrail data delivery, service-linked role description, permission policy management, user management, and role management features related to access control.

    • Before you use check items of the identity permission management (CIEM) type in Cloud Security Posture Management (CSPM), you must turn on the Data Delivery of ActionTrail switch. After you turn on the switch, Security Center can access the log data of the ActionTrail service to check whether configuration items related to identity permission management pose risks.

    • View the description of the AliyunServiceRoleForSas service-linked role of Security Center. For more information, see Service-linked roles for Security Center.

    • For Permission policy management, click Management to go to the RAM console, where you can manage all permission policies of the current Alibaba Cloud account. For more information, see Permission policy management.

    • For User management, click Management to go to the RAM console, where you can manage the users created under the current Alibaba Cloud account. For more information, see User management.

    • For Role management, click Management to go to the RAM console, where you can manage the RAM roles created under the current account. For more information, see Role management.