This topic describes the server assets and cloud services that can be integrated with Security Center for protection.
Server assets
Alibaba Cloud: Elastic Compute Service (ECS) instances and Simple Application Servers.
Non-Alibaba Cloud: on-premises servers, IDC servers, or servers from third-party cloud providers.
Cloud services
The following table lists the cloud services supported by Security Center, including whether each service supports Cloud Security Posture Management (CSPM) and whether its resources can be displayed after integration with Security Center.
Note Symbols used in the table:
The columns displayed vary by cloud provider. Columns not shown in a table indicate that the corresponding features are not supported.
Alibaba Cloud
Service Category | Service | Service Subtype | CSPM | Resource Display |
Computing | Cloud Server | Elastic Compute Service (ECS) | Instance | Supported | Supported |
Disk (Storage) | Supported | Supported |
Security Group | Supported | Supported |
Snapshot | Supported | Supported |
Image | Supported | Supported |
Simple Application Server (SAS) | VERSION_CONFIG | Supported | Supported |
Auto Scaling | Scaling Group | Supported | Supported |
ECS-type Scaling Group Configuration | Supported | Supported |
ECI-type Scaling Group Configuration | Supported | Supported |
WUYING | WUYING Cloud Computer | Cloud Desktop | Supported | Supported |
File Storage NAS | Supported | Supported |
Container | Container Service | Container Registry | Enterprise Edition | Supported | Supported |
Personal Edition | Supported | Supported |
Container Service for Kubernetes | Cluster | Supported | Supported |
Storage | Essential Storage Service | Object Storage Service (OSS) | Bucket | Supported | Supported |
File Storage NAS | File System | Supported | Supported |
Storage Data Service | Simple Log Service (SLS) | Project | Supported | Supported |
Network and CDN | Cloud Network | Server Load Balancer (SLB) | Classic Load Balancer | Supported | Supported |
Application Load Balancer | Supported | Supported |
Virtual Private Cloud | NAT Gateway | Supported | Supported |
EIP | Supported | Supported |
VPN | Supported | Supported |
Flow Log | Supported | Supported |
VPC | Supported | Supported |
Elastic IP Address | Anycast EIP | Unsupported | Supported |
CDN | CDN | Domain Name | Supported | Supported |
Cross-region Network | Global Accelerator | Instance | Supported | Supported |
Domain Name | Supported | Supported |
Listener | Supported | Supported |
Security | Cloud Security | Anti-DDoS | Instance | Supported | Supported |
Domain Name | Supported | Unsupported |
WEB_RULE | Supported | Unsupported |
Web Application Firewall | Instance | Supported | Supported |
Domain Name | Supported | Supported |
Cloud Firewall | Asset | Supported | Supported |
Access Control Policy | Supported | Supported |
Access Control Policy Group | Supported | Supported |
Bastionhost | Instance | Supported | Supported |
Data Security | Certificate Management Service (Original SSL Certificate) | Certificate | Unsupported | Supported |
Data Security Center | Instance | Supported | Supported |
Key Management Service | Instance | Supported | Supported |
Key | Unsupported | Supported |
Credential | Unsupported | Supported |
Identity Security | Identity as a Service | EIAM Cloud Identity Service Instance | Supported | Supported |
Middleware | Microservice Tools and Platform | Microservices Engine | Cluster | Supported | Supported |
Gateway | Supported | Supported |
Cloud Message Queue | Cloud Message Queue for Kafka | Instance | Supported | Supported |
Application Integration | API Gateway | Instance | Supported | Supported |
Database | Relational Database | ApsaraDB RDS | Instance | Supported | Supported |
PolarDB | Cluster | Supported | Supported |
PolarDB for Xscale | Instance | Supported | Supported |
ApsaraDB for OceanBase | Database | Supported | Supported |
NoSQL Database | ApsaraDB for MongoDB | Instance | Supported | Supported |
Tair (Redis OSS-compatible) | Instance | Supported | Supported |
ApsaraDB for Lindorm | Instance | Supported | Supported |
ApsaraDB for HBase | Instance | Supported | Supported |
Data Warehouse | AnalyticDB for PostgreSQL | Instance | Supported | Supported |
AnalyticDB for MySQL (ADB) | Instance | Supported | Supported |
ApsaraDB for ClickHouse | Instance | Supported | Supported |
ApsaraDB for SelectDB | Instance | Supported | Supported |
Database Management Tool | Data Management (DMS) | Instance | Supported | Supported |
User and Tenant | Unsupported | Supported |
Big Data Computing | Data Computing and Analytics | Elasticsearch (ES) | Instance | Supported | Supported |
MaxCompute | Project | Supported | Supported |
Hologres | Instance | Supported | Supported |
Data Development and Service | DataWorks | Workspace | Supported | Supported |
Enterprise Service and Cloud Communication | Enterprise Basic Service | Domain Name | Domain Name | Unsupported | Unsupported |
Serverless | Computing | Function Compute | Domain Name | Supported | Supported |
Application | Supported | Supported |
Development Tool | Yunxiao DevOps | Alibaba Cloud DevOps | Organization | Supported | Supported |
Migration and O&M Management | Cloud Management | ActionTrail | Trail | Supported | Supported |
Resource Access Management | Account Alias | Supported | Supported |
User | Supported | Supported |
Permission Policy | Supported | Supported |
Group | Supported | Supported |
Role | Supported | Supported |
Access Management CAM | Supported | Supported |
Tencent Cloud
Service Category | Service | Service Subtype | CSPM | Resource Display |
Compute | Cloud Server CVM | Instance | Supported | Unsupported |
Security Group | Supported | Supported |
Container | Container Registry | Instance | Supported | Supported |
Registry Info | Supported | Unsupported |
Basic Storage | COS | Instance | Supported | Supported |
CBS | Instance | Supported | Supported |
Relational Database | MySQL | Instance | Supported | Supported |
Account | Supported | Unsupported |
PostgreSQL | Instance | Supported | Supported |
MariaDB | Instance | Supported | Supported |
Account | Supported | Unsupported |
Enterprise Distributed Database | TDSQL MySQL | Instance | Supported | Supported |
NoSQL Database | Redis | Instance | Supported | Supported |
Network | Load Balancer | Instance | Supported | Supported |
VPC | Instance | Supported | Supported |
Domain and Website | SSL Certificate | Instance | Supported | Supported |
Big Data | Elasticsearch Service | Instance | Supported | Supported |
Management and Audit | CAM | Collaborator | Supported | Supported |
Collaborator Access Key | Supported | Unsupported |
Collaborator Policy | Supported | Unsupported |
Role | Supported | Supported |
Role Policy | Supported | Unsupported |
Sub-user | Supported | Supported |
Sub-user Access Key | Supported | Unsupported |
Sub-user Policy | Supported | Unsupported |
AWS
Service Category | Service | Service Subtype | CSPM | Resource Display |
Analytics | Data Warehouse RedShift | Cluster | Unsupported | Supported |
Compute | Cloud Server EC2 | Instance | Supported | Unsupported |
Security Group | Unsupported | Supported |
Snapshot | Unsupported | Supported |
Subnet | Unsupported | Supported |
Volume | Unsupported | Supported |
VPC | Unsupported | Supported |
Transit Gateway | Unsupported | Supported |
VPN | Unsupported | Supported |
Container | Container Service ECS | Cluster | Unsupported | Supported |
Service | Unsupported | Unsupported |
Scheduled Task | Unsupported | Unsupported |
Encryption and PKI | Key Management KMS | Key | Supported | Supported |
Database | Database RDS | Instance | Unsupported | Supported |
Cluster | Unsupported | Supported |
Cluster Snapshot | Unsupported | Unsupported |
ElastiCache | Cluster | Unsupported | Supported |
Replication Group | Unsupported | Unsupported |
Management and Governance | Auto Scaling | Group | Unsupported | Supported |
Launch Configuration | Unsupported | |
Config | Configuration Recorder Status | Supported | Supported |
CloudTrail | Trail | Supported | Supported |
Networking and Content Delivery | Load Balancer | Load Balancer ELB | Unsupported | Supported |
Load Balancer CLB | Supported | Supported |
Load Balancer ALB | Supported | Supported |
Listener | Supported | Supported |
CloudFront | Distribution | Unsupported | Supported |
Security, Identity, and Compliance | Security Hub | Settings | Supported | Supported |
IAM | Policy | Supported | Supported |
Role Policy | Supported | Supported |
Credential Report | Supported | Unsupported |
User | Supported | Supported |
Account Password Policy | Supported | Unsupported |
Account Summary | Supported | Supported |
MFA Device | Supported | Unsupported |
Access Key | Supported | Unsupported |
Server Certificate | Supported | Unsupported |
Bucket Policy Access | Supported | Supported |
Storage | Object Storage S3 | Bucket | Supported | Supported |
Bucket Lifecycle Configuration | Supported | Unsupported |
Azure
Service Category | Service | Service Subtype | Resource Display |
Database | SQL Server | Instance | Supported |
MySQL | Instance | Supported |
MariaDB | Instance | Supported |
Cosmos DB | Account | Supported |
Storage | Blob | Account | Supported |
Compute | AKS | Managed Cluster | Supported |
Virtual Machine | Instance | Supported |
Container | Container Registry | Container Registry | Supported |
Networking | Virtual Network | Instance | Supported |
Security | App Configuration | Instance | Supported |
Huawei Cloud
Service Category | Service | Service Subtype | Resource Display |
Compute | ECS | Instance | Supported |
AS | Scaling Group | Supported |
Network | ELB | Instance | Supported |
VPC | VPC | Supported |
EIP | Supported |
Storage | OBS | Bucket | Supported |
EVS | Disk | Supported |
Relational Database | RDS | Instance | Supported |
GaussDB | Instance | Supported |
Non-relational Database | GeminiDB | Instance | Supported |
e-Surfing Cloud
Service Category | Service | Service Subtype | CSPM | Resource Display |
Compute | ECS | Instance | Supported | Supported |
Storage | ZOS | Bucket | Supported | Supported |
Storage | EBS | Disk | Supported | Supported |
Database | Distributed Cache Redis | Instance | Supported | Supported |
Database | RDS | Instance | Supported | Supported |
Middleware | Distributed Message Service Kafka | Instance | Supported | Supported |
Middleware | Distributed Message Service RocketMQ | Instance | Supported | Supported |
Network | ELB | Instance | Supported | Supported |
Identity Security | CTIAM | User/Policy | Supported | Supported |
Note: The preceding products are confirmed to support the permission policy inference. For the complete list of supported products, see the actual display in the Security Center console.
Kingsoft Cloud
Service Category | Service | Service Subtype | CSPM | Resource Display |
Note: For the list of cloud services supported by Kingsoft Cloud, see the actual display in the Security Center console.
Ucloud
Service Category | Service | Service Subtype | CSPM | Resource Display |
Note: For the list of cloud services supported by Ucloud, see the actual display in the Security Center console.
References
Supported systems and Install the agent: The OS and kernel versions of servers must fall within specified ranges before you can install the Security Center agent to use the protection features of Security Center.
Integrate third-party cloud assets: Connect assets deployed on third-party cloud platforms (including Tencent Cloud, Huawei Cloud, AWS, Azure, e-Surfing Cloud, Kingsoft Cloud, and Ucloud) to Security Center to centrally protect and manage these assets.
Add data center assets: Connect assets in your on-premises data centers (IDCs) to Security Center to centrally manage IDC asset information in the Security Center console.
Use proxy access: Configure a proxy server to connect servers that cannot access the public network (including hosts and containers) to Security Center for protection.
Onboard e-Surfing Cloud: Connect e-Surfing Cloud assets to Security Center by using the AK of an IAM user. The CSPM module is supported.
: Connect Kingsoft Cloud assets to Security Center by using the AK of a sub-account.
: Connect Ucloud assets to Security Center by using the AK of a sub-account.