Attack path analysis
The attack path analysis feature comprehensively scans and analyzes the access paths between cloud services on Alibaba Cloud (for example, an OSS bucket that is controlled by the RAM role attached to an ECS instance), provides visualized scan results, and helps you understand the security status of cloud resource access. This topic describes how to use the attack path analysis feature.
Feature description
By using the attack path analysis feature, you can clearly understand the connections and potential risks between different cloud services, identify unnecessary direct access permissions, and discover weak links that may be exploited, such as overly broad permission settings and unencrypted data transmission. Security Center also automatically generates security suggestions to guide you in adjusting resource permission configurations to reduce potential threats and improve the overall security of the system. This feature helps you detect and fix security vulnerabilities that may be exploited by hackers in advance, protecting critical data and applications against attacks.
Supported assets
The attack path analysis feature of Security Center can scan the assets that meet the following requirements in the current Alibaba Cloud account (primary account).
-
The types of entry assets of attack paths (intruded asset types): Elastic Compute Service (ECS) instances and RAM (roles and AccessKey IDs).
-
The types of destination assets of attack paths (target asset types): Elastic Compute Service (ECS) instances, RAM (Alibaba Cloud primary accounts, users, policies, user groups, and roles), and Object Storage Service (OSS) buckets.
Alert events are reported as the output of attack path checks only when at least one of the following risk scenarios exists on the entry asset.
-
Vulnerabilities of high urgency exist on ECS instances.
-
ECS instances are exposed to the Internet (this risk must appear together with at least one other risk).
-
Urgent alerts exist on ECS instances (alerts on ECS instances that are reported on the page).
-
Urgent alerts exist on the AccessKey pair (AccessKey ID and AccessKey Secret) associated with a RAM role (alerts of the Host and Container Security type in the security alert service).
-
RAM roles can be assumed across accounts.
Attack paths that can trigger alerts
Security Center runs scan tasks on the assets that meet the requirements based on attack path types (abnormal AccessKey pair, sensitive asset, privilege escalation by role, and privilege escalation by user) and attack path scenarios, and reports alert information about the attack paths that are detected.
Abnormal AccessKey pair
-
The RAM user to which the abnormal AccessKey pair belongs can manage RAM.
-
The RAM user to which the abnormal AccessKey pair belongs has administrator permissions.
Sensitive assets
The attack path analysis feature allows you to configure specific sensitive assets and use the sensitive assets as the target assets of attack path analysis tasks to check whether attack path scenarios exist.
-
The role attached to an ECS instance can access sensitive assets.
-
The RAM user to which the abnormal AccessKey pair belongs can access sensitive assets.
-
A role has the permissions to access sensitive assets and can be assumed by other Alibaba Cloud accounts.
If no sensitive assets are configured, the scan results for the corresponding attack path are empty. For more information about how to configure sensitive assets, see Configure sensitive assets below.
Privilege escalation by role
-
An ECS instance can directly obtain administrator permissions through its attached RAM role.
-
The role attached to an ECS instance can manage RAM.
-
An ECS instance can escalate privileges by attaching policies to its attached role.
-
An ECS instance can escalate privileges by modifying the policies of its attached role.
-
An ECS instance can escalate privileges by changing the default version of the policies of its attached role.
-
An ECS instance can escalate privileges by modifying its attached role.
-
An ECS instance can obtain long-term access credentials by creating AccessKey pairs.
-
An ECS instance can obtain long-term access credentials by enabling web console logon for RAM users.
-
An ECS instance can enable web console logon by modifying the logon configurations of RAM users.
-
An ECS instance can escalate privileges by granting policies to RAM users.
-
An ECS instance can escalate privileges by modifying the policies granted to RAM users.
-
An ECS instance can escalate privileges by modifying the user groups of RAM users.
-
An ECS instance can escalate privileges by granting policies to the user groups of RAM users.
-
An ECS instance can escalate privileges by modifying the policies granted to the user groups of RAM users.
-
An ECS instance can escalate privileges by modifying the trust policies of high-risk roles.
-
An ECS instance can escalate privileges by modifying the policies of the roles that RAM users can currently assume.
-
An ECS instance can directly escalate privileges through the roles that RAM users can currently assume.
-
An ECS instance can directly escalate privileges through the roles that its attached instance role can currently assume.
-
An ECS instance can escalate privileges by obtaining the high-risk permissions of the roles attached to other ECS instances.
-
A role has administrator permissions and can be assumed by other Alibaba Cloud accounts.
-
A role can manage RAM and can be assumed by other Alibaba Cloud accounts.
-
A role has high-risk permissions and can be assumed by other Alibaba Cloud accounts.
-
A role can escalate privileges by attaching policies to itself and can be assumed by other Alibaba Cloud accounts.
-
A role can escalate privileges by modifying its own policies and can be assumed by other Alibaba Cloud accounts.
Privilege escalation by user
-
A RAM user can escalate privileges by attaching policies to itself.
-
A RAM user can escalate privileges by modifying its own policies.
-
A RAM user can escalate privileges by attaching policies to its user group.
-
A RAM user can escalate privileges by modifying the policies of its user group.
-
A RAM user can escalate privileges by modifying the trust policy of a role and then assuming the role.
-
A RAM user can escalate privileges by running commands on an ECS instance to obtain role permissions.
-
A RAM user can escalate privileges by sending files on an ECS instance to obtain role permissions.
-
A RAM user can escalate privileges by starting an ECS terminal session to obtain the permissions of a high-risk role.
-
A RAM user can escalate privileges by resetting the password of an ECS instance to obtain the permissions of a high-risk role.
-
A RAM user can escalate privileges by binding an SSH key pair to a Linux server to obtain the permissions of a high-risk role.
-
A RAM user can escalate privileges by creating an instance and attaching an instance role to it to obtain the permissions of a high-risk role.
-
A RAM user can escalate privileges by modifying the role binding configurations of instances to obtain the permissions of a high-risk role.
Enable attack path analysis
After you activate the subscription or pay-as-you-go service of Cloud Security Posture Management, you can use the attack path analysis feature. The feature does not consume the Cloud Security Posture Management quota. For more information about how to activate the Cloud Security Posture Management service, see CSPM overview.
Description of statistics
Attack path analysis results are automatically refreshed every day. The CSPM page in the Security Center console displays the attack paths and detailed information about at-risk assets on the Attack Path tab.
|
Statistical item |
Description |
|
Attack paths that require urgent handling |
The total number of attack paths of high urgency that are detected. |
|
Number of at-risk assets |
The total number of at-risk assets involved in attack paths. |
|
Attack path information |
The list of alerts about attack paths, including information such as attack path name, path type, intruded asset, and target asset. |
Manage attack path scan configurations
Configure sensitive assets
To scan for attack paths that involve sensitive assets in attack path scan tasks, you must configure the corresponding sensitive assets. Otherwise, the scan results for the corresponding attack path are empty.
-
Log on toSecurity Center console.
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
-
On the Attack Path tab of the CSPM page, click Policy Management in the upper-right corner or click Scan Configuration in the Attack Path Scan section.
-
In the left-side navigation pane of the Sensitive Asset to Scan tab, click an asset type, and then select the check box that precedes the target asset in the asset list on the right.
-
Click OK.
Configure a whitelist
If you confirm that attack path scans are not required between specific entry assets and destination assets, you can add the target assets and the corresponding attack path rules to a whitelist. Security Center does not report the attack path information in the whitelist afterward.
-
On the Attack Path tab of the CSPM page, click Policy Management in the upper-right corner or click Scan Configuration in the Attack Path Scan section.
-
On the Whitelist Policy tab, click the By Attack Path tab.
-
Click Create Rule, configure the whitelist rule parameters, and then click OK.
Parameter
Description
Whitelist policy name
The custom name of the whitelist rule. Only Chinese characters, letters, digits, and underscores (_) are supported.
Path type selection
The path type to add to the whitelist. Valid values: abnormal AccessKey pair, sensitive asset, privilege escalation by role, and privilege escalation by user.
Attack path selection
The attack paths to add to the whitelist for the selected path type.
Assets to which the rule applies
The assets to add to the whitelist. Valid values: All Assets and Specific Assets.
If you select Specific Assets, you must select the Source Assets and Destination Assets of the attack path.
Attack path scan tasks
Security Center automatically runs a scan task once a day based on the supported asset types and attack paths.
-
If no sensitive assets are configured, the scan results of the corresponding attack path rules are empty.
-
If a whitelist is configured, Security Center does not scan the attack path rules between the entry assets and destination assets in the whitelist or generate alerts for the rules.
Manually run an attack path scan task
On the Attack Path tab of the CSPM page, click Quick Scan in the Attack Path Scan section.
View task information
Security Center provides the Task Management page, which records the automatic and manual scan tasks that were initiated within the previous seven days by default.
-
On the CSPM page, click Task Management in the upper-right corner.
-
On the Task Management page, you can view Task ID, Task Type, Start Time/End Time, and Status (To Be Started, Complete, Timed Out, In Progress, or Failed) information and the task progress percentage.
-
Click Details for a task to view the asset details of the scan task, including the number of at-risk assets, the number of risk paths, the number of assets that were successfully scanned, the number of assets that failed to be scanned, and the asset list.
You can filter and view the scan results of specific assets by status, asset type, and at-risk asset ID.
View attack path details
-
On the CSPM page, view the list of attack paths that trigger attack path rules on the Attack Path tab. The list contains the following information.
The top of the page displays the statistics about the number of attack paths that require urgent handling and the number of at-risk assets. You can filter attack paths by urgency, path type, or attack path name. The Actions column of the list provides the Details and Add to Whitelist operations.
Alert item
Description
Urgency
The risk level of the attack path: Urgent (red), Suspicious (orange), or Notice (gray).
Attack path name
The name of the triggered attack path.
Path type
The type of the triggered attack path: abnormal AccessKey pair, sensitive asset, privilege escalation by role, or privilege escalation by user.
Intruded asset and target asset
The information about the entry asset and destination asset of the current attack path.
Last occurrence time
The last occurrence time of the current attack path.
-
Click Details in the Actions column of an attack path to view the basic information, attack path information, fix solution, and attack path graph of the attack path.
-
Basic Information: includes the urgency, path type, first detection time, and latest detection time.
-
Compromised Assets and Asset Types or Targeted Asset and Asset Type: displays the instance IDs and asset types of the intruded and target assets. Click an instance ID to go to the details page of the corresponding asset in Asset Center and view the details of the at-risk asset.
-
Attack Path Information: displays the detection logic of the attack path.
-
Solution: provides suggestions and operation guidance on how to fix the attack path.
-
Attack Path Graph: displays the relationships between the assets involved in the attack path.
-
A red line between two nodes indicates a risk. Click the red line to view the corresponding fix suggestions.
The left side of the fix solution details page displays the suggestions. For example, the system may suggest that you review and revoke unnecessary RAM instance roles on the host, make sure that only the roles required by your business are attached, and avoid attaching administrative permissions such as
AdministratorAccess,AliyunRAMFullAccess, andAliyunECSFullAccess. If an instance role is attached without authorization, unbind the role immediately and perform further review. Operation path: Go to the ECS console, select the region where the host resides, go to Instance Details > Other Information > RAM Role, and then click Grant/Revoke RAM Role. The right side displays the corresponding attack path graph, which shows the attack topology from the compromised host through a high-privilege user to the policy attach operation (ram:AttachPolicyTo...). -
Click a node to view the basic information of the node and the associated vulnerability risks.
The basic information includes fields such as Instance Name, Instance ID, Region, and Instance Type. The associated vulnerability risks are displayed in a table that shows vulnerability names (such as
CVE-2024-21626) and the Details operation entry. The attack path graph on the right displays the complete attack chain from a container or Kubernetes node through vulnerability exploitation and API access to RAM privilege escalation in a topology. -
Click the help
icon in the upper-right corner of the attack path graph to view the node icons and their meanings.The node legend contains the following resource types: RAM role, RAM user group, policy, AK, API, ECS instance, ECI container, OSS bucket, alert, vulnerability, network service, IP address, and primary account or RAM account.
-
Click the settings
icon in the upper-right corner of the attack path graph to configure the layout of the attack path graph.The layout includes the line style (straight line or polyline), the distance between nodes (adjusted by using a slider), and the layout direction (RIGHT, LEFT, DOWN, or UP).
-
Click the download
icon in the upper-right corner of the attack path graph to export the attack path graph. You can share the attack path graph with security administrators to improve the analysis efficiency of attack tracing for target assets.
-
-
Add attack paths to a whitelist
If you confirm that the attack paths that are detected by attack path scan tasks can be ignored, you can use the whitelist feature.
-
On the Attack Path tab of the CSPM page, click Add to Whitelist in the Actions column of an attack path.
-
In the dialog box that appears, enter a value for Whitelist Name and select the rule that takes effect for the whitelist.
-
All Assets: This mode takes effect on attack path rules. Assets added after the whitelist rule is created do not generate alerts.
-
Current Asset: This mode takes effect only on the intruded assets and target assets included in the current attack path.
-
-
Click OK.
You can view the added whitelist information on the By Attack Path tab in the Application Whitelist tab of the Policy Management panel.
Related documents
-
If you need to handle the vulnerabilities that are detected on assets, refer to the following documents.
-
If you need to handle the urgent alerts that are detected on assets, see Respond to security alerts.
-
If you need to manage the policies of RAM users and roles, see Identity and access management.