FAQ about container protection

Updated at:

This topic provides answers to frequently asked questions about container protection in Security Center.

Can I use container microsegmentation if I am using the Enterprise Edition?

No. Only the Ultimate Edition supports this feature. Other editions do not support container microsegmentation.

  • Subscription: Ultimate (If your current edition does not support this feature, upgrade).

    Note

    The protection edition of the server must be set to the edition you purchased. For more information, see Bind a server protection edition.

  • Pay-as-you-go: Host and Container Security pay-as-you-go is activated (If not activated, purchase).

    Note

    The server protection level must be set to Full Protection for Hosts and Containers. For more information, see Bind a server protection level.

Do I need to pay extra for container microsegmentation?

No. After you activate the Ultimate Edition, you can use container microsegmentation directly.

Does upgrading to the Ultimate Edition mean that Security Center only protects containers but not ECS instances?

No. The Ultimate Edition protects both containers and ECS instances.

What container image detection mechanisms does Security Center provide to ensure the security of container runtime?

Security Center leverages cloud-native capabilities to provide the following container image detection mechanisms to reduce the risks of container intrusion and tampering.

image

Image security

  • Images added to Security Center (image security scanning)

    Container Registry Enterprise Edition, third-party image repositories such as Harbor and Quay that are added to Security Center are provided with comprehensive security detection and management capabilities. These capabilities help you detect high-risk system vulnerabilities, application vulnerabilities, malicious samples, baseline configuration risks, sensitive files, and image build command risks in images. For system vulnerabilities detected in images, fix solutions are provided to help you resolve security issues in a timely manner.

    For more information, see Image security scanning.

  • Images not added to Security Center (CI/CD plug-in integration)

    You only need to integrate the CI/CD plug-in (image security scanning plug-in for Security Center) with Jenkins or GitHub. This allows you to trigger image security scanning tasks during the build process in Jenkins or GitHub. The scanning detects high-risk system vulnerabilities, application vulnerabilities, malicious viruses, webshells, malicious execution scripts, baseline configuration risks, and sensitive data in images, and provides fix recommendations to help you detect security risks in images more efficiently.

    For more information, see CI/CD integration.

  • Image launch interception (at-risk image blocking)

    After you create an at-risk image blocking rule, Security Center performs security checks on images used to create resources in the specified cluster. For images that match the at-risk image blocking rule (malicious Internet images, unscanned images, malicious samples, baseline risks, vulnerabilities, sensitive files, and image build command risks), Security Center intercepts, alerts, or allows the image launch to ensure that the images started in the cluster meet your security requirements.

    You can go to the Image Repository tab on the Container Assets page to search for and view the risks of target images by image ID or tag, and then handle related vulnerabilities and risks based on the risk details and fix suggestions.

    For more information, see Risk Image Blocking.

Container security

  • Container runtime image scanning

    Detects security risks in container runtime, including system vulnerabilities, application vulnerabilities, baseline checks, malicious samples, and sensitive files. Fix solutions are provided for container image system vulnerabilities to help you resolve security issues in a timely manner.

    For more information, see Container runtime image scanning.

  • Configure proactive defense rules for containers

    Proactively detects security risks during container startup or runtime from multiple dimensions: container security, runtime security, and running environment security. By configuring corresponding rules, you can stop untrusted processes and block container escape behaviors to improve the overall security of the container runtime environment.

    • Non-image Program Defense:

      Program starts from outside the image during container runtime are considered abnormal behavior. Such behavior is likely caused by hackers inserting trojans or other malicious software.

      After you create a Non-image Program Defense rule, Security Center can detect and block program starts from outside the image, proactively defend against malicious software intrusions, and help you defend against known or unknown attack patterns.

    • Container Escape Prevention:

      When containers share the OS kernel with the host server, attackers can exploit container vulnerabilities to escalate privileges and gain access to the host server system or other containers, affecting the overall system security. Configuring container escape prevention rules can effectively block escape behaviors and ensure container runtime security.

    For more information, see Proactive Container Defense.

  • Configure container file defense rules

    Monitors directories or files in containers in real time, and generates alerts or blocks tampering behaviors when directories or files in containers are maliciously tampered with, ensuring the normal operation of the container environment.

    For more information, see Container file protection.

  • Block abnormal container access

    Integrates information such as namespaces, application names, images, and tags of applications in containers into network objects, and creates defense rules for access traffic between two network objects to implement traffic control from source network objects to destination network objects. When hackers exploit vulnerabilities or malicious images to intrude into container clusters, container microsegmentation generates alerts for or blocks abnormal container behaviors.

    For more information, see Container microsegmentation.

  • Deploy trusted containers

    Implements trusted signing for container images, ensures that only container images signed by trusted and authorized parties are deployed, and prevents unsigned images from being started, fundamentally helping you improve the security of your assets.

    For more information, see Container image signing.

  • Detect container baseline configurations

    Provides security detection and alerts for container configurations. Based on Alibaba Cloud best practices for container security, it performs risk checks on Kubernetes Master and Node nodes for container baseline configurations.

    For more information, see Baseline risk check.

Host security for the servers that run containers

For more information about host security protection, see Host protection features of Security Center.

How do I use container microsegmentation to manage business traffic in the container environment?

The Ultimate Edition of Security Center provides container microsegmentation. Container microsegmentation integrates the namespaces, application names, container images, and tag information of applications in a cluster into network objects as identifiers to differentiate container applications. Then, defense rules for network access are created between network objects to detect, intercept, and generate alerts for abnormal access traffic, achieving network isolation in the container environment.

Important
  • The normal operation of cluster defense rules depends on the AliNet plug-in, which is mainly used for network connection interception, DNS interception, and brute-force attack interception. Before using container microsegmentation, make sure that the OS kernel versions of your cluster nodes are within the supported range of the AliNet plug-in. Otherwise, cluster defense rules will not take effect. For the supported OS kernel versions, see Supported operating systems.

  • To use the container microsegmentation feature of Security Center, you must enable the Malicious Behavior Defense feature. For more information, see Host protection settings.

  1. Perform the following steps to configure and enable defense rules for container clusters that are added to Security Center.

    1. Create source and destination network objects.

    2. Create and enable a defense rule.

    3. Enable cluster defense.

      Cluster defense can be enabled only when the interceptable status is normal, and the enabled defense rules can take effect. If the interceptable status of cluster defense rules is abnormal, you need to troubleshoot the issue first. For more information, see Troubleshoot abnormal blocking status of cluster defense rules.

  2. For container clusters that are added to Security Center, when access traffic is generated, detection is performed based on the priority of defense rules in container microsegmentation, and abnormal access traffic is intercepted or alerted. If the action of a matched defense rule is Allow, or no defense rule is matched, container microsegmentation allows the current access.

    Alert or block actions generate alert events. For more information, see Protection status.

What do I do if I receive the error code TaskNumEmpty when running a container image scan task?

  • Cause: When you run a container image scan task, the error message The number of created tasks is empty is returned with the error code TaskNumEmpty. This is because the image creation or update time is earlier than the scan time range set in the scan configuration, resulting in an empty list of scannable images.

  • Solution: On the Container Image Scan page, go to Scan Settings and modify the Scan Time Range so that the scan time range covers the image creation or update time. For more information, see Step 1: Configure the image scan scope.

The image security scan task status is Successful, but the actual scan count is 0. What do I do?

  • Cause: After an image security scan task is executed, the task status is Successful (as shown in the following figure), but the actual number of scanned images is 0. This may be caused by the following reasons:

    • No new images are created or updated within the scan time range. For example, if the scan time range is set to the last 7 days, Security Center scans images updated within the last 7 days. Images updated more than 7 days ago are not scanned.

    • The maximum scan time range is 365 days. Images created or last updated more than 365 days ago are not supported for scanning.

    • Security Center synchronizes image data from Alibaba Cloud Container Registry (ACR) daily in the early morning. Image data updated on the current day may not be collected, resulting in images not being scanned.

  • Solution: For more information, see Run a manual scan.

    1. Confirm the creation or update time of the images to be scanned. If it exceeds 365 days, scanning is not supported.

    2. Set the scan time range for container image security scanning based on the creation or update time of the images to be scanned.

    3. Go to the Security Center console - Asset Center - Container Assets page. On the Image Repository tab, click Synchronize Assets.

    4. Perform an image security scan.