Security Situation Large Screen
Security operations often require a single screen to monitor the security status of cloud assets and external attack trends. The Security Situation Large Screen transforms security attack and defense data into a large-screen view, displaying the current network security posture of assets from three dimensions: current asset security, external attacks, and threats, helping you understand the security situation in a timely manner and quickly identify and resolve security issues.
Limitation
Before using the Security Situation Large Screen, confirm the following limits and quotas:
Site limit: The Security Dashboard tab is available only on the China site (aliyun.com). The international site does not provide this feature.
Region limit: Some regions do not support this tab. Refer to the actual console display.
Activation requirement: You must separately activate Security Dashboard before first use. Activation requires placing an order and completing payment. For the operation procedure, see Activate Security Dashboard.
Browser requirement: We recommend that you use the latest version of Google Chrome to access the Security Situation Large Screen.
Password-free address quota: You can create a maximum of 5 password-free addresses. Password-free days is a required numeric configuration item. The default value is 30, and the value range is 1 to 100, specifying the validity period of the password-free address in days.
Activate Security Dashboard
You must activate Security Dashboard before you use the Security Situation Large Screen for the first time.
Log on to the Security Center console and click Overview in the left-side navigation pane.
On the Security Dashboard tab, click Buy Now.
On the Order Upgrade page, select Yes in the Security Dashboard section, and then click Order Now and complete the payment.
Return to the Security Dashboard tab to enter the large screen. Two entries coexist under the Security Dashboard tab. Select one based on your display objective:
Security Dashboard: displays the current security status, external attacks, and threats of cloud assets.
Eye of Horus: manages cloud security assets and network topology from a global perspective. Custom configuration is not supported.
Configure Security Dashboard
There are two ways to adjust the large screen display content: directly modify the title and displayed data of the current large screen (the operations in this section, default path), which is suitable for scenarios where only one display plan is needed; or create a custom scenario and switch between scenarios as needed, which is suitable for scenarios where different business domains require multiple display plans to coexist. For the operations for custom scenarios, see Configure custom Security Dashboard.
Log on to the Security Center console and click Overview in the left-side navigation pane.
On the Security Dashboard tab, click the Security Dashboard in the upper-right corner.
On the Security Dashboard page, click the
icon in the upper-right corner.On the Content Configuration tab, set the title text, title image, and other information to be displayed on the large screen.
Click Select Data on the module where you want to modify the displayed data, and then sequentially select the data category, select business components, and set the time range on the Select Data tab.
Optional data categories include All, Assets, Vulnerabilities, Baselines, Alerts, Security Operations, and Cloud Platform Best Practices. After you select a category, you can select the business components to display under that category (for example, the Security Operations category includes components such as security posture, attack types, top 5 attack sources, attack trends, and top 5 attacked assets) and set the time range for the data (for example, Last 24 Hours).
Click Save Settings at the top of the page.
Configure custom Security Dashboard
To meet the needs of different business domains to display data for different scenarios, the Security Situation Large Screen supports custom scenarios. You can customize multiple large-screen scenarios based on business requirements and switch between them as needed.
Log on to the Security Center console and click Overview in the left-side navigation pane.
On the Security Dashboard tab, click the Security Dashboard in the upper-right corner.
On the Security Dashboard page, click the
icon in the upper-right corner.On the Scenario List page, click Add Scenario.
Set the title information and displayed data for the scenario by following Steps 2 to 4 in Configure Security Dashboard, and then click Save Settings.
After a scenario is added, the system enables it by default, and you can view the relevant data of the scenario on the large screen. To display another scenario, locate the target scenario on the Scenario List page and click Enable Now.
Set up Security Dashboard password-free access
Password-free access eliminates the need to navigate through the console levels each time, but not the logon to your Alibaba Cloud account. After you configure password-free access, you can use the password-free address to quickly enter the Security Situation Large Screen, but you must still log on to your Alibaba Cloud account before accessing the password-free address.
Go to the Security Dashboard tab of the Security Center console, hover over the Security Dashboard area, and click Logon-free Configuration.
If you use this feature for the first time, authorization is required. Follow the on-screen instructions to complete the authorization configuration.
On the Logon-free Configuration dialog box, on the Create Logon-free URL tab, set the password-free days and click Obtain Token.
After the token is obtained, Security Center automatically generates a password-free token and a password-free large-screen address. You can directly use the password-free large-screen address to enter the Security Situation Large Screen.
(Optional) On the Logon-free Configuration dialog box, on the Existing Logon-free Tokens tab, view existing password-free tokens, access the large screen through the password-free address, or delete password-free tokens. When a password-free address is no longer needed or needs to be revoked, delete the corresponding password-free token here to invalidate it. You need to confirm the operation in the confirmation dialog box. After the deletion is successful, the list is automatically refreshed.