Basic security services

更新时间:
复制 MD 格式

Simple Application Server is integrated with Alibaba Cloud Security Center. Security Center protects your Simple Application Server instances by providing a closed-loop security operations system that automates threat detection, alert response, and attack tracing with capabilities such as anti-ransomware, antivirus, tamper protection, and compliance checks.

Background information

Security Center is a unified security management system that identifies, analyzes, and warns of security threats in real time. It provides a closed-loop security operations system that automates threat detection, alert response, and attack tracing. This system protects your cloud and on-premises servers and helps you meet regulatory compliance requirements. For more information, see What is Security Center?.

Security Center Free provides basic security hardening for Simple Application Server instances. It supports the detection of unusual logons, DDoS attacks, mainstream vulnerabilities, and insecure cloud product configurations. For more information, see Security Center Free overview.

Note

Security Center is available in multiple editions: Free, Anti-Virus, Advanced, Enterprise, and Ultimate. By default, Simple Application Server instances are protected by the Free edition, which covers a limited set of protection features. If you have higher security requirements, purchase another edition. For a comparison of the features available in each edition, see Features.

View and handle alert events

Simple Application Server is integrated with Alibaba Cloud Security Center. You can view the security status of a server on its server card. To keep your Simple Application Server instance secure, we recommend that you review and handle detected alert events promptly.

  1. Go to the Servers page in the Simple Application Server console.

  2. Click the instance ID on the server card.

    Note

    If there are urgent alerts, an Anomaly Event tag appears on the server card.

  3. Click the Security Protection tab. On tabs such as Unusual Location Logon and Brute-force Attack, you can view the details of specific alert events.

    The alert event list includes the Severity, Alert name, Affected asset, Last occurred, and Actions columns. You can filter alerts by severity, handling status by using the Handled drop-down list, or date range. In the Actions column, click Handle or Details to view and handle an alert.

    In the Simple Application Server console, you can view and handle only the security alerts listed in the following table. For information about how to handle other security alerts, see Assess and handle security alerts.

    Note

    Security Center provides a comprehensive overview of its threat detection capabilities by classifying all detectable alert events by operating system, analysis target, and attack method. For more information, see CWPP (cloud workload) security alert overview.

    Actions

    Description

    Related documentation

    Click the Unusual Location Logon tab.

    You can view alert events for unusual location logons.

    The system automatically records common logon locations for your Simple Application Server instance. You can also manually add common logon locations in the Security Center console. An alert is triggered if a logon occurs from a location not on the common location list.

    • If you confirm the logon was legitimate, you can ignore the alert or add the location to your common logon locations.

    • If you do not recognize the logon activity, your password may have been compromised. Change your password immediately.

    Security alerts

    Click the Brute-force Attack tab.

    You can view alert events for successful logons on your Simple Application Server instance that occurred after multiple failed attempts.

    Security Center reports an alert when it detects a successful login to your Simple Application Server that occurs after multiple failed login attempts. This activity may indicate a brute-force attack. We recommend that you change your password as soon as possible.

    Click the Webshell Detection tab.

    You can isolate detected webshell files with a single click in the console. Isolated files can be recovered within 30 days.

    Click the Malware tab.

    Security Center uses a cloud-based scanning mechanism to regularly scan processes and monitor startup events for viruses and trojans.

    Click the Precision Defense tab.

    This feature automatically isolates common network viruses, including mainstream ransomware, DDoS trojans, cryptominers, malware, backdoors, and worms. Alibaba Cloud security experts test and validate all supported viruses to ensure zero false positives.CWPP security alerts

    Click the Emergency Vulnerability tab.

    This feature checks for recently discovered, high-risk vulnerabilities on your server. This helps you promptly identify critical vulnerabilities in your system and reduce the risk of intrusion. Emergency vulnerabilities cannot be fixed with one click. You must fix them manually based on the provided recommendations.

    View and handle vulnerabilities

  4. In the Actions column for the target alert, click Handle.

    You can click Actions in the View Details column to view more information about the alert event.

  5. In the dialog box that appears, select a handling method for the alert, and then click Handle Now.

    For information about handling methods, see Handling methods for alert events.

  6. In the Alert Handling dialog box, click OK.

Configure alert notifications

Security Center lets you configure notifications for security alerts. You can receive notifications by SMS, email, and internal message.

  1. Go to the Security Center console - Notification Settings.

  2. In the SMS/Email/Internal Message tab, in the Security Alert section, select an alert level, and set the notification method and time.

    Available alert levels are High, Medium, and Low. You can choose to be notified by SMS, Email, or Internal Message. Notification times can be set to 8:00-22:00 or 24/7.