Detect vulnerabilities and monitor security events in ACK clusters with Security Center, including malicious images, malware attacks, container intrusions, container escapes, and high-risk operations.
Prerequisites
Ensure the following:
-
An ACK cluster is created.
-
Security Center is activated.
-
(RAM users only) The AliyunYundunSASReadOnlyAccess policy is attached to your RAM user account.
View security monitoring
-
Log on to the ACK console. In the left-side navigation pane, click Clusters.
-
On the Clusters page, click the target cluster. In the left-side navigation pane, choose Security > Security Monitoring.
-
On the Security Monitoring page, review the following sections.
Alerts
Shows alerts for malware and virus attacks at the container and host level, container intrusions, container escapes, and high-risk operations. See Container firewall.
Click Alerts to perform the following operations.
Handle an alert
Click Handle in the Actions column. In the dialog box, add the alert to the whitelist or ignore it.
Investigate an alert
Click Details in the Actions column. The details page shows the event time, affected assets, and process ID. Click Diagnosis to trace the event source and view raw data.
Vulnerabilities
Lists Linux and application vulnerabilities in cluster assets. See Vulnerability Management.
Click Vulnerabilities to perform the following operations.
Review and fix a vulnerability
Click the vulnerability name or Handle in the Actions column to view details and pending vulnerabilities. The details page provides fix suggestions. From the list, fix vulnerabilities, verify fixes, or view details.
Look up a CVE
Click CVE ID next to a vulnerability to view its entry in the Alibaba Cloud vulnerability library.
Baseline risks
Identifies risks in ECS instance operating systems, databases, software, and containers to strengthen security posture, reduce intrusion risk, and meet compliance requirements. See Baseline check.
Click Baseline Risks. Click Details in the Actions column to view the risk description and affected assets.
Container firewall alerts
The container firewall is a firewall service for container environments. It generates alerts or blocks abnormal container behavior when hackers exploit vulnerabilities or malicious images to invade the cluster.when vulnerabilities or malicious images are exploited. See Overview .
Click Alerts Generated by Container Firewall to view the alert list.
Each alert entry shows the severity level, alert name, source, targeted network objects, ports, clusters, and defense mode.
To update an alert rule, click Edit Rule in the Actions column.