Attack Surface Management is an independently sold security feature. We recommend using it with Security Center Premium Edition or later and the Cloud Security Posture Management feature. When the number of assets grows beyond the purchased quota, burstable protection automatically covers the excess.
Purchase Attack Surface Management
Subscription
Visit the Attack Surface Management purchase page and complete the following configuration:
Attack Surface Management edition: Only Basic Edition is currently supported.
Assets: The number of authorizations for protected assets. One asset consumes one authorization (includes 6,000 credits).
Duration: Service duration.
After you complete the configuration, click Buy Now.
Pay-as-you-go
Visit the Attack Surface Management purchase page.
Select the Pay-as-you-go billing method and click Create Now.
Enable and disable Full Protection
After you purchase Attack Surface Management, Full Protection is enabled by default. You can also manually enable or disable burstable protection.
After Full Protection is enabled, when the number of authorizations or credits exceeds the subscription quota, the excess is automatically billed at overage rates to ensure that security protection is not interrupted due to quota exhaustion. For billing details, see Hybrid billing (burstable protection).
Log on to the Security Center console.
On the Overview page, in the Attack Surface Management section, turn on or turn off the Full Protection switch.
Change configuration (upgrade or downgrade)
-
Log on to the Security Center console.
-
On the Overview page, in the Attack Surface Management section, click Change Configuration.
-
In the configuration change, select Upgrade Now or Specification Downgrade to go to the configuration page.
-
Re-enter the asset count, and then click Buy Now.
Billing
Subscription:
-
Billing method: You are billed based on the number of protected asset quotas. Each quota includes a certain number of credits.
NoteCredits are the scanning quota units of Attack Surface Management. Each scan consumes a certain number of credits, which are used to draw attack paths of exposed assets, perform intelligent risk analysis, and generate intelligent risk remediation suggestions. The actual number of credits consumed depends on the system usage.
-
Billing rules: USD 5/quota/month. Each quota includes 6,000 credits.
-
Pay-as-you-go:
Billing method: Metered by number of protected assets and the Credits consumed by scanning.
NoteCredits are the scanning quota unit for attack surface management. Each scan consumes a certain number of Credits, which are used for attack path mapping of exposed assets, intelligent risk details, and generation of intelligent risk remediation suggestions. Actual Credits consumed are subject to the system's actual usage.
Billing cycle: Settled daily.
Price:
Assets: USD 0.5/day/asset. Each asset includes 200 Credits by default.
Excess Credits: USD 0.15/100 Credits.
Hybrid billing:
Billing method: Billing is based on the number of protected asset authorizations. Each authorization includes a certain number of Credits.
NoteCredits are the scanning quota unit for attack surface management. Each scan consumes a certain number of Credits, which are used for attack path mapping of exposed assets, intelligent risk analysis, and generation of intelligent risk remediation suggestions. The actual number of Credits consumed is subject to the system's actual usage.
Billing rules: After Full Protection is enabled, if the number of authorizations or Credits exceeds the subscription quota, the excess is charged based on the overage pricing.
Subscription quota: USD 5/authorization/month. Each authorization includes 6,000 Credits.
Overage pricing:
Excess authorizations: USD 0.5/day/authorization. Each excess authorization includes 200 Credits.
Excess Credits: USD 0.15/100 Credits.
For more billing details, see Pay-as-you-go, Subscription, and Hybrid billing (burstable protection).
Expiration or unsubscription
After the subscription expires or you self-unsubscribe from Attack Surface Management via the Unsubscription management page, the following impacts apply:
Instance status: The instance is immediately released and protection stops.
Burstable protection: Burstable protection immediately becomes invalid and stops billing. Elastic authorizations and credits consumed on the current day are billed the next day.
Data retention:
Feature policy configuration data is retained permanently.
Asset and attack path scanning task data is retained for only 7 days and then permanently released.