Security Overview

Last Updated At: 2025-11-26 14:18:25

This document will introduce the features and directions of each module of Security Overview.

Overview

The security overview of Cloud Workload Protection Platform (CWPP) displays your cloud workload protection score, pending risks, security protection status, risk trends and real-time dynamics of CWPP in real time; it offers documentation and upgrade service recommendations for CWPP to help you defend against hacker intrusion risks and attack threats, ensuring the security of enterprise hosts.

Operation Guide

1.Log in to the tenant-side console of CWPP.
2.Select Security Overview in the left navigation to view security overview information and related processing operations. The module descriptions are as follows.

Security Status

  1. In the security status, your cloud workload protection score and the following three types of security risks are shown, and a quick processing entry is provided.
    • Intrusion detection: includes 7 features of the intrusion detection module, namely malicious file scan, abnormal login, password cracking, malicious request, rebound Shell, local privilege escalation, high-risk command, and consolidated statistics of the number of pending risks and number of affected hosts.
    • Vulnerability risk: includes Linux software vulnerabilities, Windows system vulnerabilities, Web-CMS vulnerabilities, application vulnerabilities, and consolidated statistics of the number of pending risks and number of affected hosts.
    • Baseline risk: only count the number of pending baseline risks and the number of affected hosts.
  2. The CWP status is divided into 3 levels:
Level Health Checkup Score Text Color Status Description
Excellent 90-100 points Green The asset safety status is good and needs to be maintained and inspected regularly.
Medium-risk 60-89 points Orange There are relatively many security risks in assets. It is recommended that you handle security incidents in a timely manner.
High-risk 20-59 points Red Serious security risks exist in the assets. Handle the security incident as soon as possible.

Note:

The lowest health checkup score for CWPP status is 20 points.

Deduction items will be calculated based on the classification of security incidents. The following are the security incident classification and deduction rules:

Security Event (Counted by Number of Events) Point Deduction Per Instance Maximum Points Lost
Severe Trojans, viruses, and successful brute force attacks. 50 points
High-risk High-risk vulnerabilities, high-risk baselines, remote log-in, local privilege escalation, rebound shell, and high-risk commands. 10 points
Medium-risk Medium-risk vulnerabilities, medium-risk baselines. 3 points
Low-risk Low-risk vulnerabilities and low-risk baselines. 2 points
Others Basic editions (non-protected state). 1 point

Security Protection

  1. In Security Protection, show the full-process solution (prevention-defense-detection-response) provided by CWPP to deal with intrusion attacks, and display in detail the security protection items required at each stage. If all protection features are activated, intuitively understand the current situation of your host security and provide quick access to security risk handling.

Protection Detail

In Protection Detail, you can view the total number of hosts, total number of online hosts, number of shutdown or offline hosts, number of hosts without client installation, number of protected hosts, number of Ultimate Edition hosts, number of Basic Edition hosts. It also provides asset update time, virus database update time, vulnerability database update time, and security engine protection information.

Note:

Since the protection level of the basic edition host is relatively weak, the number of protected hosts contains only Ultimate Edition hosts.

Risk Trend

The risk trend feature uses a line chart to show you the security risk and threat trends in the past 7 days, 14 days, or 30 days, and supports filtering and viewing by time period. Hovering the mouse over the trend chart will display the number of security events such as file detection, password cracking, exception log-in, vulnerability risk, baseline risk, etc. on that date. Click the upper right corner to download the security event count for the selected date to your computer.

Note:

The data source is the number of newly added pending events on the day, which is updated every hour. Historical events will be retained and will not change.

Real-Time Dynamic

The real-time dynamic feature displays discovered host risks and threat events in real time in reverse chronological order. Click the host IP in the blue field to navigate to Host Details, where you can view various risks of this host security; click View Detail to jump to the corresponding event handling page.