Cloud Workload Protection Platform (CWPP) Overview
A CWPP is a security solution that protects cloud workloads like virtual machines, containers, and serverless functions across public, private, and hybrid clouds. It provides continuous monitoring, threat detection, vulnerability management, and policy enforcement to keep cloud applications secure and compliant.
Qualifications
The CWPP holds several prestigious international certifications, including the CSA CSTR (Cloud Security Technology Review) from the Cloud Security Alliance./B100: Achieved certification 42 times consecutively with a perfect 100% pass rate
- AV-Comparatives (AV-C): Awarded 29 A+ ratings and recognized as a Top Rated product for three consecutive years
- Gartner: Included in the Market Guide for Cloud Workload Protection Platforms
- AMTSO: Active member of the Anti-Malware Testing Standards Organization
- AVAR: Member of the Association of Anti-Virus Asia Researchers
- EICAR: Member of the European Institute for Computer Anti-Virus Research
How It Works
Install the CWPP agent on the server to enable protection. When you initiate a detection task through the CWPP console, the agent carries out the task and sends the results back. You can then review and manage security events directly from the CWPP console.
| Term | Description |
|---|---|
| CWPP Console | Converge Cloud’s independently developed cloud-native security system offers a comprehensive, all-in-one solution for cloud workload protection, covering prevention, defense, detection, and response. |
| Agent | The official security plugin for CWPP, designed for servers operating in hybrid cloud environments. It synchronizes risk information to the CWPP in real time and executes detection or processing tasks assigned by the CWPP Console. |
| Converge Cloud Servers | CVM, Lighthouse, and ECM. |
| Non-Converge Cloud Servers | Third-party servers and IDC servers |
| A Cloud Workload Protection Platform (CWPP) is a centralized security processing hub designed to continuously monitor and analyze data from various servers. It provides comprehensive protection by leveraging six core security engines, each addressing different aspects of server security: 1. TAV Engine specializes in the efficient detection and removal of binary Trojan viruses. 2. BinaryAI Engine is a deep learning-powered binary analysis engine that effectively identifies and eliminates malicious software samples. 3. Cloud Security Engine utilizes a multi-engine cloud detection system and deep self-learning algorithms to detect and remove common Trojans and viruses globally. 4. Threat Intelligence Engine draws from a vast, constantly updated threat intelligence database to identify malicious files, IP addresses, and domain names. 5. Anti-Attack Engine monitors and defends against real-time cyberattacks, including Webshell threats, exploitation of Struts vulnerabilities, code repository access, code injection, and brute force attacks, offering automated defense mechanisms. 6. Unusual Behavior Engine analyzes abnormal behavior patterns to detect complex, multi-stage threats and provides real-time alerts on suspicious intrusions. |