This document describes how to identify unknown risks beyond access control rules, perform intrusion prevention rule detection on the north-south traffic, and prevent vulnerabilities in Cloud Virtual Machine (CVM) from being exposed to the Internet through the intrusion prevention feature.
Operation Guide
Enabling Threat Intelligence
- After threat intelligence is enabled, CFW forwards protection traffic to the threat intelligence detection and analysis engine to identify unknown risks beyond access control rules.
- Log in to the CFW console. In the left sidebar, select Intrusion Prevention to go to the Intrusion Prevention page.
- On the Intrusion Prevention page, click the icon next to Threat Intelligence to enable this feature.
- After threat intelligence is enabled, CFW forwards protection traffic to the threat intelligence detection and analysis engine to identify unknown risks beyond access control rules.
- External malicious access: CFW monitors and identifies external access to cloud assets from malicious IP addresses and threat samples, such as malicious scans, brute force cracking, mining trojans, ransomware attacks, and remote control.
- Proactive outgoing access: CFW monitors and identifies proactive outgoing access from cloud assets to external malicious IP addresses or domain names, and determines potential host compromise risks through the comparative analysis of big data provided by threat intelligence.
Enabling Basic Prevention
- Log in to the CFW console. In the left sidebar, click Intrusion Prevention to go to the Intrusion Prevention page.
- On the Intrusion Prevention page, find the Basic Prevention module and click View Rules to pop up the Basic Prevention Rules window.
- In the Basic Prevention Rules pop-up window, view the IPS rule list. You can click any rule ID to view its corresponding description.
- Click
to enable or disable the rule for NAT and VPC firewalls.
If the versions of some firewall engines are too early, the prevention rules that rely on later engine versions will not take effect for earlier versions of firewall instances. However, basic prevention rules may still remain effective.
- In the Current Action column, select the action after a rule is hit. Rule actions take effect only for the assets whose protection mode is the interception mode.
Custom intrusion prevention rules only take effect for NAT Firewall and VPC boundary firewalls. If the versions of some firewall engines are too early, the custom intrusion prevention rules will not take effect for the corresponding firewalls.
- For all IPS rules, provide keyword searching, one-click reset, and batch operations.
- Keyword searching: You can query the corresponding rules based on rule attributes, and then configure the toggle status and handling actions.
- One-click reset: You can restore the toggle status of all rules with one click and change a rule action to the default action to make the corresponding rule take effect immediately.
- Batch operations: You can select multiple rules and enable or disable them or change their handling actions in batches.
- After viewing the rules, click
in the Basic Prevention module to enable this feature.
After Basic Prevention is disabled, all basic prevention rules no longer take effect. In interception mode, malicious behaviors that hit high-confidence rules are automatically intercepted, and security event alarms are generated when other rules are hit.
Enabling Virtual Patching
- Log in to the CFW console. In the left sidebar, click Intrusion Prevention to go to the Intrusion Prevention page.
- On the Intrusion Prevention page, find the Virtual Patching module and click View Rules to pop up the Virtual Patching Rules window.
- For specific rule operations, see the preceding basic prevention rules.
- Click
in the Virtual Patching module to enable this feature.
Protection Mode Description
- Log in to the CFW console. In the left sidebar, click Intrusion Prevention to go to the Intrusion Prevention page.
- On the Intrusion Prevention page, locate the Protection Mode module to configure the protection mode.
- Protection modes include the observation mode, interception mode, and strict mode.
The observation mode is used by default.
- Observation Mode: threat intelligence, basic prevention, and virtual patching are all in detection mode. Only alarms are generated for malicious access or network attack behaviors; connections are not blocked.
- Interception Mode: high-confidence network attacks or malicious access are automatically intercepted. Threat intelligence supports automatic interception of outbound malicious access. Basic prevention supports automatic interception of high-confidence rule alarms. Virtual patching supports automatic interception of traffic detected as vulnerability exploits.
- Strict Mode: threat intelligence (except threat intelligence detection for outbound domain names), basic prevention, and virtual patching are all in global interception mode. Any detected alarms automatically block connections, but false positives may occur. Suitable for critical period guarantees or attack and defense scenarios.
Feature Dynamic Description
- Log in to the CFW console. In the left sidebar, click Intrusion Prevention to go to the Intrusion Prevention page.
- On the right side of the Intrusion Prevention page, view the feature dynamics and feature descriptions:
- Feature Dynamic: view the features of the intrusion prevention module.
Managing the Blocklist (IPS Blocklist) and Allowlist Policy
- Log in to the CFW console. In the left sidebar, click Intrusion Prevention to go to the Intrusion Prevention page.
- On the Intrusion Prevention page, view the blocklist and allowlist policy.
Blocklist
Viewing the Blocklist
Click Blocklist to go to the Blocklist tab.
Disabling the Blocklist
In case of emergency, click
to disable the Enable Blocklist switch.
Managing the Effective Time of the Blocklist
When an IP address in the blocklist expires, it is automatically deleted and subsequent access traffic is not blocked. To prevent deletion, click Edit in the Operation column to modify the expiration time.
For IP addresses in the blocklist, all traffic passing through CFW in the outbound or inbound direction is blocked and recorded in Intrusion Prevention Logs under Log Audit.
Allowlist Policy
Viewing the Allowlist Policy
Click Allowlist Policy to go to the Allowlist Policy tab.
The IPS feature is bypassed for IP addresses in the allowlist policy.
Managing the Allowlist Policy Effective Time
When an IP address in the allowlist policy expires, it is automatically deleted and subsequent access does not bypass the IPS feature. To prevent deletion, click Edit in the Operation column to modify the end time and date.
to enable or disable the rule for NAT and VPC firewalls.
in the Basic Prevention module to enable this feature.
in the Virtual Patching module to enable this feature.