Using Cloud Security Watcher
    • PDF

    Using Cloud Security Watcher

    • PDF

    Article Summary

    Available in VPC

    You can access the Cloud Security Watcher dashboard, and monitor and evaluate the resources of multi-cloud environment.

    Dashboard screen

    The Cloud Security Watcher manager dashboard is the first screen after login where you can view the agent status and security information at a glance. Each dashboard information item is connected to relevant menu pages and you can check statistics for each period.

    csw-use_01_dashboard_ko

    AreaDescription
    ① 24-hour change status monitoringMenu arranged on an upper end of the dashboard
    ② Service use statusUse status of group, cloud, Region information, VPC/VNet, Subnet, and so on the cloud service in use
    ③ Host statusTotal host status of the cloud service in use
    ④ OS statusThe status of the OS installed on the cloud service in use
    ⑤ Firewall operation statusTotal firewall operation status of the cloud service in use
    ⑥ Server statusServer status registered in the cloud service
    ⑦ Security topologyTopology created based on information per network of host
    ⑧ Resource monitoring real-time notificationDetails of notifications for danger and caution of host status for each threshold value designated when setting policies for hosts registered in the cloud service
    ⑨ Firewall real-time blocking logLatest notification list that have occurred for blocking of firewall of hosts registered in the cloud service

    Assets

    The Assets of Cloud Security Watcher manager provides asset information of each cloud and host and log information that has occurred by the preset application monitoring policies. Access to the desired assets tab (assets monitoring, host monitoring, application monitoring, assets status, details for each asset, remote script management). Through the group selection, the monitoring details for each menu are provided.

    csw-use_02_asset_ko

    Asset monitoring

    Through the main dashboard, summary information on the creation for 24 hours, deletion, creation of Auto Scaling, deletion of Auto Scaling and the like is provided.

    AreaDescription
    ① Assets for each cloudCheck the type and number of all cloud platforms registered in the system
    ② AssetDisplay the total quantity of NACL, ACG, Host, and so on registered in the cloud service
    ③ Host statusArrange and display the types of each server status of the cloud platform in graphs
    ④ OSDisplay the status of the OS installed on the host in graphs
    ⑤ Operation statusDisplay the operation status of the cloud platform in numbers
    ⑥ FluctuationsDisplay the fluctuations of number of cloud hosts and number of each asset type in graphs

    Host monitoring

    Provides the host change history information.

    FeaturesDescription
    Host monitoring summaryCheck the number of creations, deletions, and changes of all hosts and Auto Scaling groups of the selected group
    Group summaryDisplay the number of creations, deletions, and changes of host and Auto Scaling for the same group
    Host summary for each VPCDisplay the number of creations, deletions, and changes of host of each and every VPC of the same group
    Occurrence fluctuationsDisplay the number of creations, deletions, and changes of host and VPC in the group for a certain period in graphs
    DetailsCheck details of group of host, cloud, VPC, and so on

    Application monitoring

    Provides log information generated in the application policies.

    FeaturesDescription
    Application monitoring summaryCheck the number of creations, deletions, and changes of host set for application monitoring in the group
    Summary of TOP 5 of application monitoringDisplay of TOP 5 with the most events among the preset monitored subjects
    Occurrence fluctuationsCheck the total number of cases with application monitoring generated for a certain period for each fluctuation

    Asset status

    Provides the status of total assets.

    FeaturesDescription
    Host operation statusCheck the number of creations, deletions, and changes of host with application monitoring allocated in the group
    Agent statusCheck the status information (normal, error, and so on) of installed agent
    Firewall statusCheck the status information (normal, error, and so on) of installed firewall
    Host typeCheck the suspension and operation status of host type
    Host OSCheck the OS information of host
    Asset DetailsDisplay the detailed status information of registered assets (group, VPC, asset name, agent status, and so on)

    Details per asset

    Provides the status of total assets.

    FeaturesDescription
    Detailed information tree of assetsCheck the asset information tree structure per cloud
    Basic informationCheck the group, cloud, VPC information of selected host and the number of policies of firewall
    Connection subjectCheck the Subnet connected to NACL and IP information
    Inbound policies and Outbound policiesDisplay all firewall policies of relevant assets preset

    Remote script management

    Provide a function to register and manage scripts to check the assets and host.

    FeaturesDescription
    Project managementDeploy and run script files to subject group and host
    Project resultsProvide detailed information to promoted projects

    Account

    In the Account of Cloud Security Watcher manager, you can check the account status history information of cloud account and host.

    Account monitoring

    Provides information on the account of cloud and host.

    csw-use_03_account_ko

    AreaDescription
    ① Display 24-hour change status graphDisplay information such as account monitoring fluctuations graphs for 24 hours, recent creation details, recent deleted details, and recent login details
    ② Cloud account statusDisplay the quantity of account used in the cloud in graphs
    ③ Vulnerabilities of cloud accountDisplay the status of vulnerabilities status of cloud account such as safe and vulnerable in graphs
    ④ Host account and login statusDisplay the access account quantity for each host in graphs
    ⑤ Cloud account fluctuations status (24H)Display the number of creations, changes, deletions, and logins for the account for accessing the cloud service
    ⑥ Host account fluctuations status (24H)Display the quantity, number of creations, changes, deletions, and logins of account of host used in the cloud
    ⑦ FluctuationsDisplay the fluctuations of all information shown in the main in graphs

    Account monitoring details

    Provides detailed information on the account of cloud and host.

    FeaturesDescription
    Cloud accountCheck the details of cloud account monitoring
    Host accountCheck the details of host account monitoring

    Cloud account

    Provides all account information of each cloud for the selected host.

    FeaturesDescription
    Group statusCheck the all group information of each cloud
    User accountCheck the all account information of each cloud
    Change in accountsCheck the all change in accounts information of each cloud
    Login historyCheck the login history information on the cloud account
    Console task historyCheck the console task history on the cloud account

    Host account

    Provides the host account status information.

    FeaturesDescription
    Account statusCheck the host account information
    Change in accountsCheck the host account change information
    Login historyCheck the login history information on the host account

    Compliance

    The Compliance of Cloud Security Watcher manager provides resource vulnerability detection and diagnosis status information based on major compliance.

    csw-use_04_compliance_ko

    AreaDescription
    ① Vulnerabilities diagnosis dashboardProvides real-time vulnerabilities diagnosis dashboard
    ② Total diagnosis item summaryCheck the diagnosis item ability results of selected project
    ③ TOP 10 vulnerabilities itemsCheck the TOP 10 of each number of entity among the generated vulnerabilities items
    ④ Vulnerability status by categoryChecks the diagnosis severity of vulnerabilities generated based on the major classification and provides a comparative analysis function with execution check results
    ⑤ Fluctuations with generation of vulnerabilitiesCheck the vulnerabilities fluctuations generated in the results of the recent 10 project diagnoses
    ⑥ Tab for each diagnosis statusCheck the details such as diagnosis items, not processed, and completely processed, and so on.
    ⑦ Action statusCheck the status of generated entities of vulnerabilities (not allocated, during action, action completed, completely excluded)
    ⑧ Work status per person in charge of actionCheck the work status of users designated for and granted the charge of action in project
    ⑨ My work statusCheck the work status granted to the relevant project of the logged-in user

    Diagnosis of vulnerabilities

    Provides detailed information on the diagnosed project.

    FeaturesDescription
    ProjectManage the diagnosis and results on the project currently registered
    HistoryCheck the diagnosis history of all projects
    Exception managementCheck the exceptional entities of project where the user is designated as the person in charge of permissions for exceptions among all projects
    My task managementClassify and check in accordance with the work type allocated to the user
    Cloud account statusCheck the cloud account status registered on the compliance diagnosis project

    Compliance management

    You can check the compliance used for detecting and diagnosing vulnerabilities and creating, editing, and deleting custom versions.

    FeaturesDescription
    Add complianceCreate new custom compliance
    Compliance listCheck the currently registered compliance types
    Compliance type
  • Standard: the basically provided compliance when CSW is installed (which cannot be edited/deleted)
  • Custom: user-defined compliance (which can be edited/deleted)
  • Compliance detailsCheck the detailed items on compliance

    Project management

    You can create, edit, and delete projects used for detecting and diagnosing vulnerabilities.

    FeaturesDescription
    Add projectCreates new project
    Project taskEdit and delete projects

    Compliance report

    Provides the functions to check and output report of results executed in the vulnerabilities diagnosis menu.

    FeaturesDescription
    Creation report listCheck the result report created when diagnosing the manual/cyclical projects and the summary results
    Report output optionsSelect reports and custom reports

    Firewall

    The Firewall of Cloud Security Watcher manager provides the functions to check the cloud server, network firewall policy operation status, blocked TOP log and security topology.

    Firewall management

    Provides the host account status information.

    csw-use_05_firewall_ko

    AreaDescription
    ① 24-hour change statusCheck the firewall status information of cloud and host
    ② Total statusCheck the number of all firewalls in the group and the number of rules for each of NACL, ACG, and HFW
    ③ Firewall changesDisplay the changed figures of creation and deletion of firewalls and subject quantity of firewall policies in graphs
    ④ Changes in the number of firewall policiesDisplay the changed figures of policies of each firewall and subject quantity of firewall policies in graphs
    ⑤ Firewall operation statusDisplay the number of units in operation for each cloud platform, VPC, and firewall, and indicate each quantity
    ⑥ Security topologyAutomatically create a diagram analyzed based on information for each host and network
    ⑦ Top 10 blockedDisplay the number of cases blocked the most within 24 hours
    ⑧ Blocking historyDisplay the blocking history within 24 hours

    Firewall monitoring

    Provides log status information generated in the firewall policies.

    FeaturesDescription
    Firewall policy monitoring summaryCheck the number of all firewalls in the group and the number of rules for each of NACL, ACG, and HFW
    Firewall policy monitoring Top 5Check the Top 5 with the most number of cases of creation, deletion, and change among the total firewall assets during a period
    Occurrence fluctuationsCheck the status information of creation, deletion, and change of firewall policies during a period in graphs
    DetailsCheck the detailed change history of firewall policies during a designated period

    NCP firewall

    Provides the network information of NAVER Cloud Platform VPC and the NACL and ACG status.

    FeaturesDescription
    NACLCheck the topology of VPC and firewall policies
    ACGCheck the information of policies for permitting and blocking for each ACG and edit the policies

    AWS firewall

    Provides the AWS network information and NACL status

    FeaturesDescription
    NACLCheck the topology of VPC and firewall policies
    SGCheck the information of policies for permitting and blocking for each SG and edit the policies

    Azure firewall

    Provides the network information and firewall status of Azure VNet.

    FeaturesDescription
    Azure FirewallCheck the topology of VNet and firewall policies
    Firewall ManagerCheck the information of policies for permitting and blocking for each Azure Firewall Manager and edit the policies
    NSGCheck the information on the network security group and edit the policies
    ASGCheck the information on the Application security group and edit the policies

    HFW

    You can see HFW firewall policies and network status information.

    FeaturesDescription
    Host information within VPCSelect the cloud and the VPC/VNet and check the VPC network information and Private IP and the number of policy rules
    Security topologyCheck the position of the relevant host
    Inbound policies, Outbound policiesCheck the Inbound policies and Outbound policies of the selected host and edit and apply policies
    • In some servers, you need additional settings for activating the HFW functions in accordance with detailed OS settings.
    Note

    The measures to activate HFW are as follows:

    • Linux OS: disable the firewalld / ufw process, and then install the Agent
    • Windows OS: activate the Windows basic firewall, and then install the Agent

    Firewall status by host

    You can see the host's status, firewall policies, and network status information.

    FeaturesDescription
    Host list informationCheck the host list information of the selected VPC
    NACL informationCheck the NACL information connected to a selected host
    ACG informationCheck the ACG information connected to a selected host

    Template

    Provides a function to set the Inbound and Outbound policies templates in advance.

    FeaturesDescription
    Add templateCreate template in the selected cloud
    Add PolicySet the rules, type, protocol, port range, source, and act
    Select NACLImport the policies registered on the NACL

    Integrity

    The Integrity of Cloud Security Watcher manager provides log information generated by subjects and policies applied to the set integrity monitoring policies.

    Integrity monitoring

    You can see the list of hosts where the integrity monitoring configuration is created and monitoring history status.

    csw-use_06_integrity_ko

    AreaDescription
    ① Monitored subjectDisplay the quantities of the hosts to be monitored and the hosts not to be monitored among all the hosts in graphs
    ② Integrity detection hostDisplay the quantities with integrity detection generated in the hosts to be monitored in graphs
    ③ Number of cases of integrity monitoringDisplay the number of cases of integrity monitoring and detection during 1 month in graphs
    ④ Change statusDisplay the history information of creation, deletion, and change of each group of hosts to be monitored within 24 hours
    ⑤ Top 10 hosts for integrity monitoringDisplay the host information of top 10 hosts with the most cases of integrity monitoring and detection
    ⑥ Real-time integrity monitoringDisplay the hosts where integrity monitoring and detection have occurred in real time

    Real-time monitoring

    Provides integrity monitoring logs generated during a designated period by detected file and directory.

    FeaturesDescription
    Search featuresView the number of cases detected by inputting integrity detection files
    Select periodManually designate the date range
    Deactivate the filterReset the selected period settings, search criteria, and so on
    Settings of number of listed itemsDesignate the total number of items in a page of a table list
    Excel down buttonConvert the logs of criteria searched in the type of Excel files

    Monitoring by file

    Provides the integrity monitoring log by file generated during a designated period by host name.

    FeaturesDescription
    Search featuresEnter the host name and view the number of cases detected
    Select periodManually designate the date range
    Deactivate the filterReset the selected period settings, search criteria, and so on
    Settings of number of listed itemsDesignate the total number of items in a page of a table list
    Excel down buttonConvert the logs of criteria searched in the type of Excel files

    Status

    The Status of Cloud Security Watcher manager provides the quantity information of warnings and cautions of host status for each threshold value set up by the policy.

    Status monitoring

    You can see the list of hosts where the integrity monitoring configuration is created and monitoring history status.

    csw-use_07_status_ko

    AreaDescription
    ① Quantity by statusDisplay the status generated in the hosts as the quantity of warnings and cautions in graphs
    ② Host by statusDisplay the quantity of hosts with status monitoring generated
    ③ 24H status monitoringDisplay the number of notifications occurred within 24 hours and the quantity of host where the notifications occurred
    ④ Operation statusDiaplay the status of hosts by status in each group in graphs
    ⑤ Real-time status monitoring alarmDisplay a status history about the details of the recent notification
    ⑥ Monitoring of real-time service changesDisplay the status of real-time service changes

    Resource monitoring status

    Display the information of hosts set up in Settings > Status monitoring settings

    FeaturesDescription
    ResourceDisplay CPU, Memory, SWAP, and DISK usage thresholds based on the set status monitoring
    NetworkDisplay status monitoring information in the network, including the network traffic and cumulative transmission of host
    ProcessDisplay monitoring information by resource of the process registered in the host
    PortDisplay service type, protocol, port number, and so on which is registered in the host
    UrlDisplay the threshold and response time to reach the registered URL address
    PingDisplay the results of a communication detection test that attempts to Ping the designated host

    Resource status by host

    Provides detailed information on the host that installed the agent.

    FeaturesDescription
    OverviewDisplay the status information of the selected host
    CPUDisplay CPU usage rate during a set period of time for host where the agent is installed
    MEMDisplay memory usage rate during a set period of time for host where the agent is installed
    DiskDisplay disk usage rate during a set period of time for host where the agent is installed
    NetworkDisplay network usage traffic during a set period of time for host where the agent is installed
    ProcessDisplay CPU and memory usage rate of the process registered in the status monitoring settings menu
    NotificationDisplay notifications that occur when the threshold set in the status monitoring settings menu is exceeded

    Resource notifications

    Provides a consolidated log of resource notifications generated by status monitoring settings.

    FeaturesDescription
    Search featuresEnter the host name and view the number of cases detected
    Select periodManually designate the date range
    Deactivate the filterReset the selected period settings, search criteria, and so on
    Settings of number of listed itemsDesignate the total number of items in a page of a table list
    Excel down buttonConvert the logs of criteria searched in the type of Excel files

    Monitoring of service changes

    Provides the real-time information of creation/deletion/change detected for processes and ports used by the host where the agent is installed.

    FeaturesDescription
    Service monitoring summaryDisplay the number of Processes and Ports that have changed
    Group summaryDisplay monitoring information by group
    Host summary by VPC/VNetDisplay monitoring information by VPC/VNet
    Occurrence fluctuationsDisplay the number of service changes in graphs
    DetailsDisplay the detailed information of service changes

    Status of all processes and ports

    Provides all process and port information for the host where the agent is installed.

    FeaturesDescription
    All ProcessDisplay cloud, private IP, process name, process status, CPU, and so on which is by host
    All Open PortDisplay policy type, group, cloud, protocol, port, and so on which is by host

    Event

    The Event in the Cloud Security Watcher manager provides event information that occurred on the host set in Settings > Alert settings, Log monitoring settings.

    Alert

    Provides event information of the AWS host where the Alert is set.

    csw-use_08_event_ko

    AreaDescription
    ① All AlertsDisplace all Alerts that occurred during a set period of time
    ② DetailsDisplays detailed information about generated Alerts

    System log

    Provides system log information set up on the host where the agent is installed.

    FeaturesDescription
    System log informationDisplay details classified by log type and level

    Firewall log

    Provides firewall log information set up on the host where the agent is installed.

    FeaturesDescription
    Firewall log informationDisplay the allow/block policy log information of firewall

    Task

    The Task of Cloud Security Watcher manager provides cloud asset change the task conducted through the manager in a designated period and detailed task information on the activities of the manager.

    Task history

    Provides detailed information by classifying the changes in the cloud service due to the Cloud Security Watcher manager tasks into succeeded, failed, and proceeding.

    csw-use_09_cloudactivelog_ko

    FeaturesDescription
    ① Select periodSet search period
    ② CloudSelect cloud service
    ③ Run timeDisplay the run time for conducting the task
    ④ StatusDisplay the task conducted in relation to cloud service through manager as succeeded or failed
    ⑤ Download Excel fileYou can download Excel files so that the task history of a designated period can be separately stored
    ⑥ View detailsDisplay the detailed popup windows when there is additional information for tasks conducted for the cloud service

    Activity history

    Provides all history and details and the like on the activities such as login history and addition and deletion of user/group conducted in the Cloud Security Watcher manager.

    csw-use_10_managerlog_ko

    FeaturesDescription
    ① Select periodSet search period
    ② Task historyDisplay the history of activity inside from when the user accesses the manager
    ③ View detailsDisplay the detailed activity history on the items excluding the login/logout succeeded details
    ④ Download Excel filesYou can download Excel files so that the Active history of a designated period can be separately stored
    Note

    The maximum view period by each menu is set to the last 3 months (90 days). You can download in Excel file to extract activity logs, including task history, for separate archiving.

    Report

    The Report of Cloud Security Watcher manager provides reports that are generated based on the settings in Settings > Set reports.

    Regular report

    Provides reports created monthly/weekly/daily.

    AreaDescription
    Monthly reportProvide a list and file of monthly report created
    Weekly reportProvide a list and file of weekly report created
    Daily reportProvide a list and file of daily report created

    Report by period

    Provides a feature where dates can be selected to create a report for the period.

    FeaturesDescription
    Select groupDisplay a report for the selected group
    Create reports buttonAfter specifying the dates, click Create button to create a report by period
    Report buttonProvide visualizations of all data in CSW, including asset status, account status, account monitoring, and so on which is in the form of charts

    Notification settings

    In the Notification settings of Cloud Security Watcher manager, you can set to in real time provide email and screen notification when a resource change history of a specific criteria has been detected. The following describes how to set up the notification:

    1. Click User icon.
      csw-use_11_alarm1_ko
    2. Click [Notification settings].
      csw-use_12_alarm2_ko
    3. Select a desired notification function.
      csw-use_13_alarm3_ko
    Note

    In the Notification reception exception tab, you can select a VPC or host to be designated as an exception.


    Was this article helpful?

    Changing your password will log you out immediately. Use the new password to log back in.
    First name must have atleast 2 characters. Numbers and special characters are not allowed.
    Last name must have atleast 1 characters. Numbers and special characters are not allowed.
    Enter a valid email
    Enter a valid password
    Your profile has been successfully updated.