Documentation Index

Fetch the complete documentation index at: https://guide.ncloud-docs.com/llms.txt

Use this file to discover all available pages before exploring further.

Getting started

Prev Next

Available in VPC

Once you've reviewed the Webshell Behavior Detector supported environments, specifications, quickstart, and glossary, you're ready to start using the service. Your first step is subscribing to Webshell Behavior Detector. You can subscribe to and manage Webshell Behavior Detector in the NAVER Cloud Platform console.

Here is what you can learn from this Getting started page:

Subscribe to service

To subscribe to Webshell Behavior Detector:

  1. Access the NAVER Cloud Platform console.
  2. In the top-right corner, click Region & Platform.
  3. Select your region and VPC platform, then click [Apply].
  4. In the top-left corner, click Menu.
  5. Navigate to All Services > Security > Webshell Behavior Detector.
  6. Click [Subscribe].
    wbd-wbdstart-subscribe-vpc-ko
  7. Read the Terms of service, agree to them, and click [OK].
Note

Click [Subscribe] in Services > Security > Webshell Behavior Detector in the NAVER Cloud Platform portal to directly go to the page in Step 3.

Detection target registration

Once you are subscribed to the Webshell Behavior Detector service, you need to register servers to detect web shell behaviors for as detection targets.
To register detection targets:

  1. In the NAVER Cloud Platform console's VPC environment, navigate to Menu > All Services > Security > Webshell Behavior Detector.
  2. Navigate to Detection Setting > Configuration.
  3. Click [Detection target registration].
  4. Select a server to register as a detection target, and set the server environment and notification recipients.
    wbd-wbdstart-addserver-vpc-ko
    • You should enter the webroot and upload directory after selecting a server environment. Click [Add] after entering the path to complete.
    • Webroot directory path is a required item.
    • Enter an absolute path, just like the example displayed on the NAVER Cloud Platform screen. If there are multiple paths, enter them all. If some of paths are overlapped, enter the upper path only.
    • You can add a note for the detection target server if needed.
Note

For Kubernetes environments, you can set up the web server environment and web root/upload directory paths after running the Agent POD.

  1. Click [Complete settings] once you are done with the settings.

  2. Check if the configuration is accurately entered from the confirmation popup window, and click [Detection target registered].

    • Once the detection target registration is completed, a notification will be sent to notification recipients according to the notification settings.
    • The server registered will be added to the list of detection targets, but the agent status will be displayed as Not installed. You have to install and execute the agent in the server.

Install and execute agent

In order for Webshell Behavior Detector to start detecting web shell behaviors normally, you should install and execute the agent in the registered detection target server. For more information, see Install and execute agent.

Remove detection target

You can remove servers registered as detection targets. Please proceed carefully as you're exposed to the risk of web shell attacks if you remove servers from detection targets. The agent ends automatically, and you will not be charged anymore.

To remove servers from detection targets:

  1. In the NAVER Cloud Platform console's VPC environment, navigate to Menu > All Services > Security > Webshell Behavior Detector.
  2. Navigate to Detection Setting > Configuration.
  3. Select a server to remove from the detection target list and click [Remove detection target].
  4. Check the server's information in the confirmation popup window and click [Remove detection target].
Note
  • We recommend disabling it if you won't be using the service in the short term for the detection target. You won't be charged if you disable the detection target, and you can easily enable it again if needed.
  • If you remove a server from detection targets, the agent's process is ended, but it won't be deleted. To delete the agent from the server, see Delete agent.

Cancel service

You can cancel your subscription to Webshell Behavior Detector in the NAVER Cloud Platform console. You can unsubscribe any time you want, but take note of the billing unit when canceling.

Caution

If you cancel the subscription, all data set, produced and saved while using Webshell Behavior Detector, will be deleted, and you will be exposed to the risk of web shell attacks. Consider carefully before proceeding with canceling the service.

To unsubscribe:

  1. Access the NAVER Cloud Platform console.
  2. In the top-right corner, click Region & Platform.
  3. Select your region and VPC platform, then click [Apply].
  4. In the top-left corner, click Menu.
  5. Navigate to All Services > Security > Webshell Behavior Detector.
  6. Click the Subscription menu.
  7. Click [Subscribed], then select Unsubscribe.
  8. Check the notification in the Confirmation popup window, and click [OK].
    wbd-wbdstart-cancel-vpc-ko