Chuyển tới nội dung chính

Security Hub v1.2.2

I. Thông tin nổi bật

FPT Smart Cloud giới thiệu Security Hub v1.2.2 thuộc nền tảng FPT Security Platform (FSP), bổ sung module mới CWPP (Cloud Workload Protection Platform) — mang đến khả năng giám sát runtime cho Kubernetes workloads.

Phiên bản này cho phép Tenant Admin quản lý runtime agent trên từng Kubernetes cluster (cài đặt / gỡ cài đặt), xem K8s Asset Inventory (toàn bộ workload resource bên trong cluster), và theo dõi Runtime Findings — security signal phát hiện bởi kernel-level agent, phân loại theo MITRE ATT&CK. Chi tiết từng finding được hiển thị trong Finding Detail Drawer với đầy đủ context: infrastructure, process chain, threat classification và raw event.

ghi chú

Observe mode: Phiên bản v1.2.2 hỗ trợ observe mode only. Findings hiển thị để giám sát; response action trực tiếp từ màn hình Findings sẽ được bổ sung trong phiên bản tiếp theo.


II. Tính năng released

1. K8s Asset Inventory

a. Description

K8s Asset Inventory cung cấp visibility toàn diện về tất cả Kubernetes cluster trong tenant: trạng thái runtime agent trên từng cluster, khả năng cài đặt / gỡ cài đặt agent, và danh sách đầy đủ workload resource bên trong mỗi cluster.

b. Feature

K8s Asset List (tab K8s Assets trong Inventory):

  • Tab K8s Assets mới trong màn hình Asset Inventory — hiển thị tất cả cluster
  • Network Requirement Banner cố định phía trên bảng — hiển thị protocol, port và IP endpoint outbound cho runtime agent; không có nút dismiss
  • Bảng cluster với 4 cột: Cluster · VPC · Agent · Actions — mặc định sort theo Cluster name A → Z
  • Search theo cluster name (real-time)
  • Filter VPC (single select) và Filter Agent status (single select) — kết hợp AND với Search
  • Agent badge — 5 trạng thái với màu và icon riêng
  • Error indicator: icon đỏ khi lần thao tác trước thất bại; có thể retry ngay

Install Agent Flow:

  • Modal Install Confirmation: mô tả + Terms & Agreement (scrollable) + checkbox đồng ý
  • Button Request installation: disabled khi chưa tích checkbox; enabled sau khi tích
  • Sau khi xác nhận: modal đóng, agent status: No agentInstalling

Uninstall Agent Flow:

  • Modal Uninstall Confirmation: yêu cầu gõ chính xác "uninstall" (chữ thường) vào text input
  • Button Confirm: disabled khi input chưa khớp; enabled khi khớp đúng
  • Sau khi xác nhận: modal đóng, agent status: Agents activeUninstalling

K8s Asset Details:

  • Click tên cluster → navigate sang màn hình K8s Asset Details
  • Header: cluster name + agent badge + VPC name
  • Resource list từ KSPM / asset inventory — độc lập với trạng thái agent
  • 4 cột: Resource · Type · Namespace · Node — sort theo Resource name A → Z
  • Search real-time, Filter Type (single select), Filter Node (single select)
  • Counter N resources cập nhật real-time
  • Button Back: quay lại K8s Asset List; filter trong list không bị reset

c. Capacity

  • Danh sách cluster và resource: theo giới hạn tenant (không phân trang trong prototype v1)
  • State machine: No agent → Installing → Agents active → Uninstalling → No agent

2. Runtime Findings

a. Description

Runtime Findings tập trung toàn bộ security signal phát hiện bởi K8s Runtime agent, phân loại theo Severity và MITRE ATT&CK. Phiên bản này hỗ trợ observe mode — chưa có response action.

b. Feature

Runtime Finding List (menu Findings):

  • Menu item Findings mới trên sidebar
  • Observe-mode Banner cố định: "Findings currently support observe mode only. No actions can be taken from this screen." — không có nút dismiss
  • Button Refresh: reload findings mới nhất; giữ nguyên filter
  • 8 cột: Severity · Time · Source · Finding · Entity · MITRE · Event ID · Finding ID — sort theo Time DESC

Filter Bar (trái → phải: Search → Severity → Time → MITRE):

  • Search: tên finding, entity, Event ID, Finding ID — real-time
  • Severity: Critical / High / Medium / Low
  • Time: Last 1h / Last 24h (mặc định) / Last 3d / Last 7d — Last 24h áp dụng ngay khi vào trang
  • MITRE: prefix match — chọn T1059 khớp tất cả T1059.x sub-technique

Finding Detail Drawer:

  • Click tên finding → drawer trượt từ phải; Finding List vẫn visible phía sau
  • Header: finding title + 3 badges (Source · Severity · MITRE link)
  • 4 sections: DETAILS · KNOWN BENIGN CAUSES · SECURITY GRAPH CONTEXT · RAW EVENT
  • Details: Time, Event ID, Finding ID, Detection rule, Cluster, Node, Namespace, Pod, Container, Image, Process, Command, Parent, Tactic, Technique, Context flags
  • Known Benign Causes: accordion, mặc định collapsed; ẩn hoàn toàn khi không có content
  • Security Graph Context: placeholder tính năng sắp ra mắt
  • Raw Event: JSON toggle (Expand/Collapse), mặc định collapsed

c. Capacity

  • Finding list: toàn bộ findings trong time range đang chọn (không phân trang trong v1)
  • Activity/history: không áp dụng — Runtime Findings là read-only trong observe mode

III. Bug Fixes & Improvements

#Mô tảLoại
1Module CWPP khởi tạo — không có bug fix từ phiên bản trướcN/A