Skip to content

Security Insights

Visibility is a core component of Valtix's Cloud Network Security Service. Valtix Cloud Network Security Insight analyzes the security posture of Cloud accounts. Unlike other Cloud Security Posture Management (CSPM) tools, Valtix focuses on providing deeper Analytics on Network Security specific posture.

Security Insights is supported for both AWS and Azure. Findings can be made into security insights without deploying Valtix Gateways. Simply add a Cloud account as indicated in the Cloud Provider Setup section of this guide and Valtix will continuously analyze the Cloud accounts and provide near real-time updates of all cloud assets and security findings across severity levels.

Summary

To get started, navigate to Discovery -> Summary to display a Summary view of the findings across Cloud asset types:

  1. Security Groups
  2. Subnets
  3. Route Tables
  4. Network Interfaces
  5. VPCs/VNets
  6. Applications
  7. Load Balancers
  8. Instances
  9. Tags
  10. Certificates

Security Groups

Customers often struggle with the proliferation of security groups. Security groups are often shared amongst resources that could present risk as changes made to a security group intended for a handful of resources could impact a larger group.

Security Groups provides a list of all security groups on the filtered account(s) and provides details on the number of resource utilizing the same. The Is Inbound Public and Is Outbound Public fields indicate security group rules configured with 0.0.0.0/0.

In the filter window, select preset filters with selection options to filter the list of security groups with the option to create a rule based on the filtered selection.

Rules

Rules provide a view of specific security group rules. In this view, filtering is performed using the selection window. Filters can be used to identify rules based on port information.

Ports

Ports provide a port-centric view of the security groups. This is used to quickly identify security groups that are open on a specific port.

Subnets

Shows a listing of all subnets discovered in Cloud accounts. This view can provide details about subnets that are publicly accessibly through based on whether auto-assign public IP is enabled.

Route Tables

Shows a listing of route tables discovered in Cloud accounts. This view can provide details about whether there are public internet inbound and internet outbound routes.

Network Interfaces

Shows a listing of network interfaces discovered in Cloud accounts. This view also shows Private and Public IP addresses for any of the network interfaces.

VPCs\VNets

Shows a listing of VPC's and/or VNet's discovered in Cloud accounts.

Application

Shows a listing of Applications indicated by the presence of Cloud Service Provider Application Load Balancers deployed. This view identifies whether a Valtix Gateway and Security Policy is applied to secure the Application. The secured field shows options to move forward with a Create Rules workflow for an application that has not yet been secured.

Load Balancers

Shows a listing of Cloud Service provider Load Balancers discovered in the Cloud accounts. This view allows filtering to determine whether an Application front-ended by a Load Balancer has a Cloud Service Provider WAF enabled, or not.

Instances

Shows a listing of Instances or VM's with summary information on the number of security groups and interfaces for each Instance or VM.

Tags

Shows all Instance and Load Balancer tag key values discovered in Cloud accounts.

Certificates

Shows Certificates. This is currently only supported for AWS Certificate Manager. This is useful to display all Certificates with associated Issuer, Domain Name and Expiry Date.

Map View

Shows a high level map view by Region of Cloud assets in cloud accounts.

Rules

Valtix provides a default set of Insight Rules that are used to identify findings in your Cloud accounts. Insight rules can be modified and new Insight rules can be added by using the search filters in the above sections along with the Add Rule option.

Findings

Findings a summary of the findings based on the Insight Rules configured. Findings can be filtered using the Search bar.