
Qingteng Wanxiang
Overview
The Qingteng Wanxiang Host Adaptive Security Platform quickly and accurately detects security threats and intrusion events through continuous monitoring and fine-grained analysis of host information and behavior, and provides flexible and efficient problem solving capabilities to provide users with next-generation security detection and response capabilities.
The core platform architecture of Qingteng Wanxiang is mainly composed of three parts: Agent, Engine, and Console, to provide basic, flexible and stable core competency support for product services: Agent - Host Probe Agent can be installed on the host with just one command. It runs stably, has low consumption, and automatically adapts to various physical machines, virtual machines, and cloud environments. Engine - As the information processing center of the core platform, the security engine supports horizontally expanded distributed deployment, and can continuously analyze, detect, and store the information and behavior received from various agents. Console - The control center interacts with users in the form of a web console, clearly displays the results of various security tests and analyses, and provides centralized security tools to facilitate users to perform system configuration, management, security response and other related operations.
Product features: Asset inventory: find out the bottom of the family and quickly locate The asset inventory function can automatically construct fine-grained asset information according to user needs, and can perform a comprehensive inventory of host assets, application assets, web assets, etc., to ensure that users can grasp all host asset conditions in real time, including the Web, systems, processes, ports, accounts, software applications, etc.
Risk discovery: understanding risks and continuous testing
The risk discovery function analyzes potential risks and compliance issues within the system in a fine-grained manner, discovers web application vulnerabilities, weak passwords, risk files, misconfigurations, etc. in a timely manner, generates analysis reports and gives detailed repair suggestions, making security management clear and measurable. Formulate reasonable security policies according to business needs, and build a complete and customized security system.
Intrusion detection: Detect intrusions and respond quickly By laying down characteristic anchors as a necessary path for hacking, hacking behavior is analyzed based on behavioral patterns and key models, and combined with the latest threat intelligence, intrusions are discovered as soon as possible to ensure that corporate losses are minimized.
Compliance baseline: identify issues and supervise rectification The compliance baseline establishes a benchmark requirement composed of domestic equal guarantee requirements and CIS, covering multiple versions of mainstream operating systems, web applications, databases, etc. Users can quickly self-test risks within the enterprise, find problems and fix them in a timely manner, and can also define their own baseline standards as a security benchmark for internal enterprise management.
Highlights
- Deploy 6 million+ agents Single customer installed more than 150,000+ agents The largest share of the domestic host security market The financial industry has the highest share of the host security market In the host security product category, the domestic operating system and processor compatibility category is number one in China (information technology innovation)
- 7 years, 3 million lines of self-developed code, 300 version iterations, 50,000 knowledge bases, stability up to 99.9999%, CPU usage < 1%, memory usage <40M
- It comprehensively covers all stages of the attack, provides specialized security guarantees, effectively avoids risks in advance, monitors and captures intrusions in real time during the incident, and analyzes the entire attack process from the beginning to form reports
Details
Pricing
Qingteng Wanxiang
Usage costs (24)
Dimension | Cost/hour |
|---|---|
m5.2xlarge Recommended | CN¥2.63 |
m5.4xlarge | CN¥2.63 |
m4.4xlarge | CN¥2.63 |
g2.2xlarge | CN¥2.63 |
g3.4xlarge | CN¥2.63 |
r4.16xlarge | CN¥2.63 |
c5.2xlarge | CN¥2.63 |
g3.8xlarge | CN¥2.63 |
c4.2xlarge | CN¥2.63 |
c5.4xlarge | CN¥2.63 |
Vendor refund policy
Non-cancellable, non-refundable
Legal
Vendor terms and conditions
Content disclaimer
Usage information
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
2024_10
Additional details
Usage instructions
- After the AMI image starts, you need to wait about 10 minutes to automatically complete the console deployment and startup;
- Communication requirements: (1) The agent host needs to be able to access the console IP port 8888, 8001, 8002, 6677, 7788, 8443, 8243, 8244 (2) The management terminal needs to be able to access the console's 8888 and 81 ports
- Link to the operating system via SSH. The default user name is “centos”, and a randomly generated administrator password is obtained from the /etc/password file.
- Use a browser (Chrome is recommended) to access the main product interface http://PublicIP/PrviteIP:8888,用户名: admin@sec.com ,密码:步骤1获取的管理员密码进行登陆,进行正常产品使用.
- Use a browser (Chrome is recommended) to access the system rules backend http://PublicIP/PrviteIP:81,用户名: admin@sec.com ,密码:步骤1获取的管理员密码进行登陆. (The main interface of the product and the system rules backend can be accessed by setting the system management backend as https. If the system management backend needs to be accessed using the HTTPS method, it is necessary to link to the operating system via SSH and execute commands in the /data/app/titan-patrol-srv/script/ directory: To enable 6110 https, run the following command: bash /data/app/titan-patrol-srv/script/ssl.sh on To turn off 6110 https, run the following command: bash /data/app/titan-patrol-srv/script/ssl.sh off
Resources
Vendor resources
Support
Vendor support
Marketplace
Amazon Web Services infrastructure support
Amazon Web Services Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.