Ensure that your Object Storage Service (OSS) buckets enforce encryption of data over the network, as it travels to and from OSS, using Secure Sockets Layer (SSL).
When OSS buckets are not configured to strictly require SSL connections, the communication between the buckets and their clients (users and applications) is vulnerable to eavesdropping and Man-in-the-Middle (MITM) attacks. Trend Vision One™ strongly recommends enforcing SSL-only access by denying all regular, unencrypted HTTP requests to your OSS buckets when dealing with business-critical, sensitive, or private data.
Audit
To determine if your OSS buckets are protecting data in transit using SSL, perform the following operations:
Remediation / Resolution
To enable in-transit encryption for your Object Storage Service (OSS) buckets using bucket policies, perform the following operations:
References
- Alibaba Cloud Documentation
- Buckets Overview
- Access and Control Overview
- Authorize other users to access OSS by using bucket policies
- ossutil Documentation
- bucket-policy