Business → Security center (business.center, Warda Business,
beta: open to every installation during the beta; internal/admin/center.go)
gathers what the other pages know, in one page: a Security score out of
100, the Actions by priority and the Trend. Nothing more is
watched: the score is read from the alerts, the threats, the data loss
prevention, the network checks and the settings.
Each action to take costs points; the score is 100 minus the points (0 at least), and its level is good from 85 ("Good: keep it that way."), fair from 60 ("Fair: a few actions to take."), poor below ("Poor: act now, starting with the most serious."). The actions come by severity (Serious, Important, Minor), then by points, each with the number of things concerned, its points ("−15 points") and Open, the page that settles it:
Action (id) |
Severity | Points | Page |
|---|---|---|---|
Devices in quarantine (quarantine) |
serious | 15 each, 30 at most | Devices |
Devices that contacted a spyware or a hidden server at regular intervals this week (spyware) |
serious | 10 each, 20 at most | Protections |
Devices that behave as infected ones or leak data through DNS, this week (suspects) |
serious | 10 each, 20 at most | Security report |
Devices that asked look-alike names this week (lookalikes) |
important | 3 each, 10 at most | Look-alike names |
Serious / important / minor alerts not seen, last 30 days (alerts.high, alerts.medium, alerts.low) |
as the alert | 2 each (10 at most) / 1 each (5 at most) / 0 | Alerts |
Devices that sent data to channels told or blocked this week (dlp, with the data loss prevention) |
important | 2 each, 10 at most | Data loss prevention |
Devices on the network that never ask Warda (silent) |
important | 3 each, 15 at most | Network |
A router announces another IPv6 DNS server (ipv6) |
serious | 15 | Network |
Devices that tried an encrypted DNS service, a VPN or a proxy this week (bypass) |
important | 2 each, 10 at most | Device policies |
Devices given to nobody, seen this week (unplaced) |
minor | 1 each, 5 at most | Device policies |
Administrator accounts without a second factor (twofactor) |
serious | 10 each, 20 at most | Access to Warda |
An update of Warda waits, or failed (updates) |
important | 10 | System |
No backup password (backups.none), or the last backup older than 7 days (backups.old) |
important | 10 / 5 | System |
The devices cannot ask Warda over encrypted DNS (encrypted) |
minor | 5 | DNS services |
Protections against rebinding, spyware or hidden servers off (protections) |
important | 5 each, 15 at most | Protections |
Company baseline rules not in force (baseline) |
minor | 5 | My rules |
The score of the day is recorded each time the page opens and every hour
by the task Security center (business.center, with the plan), and
kept 400 days. The Trend draws over 7 or 30 days the Score of each
day (the last one recorded that day; "no score" for a day without one)
and the Alerts of each day by severity (the severity of an alert comes
from its CEF severity: 7 and more serious, 5 and 6 important, the others
minor).
GET /api/v1/business/center?period=7d|30d (reports read; 402 without
the plan) gives score, level (good, fair, poor), actions
(id, severity high/medium/low, count, points, page),
period, trend (day, score, -1 when not recorded, high,
medium, low) and at.