Public ports in an Alicloud security group need a documented purpose

Identify the services and purpose of public ports, then allow only the required access.

Description

Leaving internet-facing ports without an understood purpose can expose unnecessary services or retain obsolete allow rules. An unfamiliar port number is not inherently unsafe; identify the actual service and its business requirement.

When public addressing, routing and other connection requirements are met, external clients can attempt connections to the allowed ports.

Potential impact

  • Unintended services may face external scanning or vulnerability exploitation attempts.
  • Unclear ownership and purpose make unnecessary access permissions harder to remove.

Remediation

  • Identify the service, purpose and owning team for each public port.
  • Remove unused rules and allow only required ports and approved sources.
  • Review other allow rules and actual connectivity, and document the changes.

Examples

These excerpts use an existing security group. VPC security groups require nic_type = "intranet"; this value does not itself block internet access.

Before

hcl
resource "alicloud_security_group_rule" "unknown_ports_open" {
  type              = "ingress"
  ip_protocol       = "tcp"
  nic_type          = "internet"
  policy            = "accept"
  port_range        = "54/60"
  priority          = 1
  security_group_id = alicloud_security_group.default.id
  cidr_ip           = "0.0.0.0/0"
}

TCP 54–60 is allowed from all IPv4 addresses. Identify the services using this range and whether public access is necessary.

After

hcl
resource "alicloud_security_group_rule" "unknown_ports_open" {
  type              = "ingress"
  ip_protocol       = "tcp"
  nic_type          = "internet"
  policy            = "accept"
  port_range        = "22/22"
  priority          = 1
  security_group_id = alicloud_security_group.default.id
  cidr_ip           = "10.159.6.18/32"
}

This assumes the review established that only SSH administration is required. Access is narrowed to TCP 22 from one approved client. Choose ports and addresses for the actual purpose and remove the earlier broad rule.

References