Insights
The Insights page adds another level of incident analysis and provides recommendations to enhance your security posture.
|
|
Last Update reflects when changes to detected threats occur, not the most recent system scan. Threat detection is based on multiple trigger conditions, some of which run more frequently than others, resulting in varying update intervals. Updated threat insights may appear immediately or within the same day. |
The pie chart on this page shows the highest security risk factors in your application, along with the number of violations detected for each risk factor across your applications.
Clicking on one of the listed threats next to the pie chart will modify the table below the chart to show information specific to the selected threat, along with information for suggested actions.
| Threat | Description |
|---|---|
| Exposed Origin Servers |
This refers to situations where parts of your application expose the address of the physical or virtual machine hosting the application and/or database software. Examples include when the Origin Server IP is directly accessible through HTTP/HTTPS requests or is visible in public DNS records. |
| Trust IP Policy Alarm | This threat occurs when your account's Trust IP list contains IPs with a bad reputation that have been identified as malicious. We recommend removing these IPs immediately from the Trust IP list in Access Rules > IP Protection. |
| Unprotected API Hosts | This threat occurs when one of the hosts in your account is not protected by API security. When this occurs, we recommend enabling ML based API Protection to automatically discover and protect all API endpoints. |
| WAF Configuration Alarm | This refers to when one or more websites on your account are not configured to block important attack types. To better protect your application, please find the suggested page under Configuration in the table below, and navigate to said page under WAF. |
| Fortinet Monitoring Service | This includes threats detected by engineers through Fortinet's managed services, such as SOCaaS. |