tencent cloud

DokumentasiTDSQL-C for MySQL

Access Topology

Download
Mode fokus
Ukuran font
Terakhir diperbarui: 2026-08-25 15:41:06
Diterjemahkan oleh AI
The data security audit access management module achieves refined control over database access behaviors through complementary dual-dimension governance from the "source IP address perspective" and the "instance perspective". It supports visual presentation of access behaviors (such as access topology diagrams) and IP address/account labeling operations, enabling fine-grained access control. It manages access behaviors from both the "source IP address" and "instance" dimensions to address the core questions of "who can access, from where, and what they access", preventing security vulnerabilities caused by coarse-grained access control.
Management Perspective
Description
Applicable Scenarios
With the source IP address of the access initiator as the core control dimension, integrate the access data of this IP address to database instances, provide capabilities for access topology visualization, precise IP address/account tagging, and rapid security group policy adjustment, and implement centralized and refined control over the access initiator.
Identify cross-instance access risks of a single IP address and batch mark certain types of access sources.
With the database instance on the access target side as the core resource dimension, integrate the access data of source IP addresses to this instance, provide capabilities for asset access topology visualization, precise IP address/account tagging, and rapid security group policy adjustment, and implement centralized and refined control over the access target.
Identify all access sources of a single instance and implement targeted control for core instances.

Source IP Perspective

1. Log in to the TDSQL-C for MySQL console and click Data Security Audit in the left sidebar.
2. On the DSAudit page, choose Access Management > Source IP Perspective.

3. On the Source IP Perspective tab, you can view information such as Source IP Address/Region, IP Type/Tagging, Instance ID/Name, Region, Visiting User/Type, and Last Access Time.

IP Access Topology

Visually present the access relationships, access frequency, and security status between a single source IP address and all associated accounts and database instances in the form of a visual topology map.
In the source IP perspective list, click IP Access Topology in the operation column of the target IP address to view the access relationship map between the IP address and its associated database instances.


IP Tagging

Add preset or custom tags to target source IPs to classify and manage the IPs, facilitating differentiated assessment during subsequent risk monitoring.
1. In the source IP perspective list, click More > Tag Source IP in the operation column of the target IP address.

2. In the Tag Source IP window, edit the source IP remarks and click Confirm to complete the tagging.
Note:
The tagging operations in the source IP perspective and the instance perspective are mutually linked. After you tag an IP address in the source IP perspective, the tag status is synchronously updated when you view the IP address in the instance perspective, and vice versa.

Account Tagging

Add preset or custom tags to the accounts used by target source IPs to access databases, enabling classified management of access accounts for subsequent auditing and risk investigation.
1. In the source IP perspective list, click More > Tag Account in the operation column of the target IP address.

2. In the Tag Account window, select the account type, edit the account remarks, and click Confirm to complete the tagging.
Note:
You can edit the access account type if it is a self-built account. If the current access account is a cloud root account/sub-account, the system automatically identifies it, and no manual editing is required.

Modifying a Security Group Policy

Quickly go to the asset page of the database instance associated with the target IP address and directly modify the security group policy to quickly control access permissions for the IP address (allow/deny access).
In the source IP perspective list, click More > Modify Security Group Policy in the operation column of the target IP address to go to the database instance asset page and modify the security group policy.


Instance Perspective

1. Log in to the TDSQL-C for MySQL console and click Data Security Audit in the left sidebar.
2. On the DSAduit page, choose Access Management > Instance Perspective.

3. On the Instance Perspective page, you can view information such as Instance ID/Name, Region, Visiting User/Type, Source IP Address/Type, and Last Access Time.

Asset Access Topology

Visually present the access relationships, access frequency, and risk status between all source IPs and associated access accounts of a single database instance in the form of a visual topology map.
In the instance perspective list, click Asset Access Topology in the operation column of the target instance to view the topological relationships between all source IPs and associated accounts of the instance.


IP Address Tagging

Add preset or custom tags to the specified source IPs that access the target instance to achieve precise classification and control of IPs accessing the instance, facilitating subsequent risk monitoring and auditing.
1. In the instance perspective list, click More > Tag Source IP in the operation column of the target instance.

2. In the Tag Source IP window, edit the source IP remarks and click Confirm to complete the tagging.
Note:
The tagging operations in the source IP perspective and the instance perspective are mutually linked. After you tag an IP address in the source IP perspective, the tag status is synchronously updated when you view the IP address in the instance perspective, and vice versa.

Account Tagging

Add preset or custom tags to the specified accounts that access the target instance to achieve precise classification and control of accounts accessing the instance, facilitating subsequent risk investigation and permission auditing.
1. In the instance perspective list, click More > Tag Account in the operation column of the target instance.

2. In the Tag Account window, select the account type, edit the account remarks, and click Confirm to complete the tagging.
Note:
You can edit the access account type if it is a self-built account. If the current access account is a cloud root account / sub-account, the system automatically identifies it, and no manual editing is required.

Modifying a Security Group Policy

Quickly go to the asset page of the target database instance and directly modify the security group policy to control all source IPs that access the instance.
In the instance perspective list, click More > Modify Security Group Policy in the operation column of the target instance to go to the database instance asset page and modify the security group policy.


Bantuan dan Dukungan

Apakah halaman ini membantu?

masukan