Skip to content

Security Recommendations for AutoSteps

AutoSteps provides synthetic monitoring for application performance management by running executable and scripted recordings of transactions. Because AutoSteps runs as a logged-on user with automatic logon, limit access both to and from the computers with PerformanceGuard agents that run AutoSteps. Consider the following recommendations when you install AutoSteps.

Diagram of the security layers around an AutoSteps computer: network firewall, computer firewall and user context, with rules on traffic to the PerformanceGuard frontend on port 4001 and to external servers

AutoSteps runs as a user and not as a service. It only works, and keeps running, while the computer is logged on. That’s why the AutoSteps installer turns on Windows automatic logon for the account you specify, see Install AutoSteps.

If the computers are physical rather than virtual, restrict access to them at the same level as production servers, for example by placing them in a locked server room. Configure automatic locking for the shortest practical time. A computer without a monitor and keyboard further limits physical access.

Restrict remote desktop access from other computers as much as possible with:

  • User login permissions
  • Subnet or IP-based restrictions
  • Place the computers on a separate subnet behind a firewall to have the most granular control of the network traffic.
  • Only allow access from the AutoSteps computers to the PerformanceGuard frontend server on port 4001 (or the port you have configured for agent connections).
  • Set the agents’ authentication and encryption to the strictest level for connections to the PerformanceGuard frontend server, to avoid rogue servers.
  • Minimize traffic between the AutoSteps subnet and the production and server subnets as much as possible.

Set up dedicated firewall rules on the computers, as well as rules for the processes that AutoSteps runs. You can combine these with other rules for more granular network access.

  • Only allow access from the AutoSteps computers to the PerformanceGuard frontend server on port 4001.
  • Only allow access to external servers from the processes that run the scripts.
  • Consider rules in the local Windows firewall that only allow the processes run by AutoSteps.exe.
  • Use a dedicated user account for AutoSteps.
  • Give this account the minimum network permissions it needs.

The AES key ensures secure communication between the PerformanceGuard agent and the frontend server.

  • Create a secret encryption key.
  • Enable the key both for the AutoSteps agents and for the frontend server during installation.
  • Configure the agents to use Strong encryption.