
40
Appendix 1 Security Recommendation
Account Management
1.
Use complex passwords
Please refer to the following suggestions to set passwords:
●
The length should not be less than 8 characters;
●
Include at least two types of characters: upper and lower case letters, numbers and symbols;
●
Do not contain the account name or the account name in reverse order;
●
Do not use continuous characters, such as 123, abc, etc.;
●
Do not use repeating characters, such as 111, aaa, etc.
2.
Change passwords periodically
It is recommended to periodically change the device password to reduce the risk of being
guessed or cracked.
3.
Allocate accounts and permissions appropriately
Appropriately add users based on service and management requirements and assign minimum
permission sets to users.
4.
Enable account lockout function
The account lockout function is enabled by default. You are advised to keep it enabled to protect
account security. After multiple failed password attempts, the corresponding account and source
IP address will be locked.
5.
Set and update password reset information in a timely manner
The device supports password reset function. To reduce the risk of this function being used by
threat actors, if there is any change in the information, please modify it in time. When setting
security questions, it is recommended not to use easily guessed answers.
Service Configuration
1.
Enable HTTPS
It is recommended that you enable HTTPS to access web services through secure channels.
2.
Encrypted transmission of audio and video
If your audio and video data contents are very important or sensitive, it is recommended to use
encrypted transmission function in order to reduce the risk of your audio and video data being
eavesdropped during transmission.
3.
Turn off non-essential services and use safe mode
If not needed, it is recommended to turn off some services such as SSH, SNMP, SMTP, UPnP, AP
hotspot etc., to reduce the attack surfaces.
If necessary, it is highly recommended to choose safe modes, including but not limited to the
following services:
●
SNMP: Choose SNMP v3, and set up strong encryption and authentication passwords.
●
SMTP: Choose TLS to access mailbox server.
●
FTP: Choose SFTP, and set up complex passwords.
●
AP hotspot: Choose WPA2-PSK encryption mode, and set up complex passwords.
4.
Change HTTP and other default service ports