Ransomware is malware that encrypts your business data, causing service disruptions, data leakage, and data loss. These attacks pose significant risks to your business. This topic describes how to enhance the anti-ransomware capabilities of your instances.
Background
As technology evolves, new types of malware emerge, and ransomware has become a common threat. Alibaba Cloud uses its extensive experience in cloud security and cutting-edge security technologies to provide comprehensive security solutions. For more information about how to defend against ransomware, see Overview of the anti-ransomware service.
Symptoms
When your instance is attacked by ransomware, its system files are encrypted, and you will find a ransom note in the user's working directory. For example, on a Windows-based instance, a ransom note like the one below typically appears.

After ransomware encrypts or locks system files, the instance may fail to start or you may be unable to connect to it remotely. This is often one of the first signs of an anomaly. If you are suddenly unable to connect to your instance, investigate a potential ransomware attack.
Solution overview
Although preventive measures can reduce the risk of infection, they cannot entirely eliminate it. For ransomware, data backup is your last line of defense. However, when you restore data from a backup or a snapshot, any data generated between the snapshot creation and the disk rollback is lost. Therefore, you must develop a data backup strategy suitable for your business to protect your critical data.
The following are common strategies to protect against ransomware.
-
Strategy 1: Use Security Center to enhance anti-ransomware capabilities
-
Strategy 2: Use an automatic snapshot policy to create backups
-
Strategy 3: Use security policies such as security groups and firewalls to enhance protection
You can implement these protection strategies in parallel and select the ones that best suit your business needs. For example, if your business has high requirements for business continuity, you can apply all three strategies. However, this may incur charges for backups or snapshots.
Strategy 1: Use Security Center for anti-ransomware
Workflow
Procedure
-
Enable the anti-ransomware service and purchase anti-ransomware capacity.
To use the anti-ransomware feature in Security Center, you must enable the service and purchase anti-ransomware capacity. For more information, see Enable and purchase the anti-ransomware service.
NoteYou can purchase anti-ransomware services based on your business requirements.
-
Create a protection policy.
After you enable the service, follow these steps to create a protection policy.
-
(Optional) Restore data from a valid backup in Security Center.
-
Create a snapshot of the system disk and data disks of the infected instance. For more information, see Create a manual snapshot.
-
If your instance is attacked by ransomware, you can use a backup from Security Center to quickly restore your services. Follow these steps to restore your data.
-
Strategy 2: Use automatic snapshots
Workflow
Procedure
Creating backups for an instance by using snapshots allows you to recover data after a ransomware attack. Note that this strategy provides only post-incident recovery capabilities and is not a substitute for proactive protection measures.
-
Create an automatic snapshot policy for the instance. For more information, see Create an automatic snapshot policy.
-
(Optional) Restore data from a valid snapshot that was created before the instance was infected.
-
Create a snapshot of the system disk and data disks of the infected instance. For more information, see Create a manual snapshot.
ImportantA disk rollback is irreversible. Data generated between the snapshot creation and the rollback is lost. To prevent data loss from accidental operations, we recommend that you create a snapshot to back up your data before you roll back a disk.
-
For more information about how to reinitialize the system disk of an instance, see Re-initialize a system disk (reset the OS).
-
To learn how to use a snapshot to restore data to a system disk or a data disk, see Roll back a disk by using a snapshot.
-
Strategy 3: Use security groups and firewalls
Workflow
Procedure
Security policies, such as those for security groups and firewalls, can enhance an instance's protection against ransomware. However, this requires you to have technical expertise in network security.
-
For best practices for security group and firewall policies, see Best practices for ECS security groups (inbound rules) and Configuration guide for Windows Firewall policies.
-
(Optional) Contact a third-party company to decrypt and restore data.
-
Create a snapshot for the system disk and data disks of the instance that is infected with ransomware. For more information, see Create a manual snapshot.
-
For more information about how to reinitialize the system disk of an instance, see Re-initialize a system disk (reset the OS).
-
After you reinitialize the system disk of the compromised instance, if you have not backed up important data or created a snapshot, you can contact a third-party company to decrypt and restore the data.
WarningThe data decryption capabilities provided by third-party companies after a ransomware attack are independent of Alibaba Cloud. Alibaba Cloud is not responsible for the success of data recovery or any data corruption.
-
Related documents
-
To troubleshoot anti-ransomware client and backup task exceptions, see Troubleshoot anti-ransomware exceptions.
-
For solutions to high disk space usage caused by anti-ransomware backups, see Solutions for high disk space usage by anti-ransomware backups.
-
For solutions to high memory usage caused by anti-ransomware backups, see Solutions for high disk space or memory usage by anti-ransomware backups.
-
For information about how to manage protection policies after you change the operating system of a server, see Create a protection policy and manage clients.