All Products
Search
Document Center

Security Center:Asset Center FAQ

Last Updated:Sep 11, 2026

Find answers to common questions about the Asset Center page in Security Center. This FAQ also covers related server management topics, such as quota usage, Security Center agent behavior, and log collection.

How do I unbind (release) a non-Alibaba Cloud asset?

If a non-Alibaba Cloud server no longer requires protection, you can unbind it manually in Security Center. For instructions, see Manage server protection status.

After you unbind a server, Security Center no longer protects it. No data about that asset, including alerts, vulnerabilities, and attack information, is available in the Security Center console.

How does Security Center unbind an Alibaba Cloud ECS server?

Security Center does not support unbinding an Alibaba Cloud ECS server. An Alibaba Cloud ECS server that you purchased remains in the server list with an offline status even after you uninstall the Security Center agent. The server is removed from the server list only after you release it in the ECS console.

Two servers with the same information appear in the server list — one Online and one Offline

Issue symptoms

After you reinstall the operating system and the Security Center agent on a non-Alibaba Cloud server, two identical servers appear in the server list: one is online and the other is offline.

Cause

For a non-Alibaba Cloud server, Security Center uses the UUID of the Security Center agent as its unique identifier. Reinstalling the operating system and the Security Center agent generates a UUID that differs from the previous one, so the console displays two records for the same server.

Solution

Unbind the offline server in the server list. Unbinding releases its quota, which you can use to bind a new server. For instructions on unbinding a non-Alibaba Cloud server, see Unbind non-Alibaba Cloud servers.

Why does an operation not permitted error occur when I run a command or terminate a process on a host?

Check the following possible causes.

  • Insufficient permissions

    Confirm that the current user is root. If the current user is not root, switch to root before you perform the related operation.

  • Agent self-protection interception

    Attempts to terminate a process or modify files related to the Security Center agent can be intercepted by the agent self-protection process (AliSecGuard). The console displays a corresponding security alert. Disable agent self-protection in the console before you retry the operation. Perform the following steps:

    • Disable agent self-protection for a specific host

      1. Log on to the Security Center console. In the Asset Center > Host section of the asset list, select the server for which you want to disable agent self-protection.

      2. In the Actions column, click View to open the asset details page. On the Basic Information tab, select the Defense Status subtab, and turn off Self-Protection Status.

    • Disable agent self-protection for all hosts

      1. Log on to the Security Center console. Go to System Configuration > Feature Settings, select the Settings tab, and then select the Agent Settings subtab.

      2. In the Agent Protection section, turn off Defense Mode:.

  • The operation triggered a Security Center malicious-detection rule and is blocked by Malicious Host Behavior Defense (AliHips process).

    When you run certain commands or perform certain actions, Malicious Host Behavior Defense can block the operation if it triggers a Security Center malicious-detection rule. The console displays a corresponding security alert in Detection and Response > Security Alerts > Precision Defense. You can perform the following steps:

    • Add the blocked alert to the allowlist by using Malicious Host Behavior Prevention. For instructions, see Create custom defense rules.

    • Go to System Configuration > Feature Settings, select the Settings tab, and then select the Protection Settings subtab. Turn off Malicious Host Behavior Prevention.

Why does quota management show a negative used-core or active-core count?

A negative used-core or active-core count in quota management (for example, active -220 cores) usually indicates that the total cores of the currently connected servers exceed the effective quota, or is a calculation difference caused by a quota adjustment such as a downgrade or an unsubscription.

Compare the total cores of the currently connected servers with the purchased and effective quota.

How do I troubleshoot a website logon session timeout or restricted access message?

A website logon session timeout or restricted access message is usually caused by the website's logon restrictions, code rules, or damaged files, rather than a direct block by Security Center. Troubleshoot the issue in the following order:

  1. Check the website's logon restriction policy and code rules.

  2. If you suspect that malware damaged files, uninstall and reinstall the Security Center agent, and then run an anti-virus scan.

  3. If custom website files are confirmed to be damaged, repair the website code.

Can a server join multiple server groups?

No. A server can belong to only one server group (resource group) and cannot join multiple server groups.

If you want to classify servers across multiple dimensions, use the tag feature. A server can have multiple tags. Use Manage Server Groups to determine the unique ownership of a server, and use Manage Server Tags for multi-dimensional classification. Choose a management method based on the differences between these two features.

Why does Security Center not record SSH logon logs?

Troubleshoot the issue in the following order:

  1. Log on to the server and check the local system log (for example, /var/log/auth.log) to confirm that it contains SSH logon records.

  2. If the local log contains records but Security Center does not, check that the Security Center agent is running normally.

  3. In the Security Center console, go to Risk Governance > Log Analysis > Log Management Settings, and confirm that the delivery switch for logon events and other host log types is turned on.