When you enable pay-as-you-go, Security Center automatically activates protection and scanning features based on recommended strategies. This topic describes the default strategies and billing rules for each feature to help you estimate costs and avoid unexpected charges.
After you select Enable the one-click policy to automatically receive your bill the next day. and click Activate and Authorize, the system performs the following actions by default: it assigns a protection level—Comprehensive Host Protection or Hosts and Container Protection—to all servers, authorizes all Serverless assets, applies the recommended log onboarding strategy for Agentic SOC, enables periodic scanning for Cloud security posture management (CSPM) and Agentless detection, activates the application protection onboarding strategy, and enables the periodic detection strategy for the Malicious file detection SDK.
Security Center enables protection, assigns the corresponding licenses, ingests the required logs, and runs the specified scanning and detection tasks based on the one-click onboarding strategy.
Security Center generates billing statements on a daily basis according to the the billing rules of each feature. To avoid unexpected charges, carefully review and understand the one-click onboarding strategy before enabling this feature.
One-click onboarding strategies
Host and container security
After you enable and authorize the service, the host and container security feature of Security Center automatically assigns a protection level to all servers under your Alibaba Cloud account: either Comprehensive Host Protection or Hosts and Container Protection.
Server assets that run container environments (including Alibaba Cloud ACK cluster nodes, Lingjun nodes, and servers connected from self-managed Kubernetes clusters) are automatically assigned to the Hosts and Container Protection protection level. All other assets are assigned to Comprehensive Host Protection.
Later, you can change the protection level assigned to a server on the Security Center consoleOverview page by using the Quota Management entry. For more information, see Configure protection editions or levels.
Newly added hosts are assigned to the Unprotected protection level by default. We recommend that you use the Quota Management feature to configure the automatic protection level for newly added hosts.
Serverless security
After you enable and authorize the service, the Serverless security feature of Security Center automatically authorizes all Serverless assets under your Alibaba Cloud account.
For ECI assets created by managed or dedicated ACK clusters, ACK Serverless clusters, or ACS clusters, you must install and start the Security Center agent before you can use the Serverless security protection capabilities provided by Security Center. For more information, see Serverless security.
Later, you can manage the authorization status of assets on the Security Center console page. For more information, see Serverless security.
Application protection
After you enable and authorize the service, the application protection feature of Security Center automatically enables full protection (Java processes only) and onboards using the slow rollout method.
You can later adjust the servers and processes to be onboarded on the tab. For more information about automatic full onboarding, see Automatic full access (Java processes only).
Agentic malicious file detection
After you enable and authorize the malicious file detection feature, the system automatically creates and enables a default detection policy named Auto_Create_Config. To modify the policy, navigate to the tab, and click Policy Management in the Policy Configuration section to view and modify the policy. The policy details are as follows:
Detection scope: All OSS buckets under your Alibaba Cloud account.
Detection objects: All newly added or updated files after the feature is enabled.
Execution cycle: Once per day.
Detection method: No decompression or decryption by default.
On the day you enable the service, a detection task is executed once based on the preceding policy.
Agentic CSPM
Users who have never enabled the CSPM periodic scanning policy:
Scan frequency: Once per day. The specific scan time is randomly generated by the system.
Scan scope:
The system checks for common high-risk configuration issues in security best practices, including misconfigured security protection settings, exposed high-risk ports, public network access via whitelists, public read/write access to data, and risks related to identity authentication and privileged permissions. These checks help improve the security of cloud products and the cloud platform.
You can view the default scan check items in the Policy Management panel on the page of the Security Center console. The selected check items represent the scan scope of the recommended strategy.
Users who have previously enabled the CSPM periodic scanning policy:
Scan frequency: Consistent with the historical configuration.
Scan scope: The union of the historically configured check items and the check items included in the recommended scan scope described above.
Vulnerability remediation
After you enable and authorize the service, the vulnerability remediation pay-as-you-go feature is activated.
Security Center configures an automatic vulnerability remediation strategy. Every day between 00:00 and 06:00, it automatically remediates high-severity vulnerabilities on all affected assets (including newly added hosts). Before remediation, a snapshot is created and retained for one day. For more information, see Manage vulnerabilities.
Agentic agentless detection
Scan frequency: Once every 5 days.
Scan scope: All machines, with Default Scan for New Assets selected by default.
On the day after you enable the service, a detection task is executed once based on the preceding policy.
Anti-Ransomware
Regularly backs up important file paths on servers. If a ransomware attack occurs, you can use the backup files for fallback recovery. To adjust the protection scope, go to the anti-ransomware policy management page.
Log Management
Security Center logs are delivered to the log store. By default, logs in mainland China are delivered to China (Shanghai), and logs outside mainland China are delivered to Singapore.
Billing
Base service fee
When you enable any pay-as-you-go feature on the Security Center unified sales page, the system charges an additional base service fee. The billing rules are as follows:
After activation, DingTalk chatbot, security reports, and task center (requires Vulnerability Fixing to be enabled or purchased first) are available by default.
Billing method: Metered by the duration that pay-as-you-go service is enabled.
ImportantThe minimum billing unit is one hour. Enabled duration shorter than one hour is billed as one hour.
Billing cycle: Settled daily.
Price: USD 0.0072/hour.
Host and container security
After you enable pay-as-you-go for host and container security, charges are calculated based on the number of servers assigned to the protection level and the actual protection duration (calculated only when the agent is online), billed per second and settled on a daily basis.
Billing method: Metered by protection level, number of bound servers, and actual protection duration (in seconds). Actual protection duration is measured from client online time.
Billing cycle: Settled daily.
Price: Varies by protection level. See the following table.
Protection level
Price
Monthly cost (30-day reference)
Antivirus
USD 0.000000578/core/second
USD 1.5/core/month
Advanced
USD 0.000005497/server/second
USD 14.25/server/month
Comprehensive Host Protection
USD 0.000013599/server/second
USD 35.25/server/month
Hosts and Container Protection
USD 0.000013599/server/second+USD 0.000000578/core/second
USD 35.25/server/month+USD 1.5/core/month
Serverless security
Billing method: Metered by number of authorized server cores × actual protection duration (seconds). Actual protection duration is measured from client online time.
Billing cycle: Settled daily.
Price: Tiered pricing based on monthly cumulative usage.
Monthly cumulative usage description:
Daily monthly cumulative usage = monthly cumulative usage up to the previous day (0 on the first day) + current day's daily usage.
NoteIn the first month of activation, the statistics period runs from the activation date to the end of that month. Starting from the second month, the statistics period is a calendar month (from the 1st to the end of the month).
Example: Day 1 monthly cumulative usage = Day 1 usage. Day 2 monthly cumulative usage = Day 1 usage + Day 2 usage. Day 3 monthly cumulative usage = Day 1 usage + Day 2 usage + Day 3 usage, and so on.
Tier pricing:
Monthly cumulative usage
Price
Fee formula (U = daily usage, unit: core/second)
Tier 1: 0-200,000,000 core/second
USD 0.000003/core/second
0.000003×U (USD)
Tier 2: 200,000,001-1,000,000,000 core/second
USD 0.000002/core/second
First day entering this tier:
0.000003×200,000,000+0.000002×(U-200,000,000) (USD)
Subsequent days: 0.000002×U (USD)
Tier 3: 1,000,000,001-9,999,999,999,999 core/second
USD 0.0000015/core/second
First day entering this tier:
0.000003×200,000,000+0.000002×800,000,000
+0.0000015×(U-1,000,000,000) (USD)
Subsequent days: 0.0000015×U (USD).
Billing example:
Scenario: Serverless assets have 20,000 cores running 24 hours (86,400 seconds) per day. Daily usage (U) = 20,000 cores × 86,400 seconds/day = 1,728,000,000 core/second.
Day 1 fee:
Usage description: Day 1 monthly cumulative usage = Day 1 usage = 1,728,000,000 core/second. The monthly cumulative usage has reached Tier 3, so it is billed using the cross-tier "first day entering Tier 3" formula.
Fee calculation: Day 1 fee = 0.000003 (Tier 1 unit price)×200,000,000+0.000002 (Tier 2 unit price)×800,000,000+0.0000015 (Tier 3 unit price)×(1,728,000,000-1,000,000,000)=3,292 (USD).
Day 2 and subsequent fees:
Usage description: Since the Day 1 monthly cumulative usage has already reached Tier 3, from Day 2 to the end of the month, the monthly cumulative usage remains in Tier 3 and daily fees are billed at the Tier 3 unit price.
Fee calculation: Daily fee = 0.0000015 (Tier 3 unit price)×(20,000×86,400)=2,592 (USD).
Application protection
After you enable pay-as-you-go for application protection, the system counts the number of online instances per minute (0–60 seconds) and charges USD 0.0002 per instance per minute, billed on a daily basis.
Agentic Malicious File Detection
Billing method: Metered by the number of files detected.
Billing cycle: Settled daily.
Price: USD 0.0012 per file.
Agentic CSPM
A billing instance is the measurement unit for Agentic CSPM paid features. An "instance" refers to a specific network device or application entity (such as an OSS bucket or ECS instance). Agentic CSPM bills based on the number of cloud product billing instances that are scanned, verified, and remediated. Multiple scans, verifications, or remediations within a single billing cycle do not incur additional charges. Instances can be divided into two types based on whether charges are generated:
Billing instance: such as OSS buckets and ECS instances.
Non-billing instance: such as ECS security groups.
For example, if you have 50 OSS buckets (all billing instances) and multiple scan and remediation operations are performed on them within the same billing cycle, the number of billing instances remains 50 and does not increase due to the number of operations.
Billing method: Metered by the number of billable cloud service instances scanned, verified, and remediated. For authorization consumption rules, see Authorization (postpaid) consumption description.
Billing cycle: Settled daily.
Price: USD 0.0732/instance/day. Multiple scans, verifications, and remediations within one billing cycle do not incur additional charges.
Vulnerability remediation
After you enable pay-as-you-go for vulnerability remediation, charges are USD 0.3 per remediation, billed on a daily basis. For more information, see Overview.
Agentless detection
Billing method:
Agentic agentless detection and analysis: Billed by scanned data volume (GB).
Agentic vulnerability fixing: Billed by the number of successfully fixed vulnerabilities.
If a vulnerability exists on 3 hosts, successfully fixing all of them counts as 3 fixed vulnerabilities.
If a fixing task involves 3 vulnerabilities, successfully fixing all of them counts as 3 fixed vulnerabilities.
Billing cycle: Settled daily.
Price:
Agentic agentless detection and analysis: USD 0.13/GB.
Agentic vulnerability fixing: USD 1.33/vulnerability.
NoteDuring detection and fixing, custom images are created for ECS hosts. and storing a 40 GB custom image for one day costs approximately USD 0.027. These costs are charged by ECS.
Anti-Ransomware
Billed based on the backup file size and storage duration. The price is USD 0.00013 per GB per hour.
Log Management
Billed based on the daily cumulative storage volume (GB). The price is USD 7.2 per 1,000 GB.
FAQ
Can I modify the recommended strategies after enabling them?
Yes. You can modify the recommended strategies for each feature on their respective management pages.
To change the protection level assigned to a server, see Configure protection editions or levels.
To modify the authorization status for Serverless assets, see Serverless security.
To modify the default detection policy of the Malicious file detection SDK for OSS files, see Malicious file detection.
To modify the CSPM periodic scanning policy, see Configure and run check policies.
To modify the Agentless detection scanning policy, see Detect and fix risks.
To modify the log types connected to Agentic SOC, see Product logs.
To modify the onboarding configuration for application protection, see Manage protection policies.