All Products
Search
Document Center

Security Center:What is Security Center

Last Updated:Aug 06, 2026

Security Center is a cloud-native workload protection platform. Managing security across hybrid and multi-cloud environments can be complex. Security Center provides a single control plane to discover assets, detect risks, and respond to threats automatically. It protects workloads on Alibaba Cloud, other cloud providers, and in on-premises data centers against ransomware, malicious mining, and vulnerability exploits, and helps you meet compliance requirements such as Multi-Level Protection Scheme (MLPS) 2.0.

How it works

Security Center runs a closed-loop security operations cycle built on five components:

  • Asset inventory: Maintains a unified inventory of all servers, containers, and cloud-native resources across multi-cloud environments, providing the visibility needed for risk assessment and policy enforcement.

  • Risk discovery: Proactively scans for operating system (OS) and application vulnerabilities, cloud product misconfigurations, and identity risks such as leaked AccessKey pairs.

  • Security hardening: Remediates discovered risks by patching vulnerabilities, correcting misconfigurations, enabling web tamper proofing, and backing up data against ransomware.

  • Real-time protection: Monitors host and container runtime environments continuously. Using virus signatures, behavior analysis, and Runtime Application Self-Protection (RASP), it detects and automatically blocks viruses, Trojans, unauthorized logons, and malicious files.

  • Proactive detection and response: Uses cloud honeypots to lure attackers, reconstructs attack chains with Agentic SOC (AI-driven Security Operations Center) [Enterprise, Ultimate], and applies a security large language model (LLM) for alert correlation. Automated incident handling runs through Security Orchestration, Automation and Response (SOAR) [Enterprise, Ultimate].image

Use cases

MLPS 2.0 compliance

Security Center maps its security capabilities directly to Multi-Level Protection Scheme (MLPS) 2.0 clauses. Baseline checks and remediation, vulnerability management, security audits, and intrusion prevention collectively satisfy the technical and administrative controls required by the standard.

image

Unified host security for hybrid and multi-cloud environments

For workloads spread across Alibaba Cloud, other cloud providers, and on-premises data centers, Security Center provides a single security control plane. Deploy the agent on all servers and manage virus scanning, vulnerability assessments, and policy configuration from one console — regardless of platform or region.

image

Full container lifecycle security

Security Center covers every stage of the container lifecycle — from build and deployment to runtime. Container image scanning, runtime intrusion detection and prevention, and Kubernetes cluster threat detection collectively secure cloud-native applications at each phase.

image

Benefits

Security Center is a cloud-native security product. Compared with traditional server antivirus software, it offers the following advantages:

  • Unified management: Centralized management console for hosts and containers across Alibaba Cloud, other cloud providers, and on-premises data centers.

  • Lightweight and efficient: Cloud-based detection with endpoint-based response. The Agent runs in low-consumption mode with no measurable effect on business workloads.

  • Deep integration: Detects configuration risks in cloud products and interoperates with Cloud Firewall to close the security operations loop with automated threat response.

  • Comprehensive attack detection: Over 380 threat detection models and eight protection engines identify and block the latest threats end to end.

Billing methods

Security Center supports subscription, pay-as-you-go, and hybrid billing. All billing methods include the Free Edition capabilities. Choose a paid billing method only when you need enhanced features.

Important

Regardless of the billing method you choose, you retain the Free Edition capabilities, which include basic vulnerability scanning, threat detection, and abnormal logon alerts. See Key considerations for guidance on choosing a paid edition.

Item

Subscription

Pay-as-you-go

Hybrid

Payment model

Single upfront fee for a monthly or yearly term. Fixed cost simplifies budgeting.

Pay only for what you use. No upfront investment.

Package fee is fixed; additional usage beyond the package is billed on a pay-as-you-go basis. The two parts are billed independently.

Fee breakdown

Fees = Edition fee + Value-added service fee (optional).

  • Edition fee: Editions such as Anti-virus, Advanced, Enterprise, Ultimate, Value-added Plan are available. Higher-tier editions include more comprehensive features.

  • Value-added service fee: Purchase additional value-added services, such as anti-ransomware and Agentic SOC.

Note

For subscription fee details, see Subscription.

Fees = Basic service fee + Feature usage fee.

  • Basic service fee: Charged when you enable any pay-as-you-go feature. It includes services such as DingTalk Robot, security reports, and Task Hub (requires purchase or activation of vulnerability fixing).

  • Feature usage fee: Charges apply for the specific features you purchase and enable. Each feature can be enabled and billed separately.

Note

For pay-as-you-go fee details, see Pay-as-you-go.

  • Fees = Subscription quota fee + Elastic quota fee. Subscription quota fee: fixed fee charged based on the quota of the purchased edition or feature package.

  • Elastic quota fee: when actual usage exceeds the subscription quota, the excess is automatically billed on a pay-as-you-go basis.

Note

For hybrid billing fee details, see Hybrid billing.

Best for

Stable, long-term workloads with a fixed budget.

Elastic scaling, short-term projects, or frequently changing demands.

Stable long-term business needs with a fixed budget but occasional incremental demand beyond the purchased quota, where you want to avoid interruption of security protection due to quota exhaustion.

Service regions and data centers

Security Center operates two global service centers with isolated data and configurations. Select the region matching your assets in the Security Center console top navigation bar.

  • Data centers in the Chinese mainland: provides security detection and protection for assets in the Chinese mainland region.

  • Singapore data center: provides security detection and protection for assets in the Outside Chinese mainland region.

Region

Data center

Asset locations protected

Chinese Mainland

Data centers in the Chinese mainland

  • China (Qingdao), China (Beijing), China (Zhangjiakou), China (Hohhot), China (Ulanqab)

  • China (Shenzhen), China (Heyuan), China (Guangzhou)

  • China (Hangzhou), China (Shanghai), China (Nanjing - Decommissioning)

  • China (Chengdu)

Outside Chinese Mainland

Singapore data center

  • Japan (Tokyo), South Korea (Seoul), Singapore, Malaysia (Kuala Lumpur), Indonesia (Jakarta), Philippines (Manila), Thailand (Bangkok)

  • Germany (Frankfurt), UK (London), US (Virginia), US (Silicon Valley)

  • SAU (Riyadh - Partner Region), UAE (Dubai)

  • China (Hong Kong)

Integrated Alibaba Cloud services

Log analysis

Security Center integrates with Alibaba Cloud Log Service (SLS) to provide a log analysis module that collects server logs and security logs, and provides accurate real-time log query and analysis capabilities.

Before using log analysis in Security Center, you must activate Alibaba Cloud Log Service (SLS) and purchase Log Storage Capacity on the Security Center buy page.

ActionTrail

ActionTrail helps you monitor and record activities of your Alibaba Cloud account, including access and usage of cloud products and services through the Alibaba Cloud console, OpenAPI, and developer tools. Download or save these behavior events to Log Service or OSS buckets for behavior analysis, security analysis, resource change tracking, and behavior compliance auditing. For more information, see ActionTrail overview.

Resource access management

Resource Access Management (RAM) is an Alibaba Cloud service that manages user identities and resource access permissions. RAM allows you to create and manage multiple identities under one Alibaba Cloud account and grant different permissions to individual identities or groups of identities, so that different users have different resource access permissions. For more information, see What is RAM?.

Get started

Before you start, make sure you have the following: an Alibaba Cloud account with Security Center activated, RAM permissions for Security Center, and outbound HTTPS access for Agent communication. Select the appropriate region (Chinese mainland or Outside Chinese mainland) in the console top navigation bar.

  1. Onboard your assets based on asset type:

  2. Manage your assets by type:

  3. Review Security Center features, then start with vulnerability scanning and baseline checks for immediate risk visibility.

  4. Verify onboarding: navigate to Security Center > Assets in the console and confirm that your servers appear with an Agent status of Online. For guided walkthroughs, see Security Center quick start and Agentic SOC quick start.

Note

Troubleshooting: If an asset shows offline, check that RAM permissions are granted, outbound HTTPS traffic is allowed, and the correct region is selected in the console.

FAQ

Editions, trials, and billing

  • How do I choose the right Security Center edition?

    See Key considerations for a quick edition decision guide, or see Editions for a detailed feature comparison.

  • Can I apply for the free trial more than once?

    No. Each Alibaba Cloud account is eligible for only one free trial of the Enterprise Edition.

  • What is the difference between the Free Edition and the Enterprise Edition free trial?

    Feature

    Free Edition

    Enterprise Edition free trial

    Eligible accounts

    All Alibaba Cloud accounts that have completed identity verification

    Accounts that have not activated a trial or paid version of the Enterprise Edition

    Capabilities

    Basic security capabilities, permanently

    Full Enterprise Edition capabilities for 7 days

    Duration

    Permanent

    7 days

    Core features

    Scanning for abnormal logons, mining and DDoS Trojans, and major vulnerabilities

    All Enterprise Edition features, including virus scanning, advanced threat detection, and vulnerability remediation

    Activation

    Activated automatically — no application required

    Each account can apply only once

  • How do I get Security Center for free?

Core features and scenarios

  • Does Security Center comply with international security standards?

    Yes. Security Center is certified for ISO 9001, ISO 20000, ISO 22301, ISO 27001, ISO 27017, ISO 27018, ISO 29151, ISO 27701, BS 10012, CSA STAR, and Payment Card Industry Data Security Standard (PCI DSS), among other international standards.

  • Does Security Center support virus scanning and removal?

    Yes. The Anti-virus, Premium, Enterprise, and Ultimate editions detect and remove common network viruses.

  • Can Security Center automatically quarantine infected files?

    Automatic quarantine is not supported, but automatic blocking is available.

    • Automatic blocking: Pre-execution defense — detects and blocks malicious processes and behaviors in real time when a virus attempts to intrude, before the system is infected. Security Center can automatically block ransomware, mining programs, Trojans, and other network viruses.

    • Manual file quarantine: Moves an infected file to a quarantine area. Because quarantining a system or business file can interrupt services, an administrator must assess the risk and perform this action manually to preserve business continuity.

  • How does Security Center provide end-to-end security during a cyberattack?

    Security Center covers all three stages of an attack:

    • Before an attack (assessment and hardening): Discovers risks through asset information collection, vulnerability assessment, and baseline checks. One-click remediation, baseline hardening, and permission optimization reduce the attack surface.

    • During an attack (detection and defense): Detects and blocks webshells, unusual outbound connections, brute-force attacks, ransomware, and mining programs.

    • After an incident (response and forensics): Correlates cloud-based threat intelligence with host behavior anomalies to generate alerts, trace the attack chain, and support emergency response.

Asset coverage and connection

  • Can Security Center protect non-Alibaba Cloud servers, such as those in on-premises data centers or from other cloud providers?

    Yes. Install the Agent on non-Alibaba Cloud servers to bring them under unified protection in Security Center.

    Server type

    How to connect

    Alibaba Cloud ECS

    Select Security Hardening at purchase and the Agent installs automatically, activating the Free Edition. To install or upgrade manually, follow the console instructions after purchasing a paid edition.

    Data center or third-party cloud servers

    Install the Agent and connect over the Internet or through a proxy. See Connect servers in data centers to Security Center through a proxy cluster and Add assets from third-party clouds.

  • My server assets are outside the Chinese mainland. Can I still use Security Center? How is my data handled?

    Yes. Security Center provides a Singapore data center for assets in the Outside Chinese mainland region. When you select Outside Chinese mainland in the Security Center console, all security data is processed and stored in the Singapore data center with no cross-border data transfer, in compliance with data sovereignty requirements.