After you install the Security Center agent, it starts processes such as AliYunDun and AliYunDunMonitor on your server to collect system information and detect threats. You can check the process status to determine whether security protection is active. This topic provides a detailed description of the files and processes of the Security Center agent.
Agent architecture
The Security Center agent uses a modular architecture that consists of core resident processes and functional processes to ensure the stable operation of basic features and the efficient scheduling of advanced features.
-
Resident processes:
AliYunDun,AliYunDunMonitor, andAliYunDunUpdatecommunicate with the Security Center server, maintain heartbeats, report basic security data, and perform self-updates to provide the basic running capabilities for the agent. -
Functional processes (non-resident processes):
AliHipsandAliNetare downloaded and started on demand only after you enable the corresponding advanced defense features in the console, such as malicious host behavior prevention and web tamper proofing.
Process details
-
To prevent agent function exceptions, do not manually terminate or delete the related processes and files.
-
To delete agent-related files, see Client configuration to disable agent self-protection.
Core processes
Core processes ensure communication between the agent and the cloud and the normal operation of basic monitoring capabilities. They start automatically after the agent is installed.
Starting from aegis_12_3x, the AliSecureCheckAdvanced and AliDetect processes are merged into AliSecCheck. Earlier versions are not affected.
|
Process name |
Folder |
Description |
|
|
|
Communicates with the Security Center server, reports heartbeats, receives instructions, reports data, and enforces agent self-protection. |
|
|
|
Monitors host security, including the collection and detection of information such as assets, processes, ports, and accounts. |
|
|
|
Automatically updates the agent version and rule libraries. |
|
|
|
Runs security scan and detection tasks, including vulnerability scans, compliance baseline checks, and runtime detection of malicious programs such as mining programs and trojans |
Functional processes
Functional processes are tied to specific paid features and start only after you enable the corresponding feature.
|
Process name |
Folder |
Description |
Start condition |
|
|
|
Provides network-layer protection to block network behaviors such as malicious IP access and outbound attacks. |
Enable Malicious Network Behavior Prevention. |
|
|
|
Provides host intrusion prevention to block malicious host behaviors, prevent ransomware, and defend against web shell connections. |
Enable any one of Malicious Host Behavior Prevention, Anti-Ransomware (Bait Capture), Webshell Connection Prevention. |
|
|
|
Performs web tamper proofing and core file monitoring. |
Enable Web Tamper Proofing or Core File Monitoring. |
|
|
|
Runs tasks such as security reports, anomaly detection, and real-time monitoring. |
Enable Anti-ransomware for Servers. |
|
|
|
Runs tasks such as data backup, data restoration, fault monitoring, and task scheduling. |
|
|
|
|
Database backup proxy process that runs tasks such as initial database backup, incremental backup, database backup restoration, scheduling and management, and logging and monitoring. |
Enable Anti-ransomware for Databases. |
Relationship between processes and features
|
Feature name |
Related process |
Edition/protection level limits |
Documentation |
|
Self-Protection Status |
|
None |
|
|
Malicious Network Behavior Prevention |
|
|
|
|
Malicious Host Behavior Prevention |
|
|
|
|
Anti-Ransomware (Bait Capture) |
|
|
|
|
Webshell Connection Prevention |
|
|
|
|
Web Tamper Proofing |
|
None Important
This feature is a value-added service that must be purchased separately. |
|
|
File Tamper Proofing |
|
|
|
|
Anti-ransomware for Servers |
|
None Important
This feature is a value-added service (Managed Anti-ransomware) that must be purchased separately. |
|
|
Anti-ransomware for Databases |
|
None Important
This feature is a value-added service (Managed Anti-ransomware) that must be purchased separately. |
Relationship between processes and agent status
Security Center evaluates the online status of the agent by monitoring the communication between the AliYunDun process and the server. The agent status changes from Online to Offline when either of the following situations occurs.
You can view the agent status of your servers on the Host page: Offline (
), Online (
).
-
The server detects that the communication with the agent is interrupted, for example, due to network exceptions, the
AliYunDunprocess being terminated, or the agent being uninstalled. -
The server has not received any information reported by the agent, such as heartbeats or security data, within 10 hours.
Running permissions and file paths
Process permissions
To provide comprehensive security monitoring and protection, the agent processes must run with high privileges in the operating system. The high privileges are used to perform low-level operations such as kernel-level monitoring, file system protection, network behavior analysis, and process self-protection.
-
On Linux, processes run as the
rootaccount. -
On Windows, processes run as the
SYSTEMaccount.
Default process file paths
-
Windows:
-
32-bit: C:\Program Files\Alibaba\aegis.
-
64-bit: C:\Program Files (x86)\Alibaba\aegis.
-
-
Linux: /usr/local/aegis.
How to check process status
You can use the following commands to quickly check whether the agent processes and services are running properly. The following examples use the core processes.
Linux
Commands to check processes:
# Check that AliYunDun, AliYunDunMonitor, and AliYunDunUpdate are all running.
ps -ef | grep -E 'AliYunDun|YunDunMonitor|YunDunUpdate'
# Check the service status. The output should show "active (running)".
systemctl status aegis
Sample output in normal state:
root 5472 1 0 Sep10 ? 00:00:18 /usr/local/aegis/aegis_update/AliYunDunUpdate
root 5524 1 0 Sep10 ? 00:01:34 /usr/local/aegis/aegis_client/aegis_12_61/AliYunDun
root 5546 1 0 Sep10 ? 00:03:13 /usr/local/aegis/aegis_client/aegis_12_61/AliYunDunMonitor
● aegis.service - LSB: Aegis service
Loaded: loaded (/etc/rc.d/init.d/aegis; generated)
Active: active (running) since Mon 2023-10-30 10:00:00 CST; 1 day 2h ago
Windows
-
Method 1: Check the processes in Task Manager. Open Windows Task Manager and go to the Processes tab. Confirm that the following Aegis-related processes are running normally:
Alibaba Security Aegis Detect Service,Alibaba Security Aegis Update Service,Alibaba Security Monitor Detect Service,AliDetect.exe,AliWebGuard.exe. The CPU usage of each process should be close to 0%, and the memory usage should range from several MB to tens of MB. -
Method 2: Run the following commands in PowerShell
Commands to check processes:
# Check that the three core processes are running. Get-Process | Where-Object {$_.Name -match '^(AliYunDun|AliYunDunMonitor|AliYunDunUpdate)$'} # Check the service status. The Status column should show "Running". Get-Service | Where-Object {$_.Name -match 'Aegis|AliYunDun'}Sample output in normal state:
Handles NPM(K) PM(K) WS(K) CPU(s) Id SI ProcessName ------- ------ ----- ----- ------ -- -- ----------- 380 26 15948 19656 615.75 6072 0 AliYunDun 599 31 47576 37356 968.73 2488 0 AliYunDunMonitor 257 14 8072 11336 232.03 2904 0 AliYunDunUpdate Status Name DisplayName ------ ---- ----------- Running Alibaba Securit... Alibaba Security Aegis Detect Service Running Alibaba Securit... Alibaba Security Aegis Update Service