This topic answers frequently asked questions about Security Center.
What's new
Pre-sales questions
Free trial questions
Purchase questions
Product usage questions
Purchase and renewal questions
Renewal questions
Upgrade and downgrade questions
Refund questions
Vulnerability fixing billing
Console operation issues
If you encounter one of the following errors in the Security Center console, refresh the page and try again. If the error persists, contact technical support.
Error code | Note |
ConsoleSystemError_1001 | A system error occurred. Please refresh the page and try again later. |
ConsoleSystemError_1007 | This API is no longer available. |
ConsoleSystemError_1008 | PostOnly validation failed. |
ConsoleSystemError_1009 | CSRF token is empty. Please refresh the page and try again. |
ConsoleSystemError_1010 | CSRF token validation failed. Please check the token and try again. |
ConsoleSystemError_1011 | RegionID is empty. Please enter a RegionID. |
ConsoleSystemError_1012 | Invalid RegionID format. Please check the RegionID. |
ConsoleSystemError_1013 | A parameter is empty. Please check your parameters. |
ConsoleSystemError_1014 | Invalid parameter format. Please check your parameters. |
Security score questions
How do I view the version of the virus library of Security Center?
What are the priorities to handle security events that I can access in the Secure Score section?
How does the vulnerability scan level affect the security score?
How does the baseline check level affect the security score?
Asset questions
How do I unbind (release) a non-Alibaba Cloud asset?
How does Security Center unbind an Alibaba Cloud ECS server?
Two servers with the same information appear in the server list — one Online and one Offline
Anti-ransomware questions
What is the anti-ransomware feature? Why is it charged separately?
Do backups start automatically after purchasing anti-ransomware capacity?
How do I view my purchased anti-ransomware capacity and its usage?
How do I clear a large anti-ransomware backup cache that occupies disk space?
Can I change the backup cache location if it uses too much C drive space?
What should I do if the anti-ransomware client consumes excessive CPU or memory resources?
What are the differences between the anti-ransomware solution and snapshot backups?
What should I do if the purchased anti-ransomware capacity is insufficient?
What should I do if a protection policy is in an abnormal state?
Why do .aeqis, .zaegis, or !aegis folders still exist on my server after I disable anti-ransomware?
Does the anti-ransomware service guarantee compensation for ransomware infections?
Is anti-ransomware protection necessary for internal network servers without public network access?
How do I confirm whether a server has been targeted by ransomware when no alerts are generated?
I purchased the anti-ransomware service but haven't used it. Can I request a deferral or refund?
Web tamper proofing questions
Can the validity period of the Security Center edition differ from that of file tamper protection?
What are the requirements for the file tamper protection local backup directory?
Why does configuring a tamper protection directory prompt a path error?
Why does file tamper protection fail after configuring a protection directory?
Can I still write files to a directory after configuring it for protection?
What should I do if tamper protection does not take effect immediately after configuration?
What should I do if I cannot modify website content and images after configuring tamper protection?
Why does the number of tamper protection alerts in the console differ from email notifications?
Does the absence of tamper protection alerts mean the files are safe?
Are tamper protection rules automatically generated after a version upgrade?
Linux software vulnerabilities
Does Security Center support Ubuntu 24.04? How do I manually scan for vulnerabilities?
How do I determine whether a Linux kernel version is affected by a specific CVE vulnerability?
What do I do if I receive a target kernel incompatibility error when fixing a kernel vulnerability?
How do I handle timeouts when connecting to the official Alibaba Cloud Yum source?
Vulnerability fixing
After the OS is end of life (EOL), does Security Center support vulnerability scanning and fixing?
Do I need to restart the server when fixing vulnerabilities? What is the impact on business?
What are the risks of not fixing high-risk vulnerabilities (such as Linux Kernel ptrace)?
Will I be charged again if I click Fix again after a vulnerability fix fails?
Do emergency vulnerabilities showing To Be Protected or Protected need to be handled?
Does Security Center support generating and exporting vulnerability scan reports?
How do I determine whether a Linux kernel version is affected by a specific CVE vulnerability?
Do servers without a public IP address support Security Center vulnerability fixing?
What are the precautions and recommendations for enabling automatic vulnerability fixing?
What do I do if batch vulnerability fixing shows "No matching records" or an empty list?
What do I do if vulnerability fixing in an ACK cluster is slow or inefficient?
How do I disable automatic vulnerability fixing to avoid additional charges?
What do I do if I receive a target kernel incompatibility error when fixing a kernel vulnerability?
What do I do if some vulnerabilities in the Security Center console show no updates?
How do I view the failure alert after a vulnerability fix fails?
Does manual vulnerability fixing cause Security Center to generate false positive attack alerts?
Why are vulnerabilities detected even though I did not actively install third-party software?
What does it mean when a vulnerability is marked as fixed with the reason Rule Offline?
Vulnerability detection
Where can I view the latest classification after vulnerability rule categories are adjusted?
Does Security Center support Ubuntu 24.04? How do I manually scan for vulnerabilities?
Why are emergency vulnerabilities not in the Vulnerabilities to Fix (CVE) list?
How do I stop automatic scanning of emergency vulnerabilities?
Why do Security Center scan results differ from third-party security software (such as Huorong)?
Why do inactive instances still report high-risk vulnerabilities?
Does a new scan use or restore historical vulnerability data?
Why does the application vulnerability detection result not show the specific file path?
Do Security Center vulnerability scan results overwrite historical data?
Why does a newly purchased ECS instance have vulnerabilities?
Why is there a significant difference in vulnerability alert counts between two servers?
Why am I prompted that high-risk system vulnerabilities are not fixed?
Baseline checks
Security alerts
How do I determine whether an asset is threatened by crypto-mining?
Virus interception is not enabled and my server is under a crypto-mining attack. What do I do?
I accidentally added a crypto-mining alert to the whitelist. How do I remove it?
How do I verify that automatic virus interception is in effect?
What objects can be added to the whitelist for security alerts?
Brute-force attacks
How do I view the number of brute-force attacks or interception status on my server?
Does brute-force prevention support protecting web applications or websites?
Why do I still receive password brute-force alerts after changing a weak password?
Does ECS logon weak password refer to system-level RDP or SSH scanning?