Ransomware poses serious threats to cybersecurity. Security Center provides protection policies, generates alerts, and backs up data to protect your server from ransomware. You can create an anti-ransomware policy to back up data on your server. This topic describes how to create an anti-ransomware policy.
Background information
After you create an anti-ransomware policy, Security Center automatically backs up data in protected directories on your server. If your protected server is attacked by ransomware, you can restore data based on the backup data. This reduces negative impacts on your business.
Version description
Data backup
Create an anti-ransomware policy
Before you create an anti-ransomware policy, make sure the operating system version of your server is supported by anti-ransomware for servers. If the operating system version is not supported, the data of your server cannot be backed up. For more information about supported operating system versions, see Operating systems and versions supported by anti-ransomware for servers.
Purchase the anti-ransomware capacity and authorize your account to use the anti-ransomware feature. For more information, see Enable anti-ransomware.
Log on to the Security Center console. In the top navigation bar, select the region of the asset that you want to manage. The following regions are supported: China and Outside China.
In the left-side navigation pane, choose .
On the Server extortion virus protection tab of the Anti-ransomware page, click Create Policies.
In the Create Policies panel, configure the following parameters and click Determine.
Parameter
Description
Policy Name:
The name of the anti-ransomware policy.
Server Type
The type of the server to which you want to apply the anti-ransomware policy.
Backup Route
If you set Server Type to Server Not Deployed on Alibaba Cloud, you must specify the communication method to back up data. Valid values:
Internet: If you select this option, you may be charged for Internet bandwidth resources.
Internal Network: If you select this option, you must use Alibaba Cloud virtual private clouds (VPCs), Express Connect circuits, or Cloud Enterprise Network (CEN) instances to establish connections between the servers that are not deployed on Alibaba Cloud and the anti-ransomware endpoint in the selected region.
Region
If you set Server Type to Server Not Deployed on Alibaba Cloud, you must select the region where the server resides or a region in which an anti-ransomware endpoint is available. The selected region specifies the endpoint that is used to access anti-ransomware. To successfully back up data, make sure that the server can access the anti-ransomware endpoint in the selected region. For more information, see Anti-ransomware endpoints.
Select Assets:
The assets that you want to protect. You can select an asset, an asset group, or multiple assets from asset groups. To select the assets that you want to protect, perform the following operations:
In the Asset group section, select an asset group. Then, all assets in the group are selected. You can clear assets that do not require protection in the Assets section.
In the Assets section, enter the name of an asset in the search box to search for the asset. Fuzzy match is supported.
NoteIf you want to apply the anti-ransomware policy to Elastic Compute Service (ECS) instances, you can select ECS instances that reside in different regions. If you want to apply the anti-ransomware policy to the servers that are not deployed on Alibaba Cloud, you must select the servers that reside in the same region.
To make sure that the anti-ransomware capacity is effectively utilized, you can add a server to only one policy.
Protection Policies:
The anti-ransomware policy that you want to configure. Valid values:
Recommendation Policy
If you select Recommendation Policy, the default values of the following parameters are used:
Protected Directories: All directories
Exclude specified directories: directories that are excluded from the policy
Protected File Types: All File Types
Start Time: a point in time within the range of 00:00 to 03:00
Backup policy execution interval: One Day
Backup data retention period: 7 Days
The bandwidth limit of the backup network: 0 MByte/s
NoteThe value 0 indicates that no limits are imposed on the bandwidth.
VSS(Windows): Yes
NoteThe VSS feature is available only if you create the anti-ransomware policy for Windows servers. After you enable the feature, the number of backup failures due to running processes is significantly reduced. We recommend that you enable the VSS feature. After you enable the feature, the data of disks that are in the exFAT and FAT32 formats cannot be backed up.
Custom policy
If you select Custom policy, you must configure parameters based on your business requirements. The parameters include Protected Directories, Protected File Types, Start Time, Backup policy execution interval, Backup data retention period, and The bandwidth limit of the backup network.
Protected Directories:
The directories that you want to back up. Valid values:
Specified directory: Security Center backs up only specified directories of the specified servers. You must enter the addresses of the specified directories for Protect directory address:. Examples:
Windows server:
C:\Program Files (x86)\
Linux server:
/usr/bin/
You can enter up to 20 addresses. Security Center runs backup tasks in sequence based on protected directory addresses. If a large number of files are stored at a protected directory address, a large amount of server resources such as CPU and memory resources may be consumed to back up data at the address. In this case, you can split the directory into multiple addresses. Then, backup tasks run in sequence based on the addresses. This helps reduce the server resources that are consumed by each backup task.
All directories: Security Center backs up all directories of the specified servers.
Protected File Types:
The type of the files that you want to protect. Valid values:
All File Types: Security Center protects all files.
Specify file type: Security Center protects files only of the selected file type. You can select file types such as document and image.
ImportantYou can select multiple file types. Security Center protects only the files of the selected file types.
Start Time:
The time at which you want to start a data backup task.
ImportantIf this is the first time that you back up all data in protected directories based on an anti-ransomware policy, a large number of CPU and memory resources are consumed. To avoid negative impacts on your services, we recommend that you back up data during off-peak hours.
Backup policy execution interval:
The time interval between two data backup tasks. Default value: One Day. Valid values:
Half a day
One Day
3 days
Seven Days
Backup data retention period:
The retention period of backup data. Default value: 7 Days.
ImportantThe backup data is stored only within the specified retention period. We recommend that you specify the retention period based on your business requirements.
Valid values:
Permanent
Custom: You can specify a retention period. Valid values: 1 to 65535. Unit: days.
The bandwidth limit of the backup network:
The maximum bandwidth that can be consumed by a data backup task. Valid values: 1 to unlimited. Unit: MB/s.
If you create the anti-ransomware policy for an ECS instance, only internal network bandwidth is consumed. Servers that are not deployed on Alibaba Cloud consume public or internal network bandwidth during data backup. You can configure this parameter to prevent backup tasks from consuming an excessive amount of bandwidth and ensure service stability.
VSS(Windows)
Specifies whether to enable the VSS feature. The feature can maintain the change history of files and audit trace logs. The feature is also used for disaster recovery for files that contain source code. The VSS feature is available only for Windows servers. After you enable the feature, the number of backup failures due to running processes is significantly reduced. Valid values:
Yes: enables the feature.
No: disables the feature.
After the anti-ransomware policy is created, the policy is enabled by default, and Security Center installs the anti-ransomware agent on your server. Then, Security Center backs up data in the protected directories of your server based on the backup settings that you configure in the anti-ransomware policy.
After you create an anti-ransomware policy, we recommend that you monitor the status of the anti-ransomware agent and handle the exceptions on the agent in a timely manner. This ensures that the data backup tasks and restoration tasks run as expected. For more information, see View the status of the anti-ransomware agent.
What to do next
View the status of the anti-ransomware agent
After the anti-ransomware policy is created, you must check the status of the anti-ransomware agent that is installed on the servers protected by the anti-ransomware policy and make sure that the anti-ransomware agent is in the Client online state. To check the status of the anti-ransomware agent, go to the Server extortion virus protection tab of the Anti-ransomware page, find the anti-ransomware policy, and then click the
icon next to the policy name. In the list of servers that are protected by the anti-ransomware policy, view the agent status in the Agent Status column. Security Center can back up data for the servers only if the anti-ransomware agent is in the Client online state. You can click a number in the Recoverable Versions column to go to the Recoverable Version panel. If a version is displayed in the Version column of the Recoverable Version panel, data on the server is backed up.
If the status of the anti-ransomware agent is Not Installed, failed, or Exception, data backup fails. You must identify the cause of the exception to the anti-ransomware agent and handle the exception.
NoteIf the status of the anti-ransomware agent is Exception, errors may occur during data backup or data restoration. If errors occur during data restoration, data backup tasks are not affected. You can handle the exception as prompted.
You can use one of the following methods to handle the exception:
Follow the instructions on the Anti-ransomware page.
Submit a ticket for consultation and start a live chat for support.
Manually install the anti-ransomware agent
After the anti-ransomware policy is created, Security Center automatically installs the anti-ransomware agent on your server. If your server is not started or is configured with specific firewall policies, Security Center may fail to install the anti-ransomware agent on the server. If the anti-ransomware agent fails to be installed, you must identify the cause and resolve the issue. Then, install the anti-ransomware agent on the server. For more information about how to manually install the anti-ransomware agent, see Manage servers that are added to an anti-ransomware policy.
Uninstall the anti-ransomware agent
If the status of the anti-ransomware agent that is installed on the server in the anti-ransomware policy is Exception or failed, you can click Uninstall in the Actions column for the server to uninstall the anti-ransomware agent. Then, reinstall the anti-ransomware agent on the server.
NoteIf you uninstall the anti-ransomware agent within the period specified by the Backup data retention period parameter, Security Center does not delete the data that the anti-ransomware agent backs up. If you uninstall the anti-ransomware agent in the time that is not within the period specified by the Backup data retention period parameter, Security Center deletes the backup data of the server.
Delete the anti-ransomware agent
If a server no longer requires the anti-ransomware policy, you can delete the anti-ransomware agent from the server. If you delete the anti-ransomware agent from the server, the server is deleted from the list of servers that use the anti-ransomware policy, and the backup data of the server is deleted. After the backup data on the server is deleted, Security Center releases the anti-ransomware capacity. The anti-ransomware capacity is updated within 24 to 72 hours after the release. We recommend that you do not run out of the anti-ransomware capacity. If the anti-ransomware capacity is used up, data backup tasks stop, and a full backup is performed. This significantly increases the resource usage of the server.
ImportantIf the anti-ransomware agent is deleted from your server, the backup data on your server is also deleted. Deleted backup data cannot be restored. Proceed with caution.