All Products
Search
Document Center

Security Center:Create and manage anti-ransomware policies and agents

Last Updated:Sep 14, 2026

Security Center's anti-ransomware feature backs up your server data to Cloud Backup. If ransomware encrypts or steals your data, restore it from a backup to minimize downtime and data loss.

Prerequisites

Before you begin, make sure that you have:

Data backup description

  • Security Center uploads data under the backup paths specified in the policy to Cloud Backup for storage. Anti-ransomware data backup uses incremental backup. After a policy is created, the first backup performs a full backup of all protected directories, which consumes a certain amount of CPU and memory resources. To avoid impacting your business, we recommend that you perform data backup during off-peak hours. For subsequent backups, Security Center backs up only the files that have changed (modified, added, or deleted), which reduces server resource usage and avoids consuming excessive anti-ransomware capacity.

  • Capacity planning suggestion: We recommend that you allocate anti-ransomware storage capacity based on the actual data volume of your servers. In general, we recommend that you configure 50 GB of protection space for each server. The first full backup occupies about 60% to 80% of the source data size after compression. Subsequent backups are incremental and consume less capacity because only changed data is backed up.

  • Security Center automatically starts different numbers of backup jobs based on the policy version and backup directories. For the differences between V1.0 and V2.0 policies, see Policy version upgrade.

    Backup directory

    V1.0 policy

    V2.0 policy

    All directories

    • Linux: One backup job is generated for the entire server.

    • Windows: One backup job is generated for each data disk. For example, if your Windows server has two data disks, Security Center generates two backup jobs. These jobs start simultaneously and consume more CPU and memory resources than Linux servers.

      Important

      We recommend that you schedule data backup based on the CPU and memory usage of your Windows servers.

    One backup job is generated for the entire server. Multiple backup jobs run in sequence, consuming less CPU and memory resources without impacting your business.

    Specific directories

    For each directory in the policy, Security Center starts a corresponding backup job. Multiple backup jobs run simultaneously and may consume significant CPU and memory resources.

    Important

    We recommend that you set a reasonable number of backup directories based on your actual needs.

Create an anti-ransomware policy

Before creating a policy, verify that your server's operating system is supported. If the OS version is not supported, data cannot be backed up. See Operating systems and versions supported by anti-ransomware for servers.

  1. Log on to Security Center console.

  2. In the left-side navigation pane, choose Protection Configuration > Host Protection > Anti-Ransomware. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  3. On the Anti-ransomware for Servers tab, click Create Anti-ransomware Policy.

  4. In the Create Anti-ransomware Policy panel, configure the basic parameters.

    Parameter

    Description

    Policy Name

    The name of the anti-ransomware policy.

    Server Type

    The type of server to which the anti-ransomware policy applies.

    Backup Route

    Required only when Server Type is set to Server Not Deployed on Alibaba Cloud. Select the communication method for data backup. Options:

    • Internet: Data is transmitted over the public network, which may incur public bandwidth charges.

    • Internal Network: To transmit data over the private network, use Alibaba Cloud VPC, Express Connect, or CEN to connect servers not deployed on Alibaba Cloud to the anti-ransomware endpoint in the selected region.

    Region

    Required only when Server Type is set to Server Not Deployed on Alibaba Cloud. Select the region where the server resides or a region that has network connectivity with the anti-ransomware endpoint. The selected region specifies the network endpoint for the anti-ransomware service. Make sure the server can communicate with the anti-ransomware endpoint in the selected region. For more information, see Network endpoint.

    Select Asset

    You can select a single asset, multiple assets across groups, or an asset group. Perform the following operations to select the assets to protect:

    • In the Asset Group section, select an asset group. All assets in the group are automatically selected. You can clear the assets that do not need protection in the Asset section.

    • In the Asset section, enter an asset name (fuzzy match is supported) and click the search icon. The related assets are displayed. Select the assets to protect.

    Note
    • When you select assets, Alibaba Cloud servers support configuring servers in multiple regions within a single policy. Servers not deployed on Alibaba Cloud support only servers in the same region within a single policy.

    • To ensure rational and effective use of protection capacity, each server can be added to only one anti-ransomware policy.

  5. In the Create Anti-ransomware Policy panel, configure the specific data backup policy and click OK.

    You can select the recommended policy or a custom policy.

    • Recommended policy: The recommended policy is a built-in policy of Security Center. It cannot be modified and is easy to configure. The specific rules are as follows:

      Setting

      Default value

      Directory to protect

      All directories (excluding system directories)

      Directory to exclude

      Displays the list of excluded directories

      Non-local mount path

      Excludes non-local mount paths (i.e., excludes OSS, NAS, and other non-local mount paths)

      File type to protect

      All file types

      First backup starts at

      Any time between 00:00 and 03:00

      Periodic backup interval

      One day

      Backup data retention period

      7 days

      Maximum backup bandwidth

      • Alibaba Cloud servers: 0 MB/s

        Note

        0 MB/s means no bandwidth limit for backups.

      • Servers not deployed on Alibaba Cloud: 5 MB/s

    • Custom policy: You can define the specific rules of the policy. This provides high flexibility. You can specify the directory to protect, directory to exclude, file type to protect, data backup start time, backup interval, backup data retention period, and maximum backup bandwidth (MB/s). The following describes the parameters.

      Setting

      Description

      Directory to protect

      Select the directories to back up. You can select the following types:

      • Specific Directory: backs up the specified directories of the selected assets. You must add the directory paths to protect in Directory Address. Configuration example:

        • Windows: C:\Program Files (x86)\

        • Linux: /usr/bin/

        You can add up to 20 directory paths. Security Center runs backup jobs for each directory path in sequence. If a directory contains many files, it may consume significant server resources (CPU and memory). You can split a directory into multiple directory paths and run backup jobs in sequence to reduce resource usage.

      • All Directories: backs up all directories of the selected assets.

      Directory to exclude

      Specifies the directories to exclude from backup. Security Center provides default directories to exclude. You can modify these directories.

      Non-local Mount Path

      Select whether to exclude non-local mount paths. Non-local mount paths refer to OSS, NAS, and other mount paths.

      File type to protect

      Select the file types to protect. You can select the following types:

      • All File Types: backs up and protects all file types.

      • Specific File Types: backs up and protects specified file types. You can select document types, image types, and more.

        Important

        You can select multiple file types. Security Center backs up only the selected file types on the assets.

      First backup starts at

      Set the data backup start time.

      Important

      After a policy is created, the first backup performs a full backup of all protected directories, which consumes a certain amount of CPU and memory resources. To avoid impacting your business, we recommend that you perform data backup during off-peak hours.

      Periodic backup interval

      Set the backup interval. Default: one day.

      Backup data retention period

      Set the backup data retention period. Default: 7 days.

      Important

      After the retention period expires, backup data is automatically cleared. We recommend that you set a reasonable retention period based on your business requirements.

      You can select the following retention methods:

      • Permanent: Backup data is retained until the Security Center service expires, the protection policy is deleted, or the server is removed from the policy.

      • Custom: Custom retention period. Minimum: 1 day. Maximum: 65,535 days.

      Maximum backup bandwidth

      Set the network bandwidth threshold for backup data. Value range: 0 MB/s to unlimited.

      Backup data for Alibaba Cloud servers uses only the private network bandwidth and does not affect the public network bandwidth. Backup data for servers not deployed on Alibaba Cloud uses the public or private network bandwidth. You can set the bandwidth threshold to prevent backup jobs from consuming excessive bandwidth and affecting your business.

      • Alibaba Cloud servers: 0 MB/s by default.

        Note

        0 MB/s means no bandwidth limit for backups.

      • Servers not deployed on Alibaba Cloud: 5 MB/s by default.

  6. After the protection policy is created, the policy status is enabled by default. Security Center automatically installs the anti-ransomware agent on the server and backs up the protected directories of the effective servers based on the backup conditions set in the policy.

    Warning

    Pay attention to the status of the anti-ransomware agent and handle abnormal statuses promptly to ensure that anti-ransomware backup and restoration tasks are properly executed. For more information, see View the status of the anti-ransomware agent.

Manage protection policies

Policy version upgrade

The latest version of the anti-ransomware policy is V2.0. Existing V1.0 policies cannot be edited.

Differences between V1.0 and V2.0

Difference

V1.0

V2.0

Custom directories to exclude

Not supported

Supported

Classic network

Compatibility with Cloud Backup

Backup method

Multiple backup jobs run simultaneously (may cause high CPU utilization).

Multiple backup jobs run in sequence.

One-click upgrade

You can upgrade a V1.0 policy to V2.0 by clicking Actions > Upgrade in the policy list. During the upgrade, the anti-ransomware agent on the affected servers is also upgraded to V2.X.X.

Note
  • The agent upgrade replaces the client but does not affect existing backup data. Backup jobs continue normally after the upgrade. If the upgrade fails, the agent automatically rolls back to V1.X.X without affecting backups.

  • Some servers may fail to upgrade automatically. If this happens, remove the failed servers from the policy, click Actions > Upgrade to upgrade the policy to V2.0, then re-add the removed servers. The V2.X.X agent is installed automatically when the servers are re-added.

Reconfigure policies (after OS replacement)

After a server's operating system is replaced, the protected directories configured in the policy remain unchanged. This may cause high resource usage or backup failures if the directories do not match the new OS.

After an OS replacement, verify whether the existing policy meets the protection requirements of the new OS:

  • If the existing policy meets the requirements: remove the server from the policy and re-add it.

  • If the existing policy does not meet the requirements: modify the policy, or remove the server from the current policy and create a new policy.

Manage the anti-ransomware agent

View the status of the anti-ransomware agent

After a protection policy is created, on the Anti-ransomware for Servers tab, find the policy in the policy list and click the 展开 icon on the left of the policy to expand the list of servers to which the policy applies. Check the status of the anti-ransomware agent on each server. Make sure that the agent status is Online. Security Center can back up server data only when the agent status is Online. You can click the number under Recoverable Versions for a server. On the Recoverable Data Versions page, determine whether the server data is backed up based on the Version name (that is, backup time).

If the backup agent status is abnormal, the protection policy cannot back up data. You must identify the cause of the abnormal status and handle the exception. For more information, see Anti-ransomware troubleshooting.

Note

A service exception may be a backup exception or a restoration exception. If the exception is related to restoration, backups can still proceed normally. Handle the exception based on the instructions on the page.

Manually install the anti-ransomware agent

After you create a protection policy, Security Center automatically installs the anti-ransomware agent on the server. If the server is offline or configured with specific firewall rules, the automatic installation may fail. After the anti-ransomware agent fails to be installed, you must first identify and handle the cause of the installation failure, and then manually install the anti-ransomware agent for the server. For more information about how to manually install the anti-ransomware agent, see Manage servers in an anti-ransomware policy.

Uninstall the anti-ransomware agent

If the agent on a server in the policy is abnormal, click Uninstall in the Actions column of the server to uninstall the anti-ransomware agent, and then reinstall the agent.

Note

After you uninstall the anti-ransomware agent, Security Center does not delete the server data that is backed up by the agent within the backup data retention period of the anti-ransomware policy. If the backup data retention period expires, the backed-up server data is deleted.

Delete the anti-ransomware agent

If a server no longer needs the protection of the anti-ransomware policy, you can delete the anti-ransomware agent on the server. When you delete the anti-ransomware agent, the server is removed from the list of servers to which the policy applies, and the backup data of the server is also deleted. The deletion of server backup data releases the corresponding anti-ransomware capacity. The release of anti-ransomware capacity is delayed by 24 to 72 hours. We recommend that you maintain sufficient storage capacity and do not exhaust the capacity. If the storage capacity is exhausted and a full backup is performed after backup stops, server resource consumption becomes excessively high.

Important

Deleting the agent deletes backup data at the same time. Deleted backup data cannot be restored. Proceed with caution.

Data recovery after ransomware infection

If your server data is infected by ransomware, you can use the data backed up by the anti-ransomware feature to restore it. The following is the complete emergency response process:

  1. Isolate the infected server: Immediately disconnect the infected server from the network to prevent the ransomware from spreading further. You can use security group rules to block inbound and outbound traffic for the server.

  2. Verify snapshot backup: In the Security Center console, on the Anti-ransomware for Servers tab, find the policy in the policy list and click the expand icon on the left of the policy to expand the list of servers to which the policy applies. Click the number under the backup count for the corresponding server to go to the backup data page and check the snapshot backup time to confirm whether the backup data is complete.

    Important

    Carefully evaluate the backup time and the time when the data was encrypted. If the backup time is earlier than the time when the data was encrypted, you can roll back the snapshot to restore the data. If the backup time is after the data was encrypted, the backup data may have been infected.

  3. Remove the virus: Before restoring data, we recommend that you reset the system disk or completely remove the ransomware from the server to prevent the data from being encrypted again after restoration. For more information, see Reconfigure policies (after OS replacement).

  4. Roll back the snapshot to restore data: After confirming that the snapshot backup time is appropriate, select the backup version to restore on the backup data page and perform a snapshot rollback to restore the data to the state at the time of the backup. For detailed operations on snapshot rollback, see the relevant documentation.

  5. Security hardening: After data restoration, we recommend that you perform security hardening, including fixing vulnerabilities, setting complex passwords, and restricting remote login IP addresses to prevent future intrusions.

Related documentation