Security Center provides security capabilities such as malicious host behavior defense, anti-ransomware (bait capture), and webshell connection defense. This topic describes the host protection features, edition restrictions, and configuration methods.
Proactive defense
Security Center can automatically intercept common viruses, malicious network connections, and webshell connections, and deploy bait files to capture ransomware. The following describes each sub-feature.
Malicious Host Behavior Prevention
Supported editions: Anti-virus, Advanced, Enterprise, and Ultimate
Overview: Automatically intercepts and removes common network viruses, including ransomware, DDoS trojans, mining programs, malicious programs, backdoors, and worms. This feature is enabled by default after you purchase Security Center, and all servers are automatically included in the detection scope.
NoteInfection-type viruses embed malicious code into normal program files. After a large number of normal programs are infected, they are detected as hosts. Such viruses may endanger system processes, and terminating these processes may cause system stability risks. Therefore, Security Center does not automatically quarantine infection-type viruses. You must handle them manually.
To create different malicious host behavior defense rules for different servers, use the custom rules feature.
Edition differences:
Anti-virus and Advanced: Automatically blocks common viruses such as ransomware and mining programs.
Enterprise and Ultimate: Can intercept large-scale intrusion events based on popular attack scenarios in the ATT&CK framework and common service applications, block ransomware encryption behavior, and support custom defense rules. For more information, see Host rule management.
Anti-ransomware (Bait Capture)
Supported editions: Anti-virus, Advanced, Enterprise, and Ultimate
Overview: Deploys bait files on servers to capture new types of ransomware and automatically activates defenses based on virus behavior analysis. Bait files are used only for detection and do not affect your normal business operations.
Webshell Prevention
Supported editions: Enterprise and Ultimate
Overview:
Automatically intercepts abnormal connections initiated by hackers through known webshells and automatically quarantines related files.
Enabled by default after you purchase the Enterprise or Ultimate edition. All servers are automatically included in the detection scope.
Malicious Network Behavior Prevention
Supported editions: Enterprise and Ultimate
Overview: Intercepts network communications between your servers and known malicious sources to enhance server security protection.
User Experience Optimization in Proactive Defense
Supported editions: Anti-virus, Advanced, Enterprise, and Ultimate
Overview: When a server shuts down unexpectedly or security defense capabilities are missing, automatically collects Kdump data for security protection analysis to continuously improve the defense capabilities of Security Center.
Enable defense capabilities
If all features in the Proactive Defense section are disabled, detected viruses are displayed as security alerts, which require manual handling in the console. We recommend that you enable all features in the Proactive Defense section to strengthen your server security. For more information about how to handle security alerts, see Evaluate and handle security alerts.
Access the Security Center console - System Settings - Feature Settings. In the upper-left corner of the page, select the region where the assets to be protected are located: Chinese Mainland or Outside Chinese Mainland. Select the System Settings > Host Protection Settings tab. In the Proactive Defense section, turn on the switches for Malicious Host Behavior Prevention, Anti-ransomware (Bait Capture), Webshell Prevention, and Malicious Network Behavior Prevention.
Click Manage to the right of a proactive defense type, select the server scope on which the virus or malicious behavior interception takes effect, and then click OK.
(Optional) Select the User Experience Optimization in Proactive Defense check box. Enabling proactive defense experience optimization helps Security Center obtain security protection data when servers encounter exceptions, thereby improving security protection capabilities. We recommend that you select this option.
View and handle defense alerts
View alerts
On the or page, set the search condition to Handled and set the alert type to Precise Defense or Proactive Defense for Containers. You can then view the viruses automatically intercepted by the proactive defense feature on the CWPP tab.
Handling suggestions
After you enable the malicious host behavior defense, anti-ransomware (bait capture), and webshell connection defense features of proactive defense, some programs may be falsely reported or fail to be quarantined. For more information about how to handle these issues, see Evaluate and handle security alerts.
If a file is quarantined due to a false positive, you can restore the file from the quarantine list.
For events that failed to be quarantined, you can manually quarantine them on the CWPP tab of or .
Webshell detection and removal
Security Center uses its proprietary detection engine to detect webshells and trojan programs in web servers and web directories. It combines periodic static detection with dynamic detection and provides one-click manual quarantine. The Security Center agent performs webshell detection only after webshell detection and removal is enabled for the server.
Supported editions: The Free edition supports detection of only some types of webshells. Other paid editions support detection of all types of webshells.
NoteFor more comprehensive webshell detection, we recommend that you upgrade to the Anti-virus, Advanced, Enterprise, or Ultimate edition.
Feature description:
Performs a full static scan of web directories daily and automatically triggers dynamic scans when web directory files change.
Allows you to configure the asset scope for webshell detection.
Allows you to quarantine, restore, and ignore detected webshell files.
Disable webshell detection and removal
Security Center enables webshell detection and removal by default for all servers with the agent installed. We recommend that you enable this detection for all servers that provide public-facing web services. If a server is on a completely isolated internal network, you can disable webshell detection and removal for that server by following these steps.
Access the Security Center console - System Settings - Feature Settings. In the upper-left corner of the page, select the region where the assets to be protected are located: Chinese Mainland or Outside Chinese Mainland.
Select the System Settings > Host Protection Settings tab. In the Webshell Detection and Removal section, click Manage.
In the Configure Servers for Webshell Detection and Removal panel, clear the check boxes for the servers on which you want to disable webshell detection and removal, and then click OK.
View and handle webshell alerts
View alerts
On the or page, set the alert type in the search condition to Webshell. On the CWPP tab, you can view related webshell alerts in the alert list.
Handling suggestions
Unhandled webshell alerts may pose serious threats to asset security. For more information about how to handle them in a timely manner, see Evaluate and handle security alerts. The handling methods for users of different editions are as follows:
Free edition users: The one-click handling feature is not supported. You must first upgrade to a paid edition.
Anti-virus edition and above: Supports one-click quarantine of detected webshell files in the console.
Adaptive threat detection
Adaptive threat detection is disabled by default and must be manually enabled. After you enable it, the system performs the following actions:
Automatically triggers strict mode: When the system detects that a server has high-risk issues (that is, generates high-severity alerts), it automatically enables the "Strict Alert Mode" for that server for seven days.
Comprehensive protection mechanism: In strict mode, all security protection rules and security engines are activated to alert on any suspicious intrusion behavior and potential threats, thereby capturing hacker intrusion traces more comprehensively.
Mode persistence: If you manually modify the protection mode of a server within the seven-day validity period, the system no longer automatically disables strict mode after the seven days expire. Instead, it retains the manually set protection status.
Edition restrictions
Only the following editions support adaptive threat detection:
Subscription: Enterprise or Ultimate (If your current edition does not support this feature, upgrade).
NoteThe protection edition of the server must be set to the edition you purchased. For more information, see Bind a server protection edition.
Pay-as-you-go: Host and Container Security pay-as-you-go is activated (If not activated, purchase).
NoteThe server protection level must be set to Host Protection or Host and Container Security. For more information, see Bind a server protection level.
Enable adaptive threat detection
Access the Security Center console - System Settings - Feature Settings. In the upper-left corner of the page, select the region where the assets to be protected are located: Chinese Mainland or Outside Chinese Mainland.
Select the System Settings > Host Protection Settings tab. In the Adaptive Threat Detection Capability section, turn on its switch.
First-time authorization: If you enable this feature for the first time and have not authorized Security Center, the page prompts you to complete the authorization.
After the authorization is successful, Resource Access Management (RAM) automatically creates a service-linked role.
Security Center uses this role to access resources in other cloud services to provide security protection. For more information, see Service-linked roles.
Alert settings
Alert mode comparison
Security Center provides multiple alert modes to meet the security requirements of different business scenarios. By default, Balanced Mode is enabled for all connected servers.
Comparison item | Balanced mode (default) | Strict mode |
Features |
|
|
Applicable scenarios |
|
|
Change the alert mode for servers
Access the Security Center console - System Settings - Feature Settings. In the upper-left corner of the page, select the region where the assets to be protected are located: Chinese Mainland or Outside Chinese Mainland.
Select the System Settings > Host Protection Settings tab. In the Alert Settings section, click Manage to the right of Strict Mode.
Perform one of the following operations based on your business needs, and then click OK.
Switch to strict mode: Select the target servers on which you want to enable Strict Mode.
Revert to balanced mode: Clear the check boxes for servers that are already in Strict Mode.