All Products
Search
Document Center

Security Center:Host protection settings

Last Updated:Jun 18, 2026

Security Center provides security capabilities such as malicious host behavior defense, anti-ransomware (bait capture), and webshell connection defense. This topic describes the host protection features, edition restrictions, and configuration methods.

Proactive defense

Security Center can automatically intercept common viruses, malicious network connections, and webshell connections, and deploy bait files to capture ransomware. The following describes each sub-feature.

Malicious Host Behavior Prevention

  • Supported editions: Anti-virus, Advanced, Enterprise, and Ultimate

  • Overview: Automatically intercepts and removes common network viruses, including ransomware, DDoS trojans, mining programs, malicious programs, backdoors, and worms. This feature is enabled by default after you purchase Security Center, and all servers are automatically included in the detection scope.

    Note
    • Infection-type viruses embed malicious code into normal program files. After a large number of normal programs are infected, they are detected as hosts. Such viruses may endanger system processes, and terminating these processes may cause system stability risks. Therefore, Security Center does not automatically quarantine infection-type viruses. You must handle them manually.

    • To create different malicious host behavior defense rules for different servers, use the custom rules feature.

  • Edition differences:

    • Anti-virus and Advanced: Automatically blocks common viruses such as ransomware and mining programs.

    • Enterprise and Ultimate: Can intercept large-scale intrusion events based on popular attack scenarios in the ATT&CK framework and common service applications, block ransomware encryption behavior, and support custom defense rules. For more information, see Host rule management.

Anti-ransomware (Bait Capture)

  • Supported editions: Anti-virus, Advanced, Enterprise, and Ultimate

  • Overview: Deploys bait files on servers to capture new types of ransomware and automatically activates defenses based on virus behavior analysis. Bait files are used only for detection and do not affect your normal business operations.

Webshell Prevention

  • Supported editions: Enterprise and Ultimate

  • Overview:

    • Automatically intercepts abnormal connections initiated by hackers through known webshells and automatically quarantines related files.

    • Enabled by default after you purchase the Enterprise or Ultimate edition. All servers are automatically included in the detection scope.

Malicious Network Behavior Prevention

  • Supported editions: Enterprise and Ultimate

  • Overview: Intercepts network communications between your servers and known malicious sources to enhance server security protection.

User Experience Optimization in Proactive Defense

  • Supported editions: Anti-virus, Advanced, Enterprise, and Ultimate

  • Overview: When a server shuts down unexpectedly or security defense capabilities are missing, automatically collects Kdump data for security protection analysis to continuously improve the defense capabilities of Security Center.

Enable defense capabilities

Note

If all features in the Proactive Defense section are disabled, detected viruses are displayed as security alerts, which require manual handling in the console. We recommend that you enable all features in the Proactive Defense section to strengthen your server security. For more information about how to handle security alerts, see Evaluate and handle security alerts.

  1. Access the Security Center console - System Settings - Feature Settings. In the upper-left corner of the page, select the region where the assets to be protected are located: Chinese Mainland or Outside Chinese Mainland. Select the System Settings > Host Protection Settings tab. In the Proactive Defense section, turn on the switches for Malicious Host Behavior Prevention, Anti-ransomware (Bait Capture), Webshell Prevention, and Malicious Network Behavior Prevention.

  2. Click Manage to the right of a proactive defense type, select the server scope on which the virus or malicious behavior interception takes effect, and then click OK.

  3. (Optional) Select the User Experience Optimization in Proactive Defense check box. Enabling proactive defense experience optimization helps Security Center obtain security protection data when servers encounter exceptions, thereby improving security protection capabilities. We recommend that you select this option.

View and handle defense alerts

  • View alerts

    On the Detection and Response > Alert or Agentic SOC > Alert page, set the search condition to Handled and set the alert type to Precise Defense or Proactive Defense for Containers. You can then view the viruses automatically intercepted by the proactive defense feature on the CWPP tab.

  • Handling suggestions

    After you enable the malicious host behavior defense, anti-ransomware (bait capture), and webshell connection defense features of proactive defense, some programs may be falsely reported or fail to be quarantined. For more information about how to handle these issues, see Evaluate and handle security alerts.

    • If a file is quarantined due to a false positive, you can restore the file from the quarantine list.

    • For events that failed to be quarantined, you can manually quarantine them on the CWPP tab of Detection and Response > Alert or Agentic SOC > Alert.

Webshell detection and removal

Security Center uses its proprietary detection engine to detect webshells and trojan programs in web servers and web directories. It combines periodic static detection with dynamic detection and provides one-click manual quarantine. The Security Center agent performs webshell detection only after webshell detection and removal is enabled for the server.

  • Supported editions: The Free edition supports detection of only some types of webshells. Other paid editions support detection of all types of webshells.

    Note

    For more comprehensive webshell detection, we recommend that you upgrade to the Anti-virus, Advanced, Enterprise, or Ultimate edition.

  • Feature description:

    • Performs a full static scan of web directories daily and automatically triggers dynamic scans when web directory files change.

    • Allows you to configure the asset scope for webshell detection.

    • Allows you to quarantine, restore, and ignore detected webshell files.

Disable webshell detection and removal

Security Center enables webshell detection and removal by default for all servers with the agent installed. We recommend that you enable this detection for all servers that provide public-facing web services. If a server is on a completely isolated internal network, you can disable webshell detection and removal for that server by following these steps.

  1. Access the Security Center console - System Settings - Feature Settings. In the upper-left corner of the page, select the region where the assets to be protected are located: Chinese Mainland or Outside Chinese Mainland.

  2. Select the System Settings > Host Protection Settings tab. In the Webshell Detection and Removal section, click Manage.

  3. In the Configure Servers for Webshell Detection and Removal panel, clear the check boxes for the servers on which you want to disable webshell detection and removal, and then click OK.

View and handle webshell alerts

  • View alerts

    On the Detection and Response > Alert or Agentic SOC > Alert page, set the alert type in the search condition to Webshell. On the CWPP tab, you can view related webshell alerts in the alert list.

  • Handling suggestions

    Unhandled webshell alerts may pose serious threats to asset security. For more information about how to handle them in a timely manner, see Evaluate and handle security alerts. The handling methods for users of different editions are as follows:

    • Free edition users: The one-click handling feature is not supported. You must first upgrade to a paid edition.

    • Anti-virus edition and above: Supports one-click quarantine of detected webshell files in the console.

Adaptive threat detection

Adaptive threat detection is disabled by default and must be manually enabled. After you enable it, the system performs the following actions:

  • Automatically triggers strict mode: When the system detects that a server has high-risk issues (that is, generates high-severity alerts), it automatically enables the "Strict Alert Mode" for that server for seven days.

  • Comprehensive protection mechanism: In strict mode, all security protection rules and security engines are activated to alert on any suspicious intrusion behavior and potential threats, thereby capturing hacker intrusion traces more comprehensively.

  • Mode persistence: If you manually modify the protection mode of a server within the seven-day validity period, the system no longer automatically disables strict mode after the seven days expire. Instead, it retains the manually set protection status.

Edition restrictions

Only the following editions support adaptive threat detection:

  • Subscription: Enterprise or Ultimate (If your current edition does not support this feature, upgrade).

    Note

    The protection edition of the server must be set to the edition you purchased. For more information, see Bind a server protection edition.

  • Pay-as-you-go: Host and Container Security pay-as-you-go is activated (If not activated, purchase).

    Note

    The server protection level must be set to Host Protection or Host and Container Security. For more information, see Bind a server protection level.

Enable adaptive threat detection

  1. Access the Security Center console - System Settings - Feature Settings. In the upper-left corner of the page, select the region where the assets to be protected are located: Chinese Mainland or Outside Chinese Mainland.

  2. Select the System Settings > Host Protection Settings tab. In the Adaptive Threat Detection Capability section, turn on its switch.

  3. First-time authorization: If you enable this feature for the first time and have not authorized Security Center, the page prompts you to complete the authorization.

    • After the authorization is successful, Resource Access Management (RAM) automatically creates a service-linked role.

    • Security Center uses this role to access resources in other cloud services to provide security protection. For more information, see Service-linked roles.

Alert settings

Alert mode comparison

Security Center provides multiple alert modes to meet the security requirements of different business scenarios. By default, Balanced Mode is enabled for all connected servers.

Comparison item

Balanced mode (default)

Strict mode

Features

  • Low false positive rate: Optimized through comprehensive testing by Alibaba Cloud experts.

  • High detection rate: Detects as many suspicious risks as possible while ensuring fewer false positives.

  • Well-balanced: Balances security and business stability.

  • High sensitivity: More stringent detection rules covering more suspicious behaviors.

  • High detection rate: Can discover more hidden or subtle potential threats.

  • False positive risk: May identify normal business behaviors as anomalies.

Applicable scenarios

  • Daily operational monitoring.

  • Scenarios with high requirements for business continuity.

  • Most routine server protection.

  • During critical protection periods (such as major events or holiday security).

  • Intensive investigation phase after an attack.

  • Core assets that are extremely security-sensitive and can tolerate a certain number of false positives.

Change the alert mode for servers

  1. Access the Security Center console - System Settings - Feature Settings. In the upper-left corner of the page, select the region where the assets to be protected are located: Chinese Mainland or Outside Chinese Mainland.

  2. Select the System Settings > Host Protection Settings tab. In the Alert Settings section, click Manage to the right of Strict Mode.

  3. Perform one of the following operations based on your business needs, and then click OK.

    • Switch to strict mode: Select the target servers on which you want to enable Strict Mode.

    • Revert to balanced mode: Clear the check boxes for servers that are already in Strict Mode.