All Products
Search
Document Center

Security Center:Onboard and protect ECS instances

Last Updated:Aug 20, 2026

By default, a newly purchased Alibaba Cloud ECS instance is onboarded to the free Basic version of Security Center, which provides only fundamental risk detection. Host protection capabilities such as automatic virus interception, vulnerability remediation, and baseline checks require a paid version of Security Center, with a protection version bound to the instance. This topic walks you through the end-to-end onboarding path: activating Security Center, onboarding ECS assets, verifying the agent, and assigning a protection version and protection level. Follow it to bring your ECS instances into a protected state the first time you use the service.

Background

Security Center is a unified security management platform that identifies, analyzes, and issues alerts on security threats in real time. Capabilities such as anti-ransomware, antivirus, web tamper proofing, and compliance checks form a closed-loop, automated security operations workflow that spans threat detection, response, and forensic tracing, protecting both cloud assets and on-premises hosts while helping you meet regulatory compliance requirements. The Anti-virus, Advanced, Enterprise, and Ultimate versions additionally intercept viruses automatically, providing proactive defense against prevalent ransomware families such as WannaCry and GlobeImposter and DDoS trojans such as XorDDos and BillGates.

Workflow

  1. Activate Security Center: On the Overview page of the Security Center console, activate a paid Host and Container Security version by using the pay-as-you-go billing method.

  2. Onboard ECS assets: Security Center automatically synchronizes the Alibaba Cloud ECS assets under the current account. For newly purchased servers, you can trigger a manual synchronization to retrieve the latest assets.

  3. Install the agent: Verify that the Security Center agent is installed and online on the ECS server. If the agent is missing, install it manually.

  4. Configure the protection level: After ECS assets are onboarded, Security Center binds a protection level automatically based on default rules. You can also change the level manually to suit your business requirements.

  5. View and handle security risks: Once a protection level is bound and the agent is online, review security risks on the Security Center Overview page or in the ECS console and remediate them promptly.

Step 1: Activate Security Center

The following procedure activates a paid version of Security Center by using the pay-as-you-go billing method.

  1. Go to the Security Center console - Overview page.

  2. In the Enable Pay-as-You-Go Service area, enable the switch for Host and Container Security.

  3. In the pay-as-you-go activation dialog box, read the service agreement, and then click Activate Now.

Step 2: Onboard ECS assets

No manual instance registration or onboarding information is required. Security Center synchronizes Alibaba Cloud host assets periodically. A newly created server may not appear in the asset list right away because of synchronization latency; in this case, trigger a manual synchronization as described below. For more information, see Access Alibaba Cloud assets.

  1. Access the Security Center console - Asset Center - Host Assets. At the top of the left side of the page, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  2. On the Host page, Server tab, click Synchronize Assets.

  3. Set the search condition to Cloud Service Provider and select Alibaba Cloud. The system automatically queries the Alibaba Cloud host assets in the current account.

Step 3: Install the agent

After assets are synchronized, install the agent on your server assets. The Security Center agent is a lightweight security component deployed on each server. Capabilities such as intrusion detection, vulnerability scanning, and baseline checks depend on the data that the agent collects. Only after the agent is installed and registered does it report data and accept detection instructions. For more information, see Install the agent.

  • Automatic installation: If you selected the Security Hardening option below the image version when you purchased the ECS instance, Security Center installs the agent automatically during instance creation. In this case, you only need to confirm that the agent is online.

  • Manual installation: If you did not select Security Hardening when you purchased the ECS instance, install the agent manually as described in the following steps.

Check the agent status

  1. Go to the Security Center console - Asset Center - Host Assets page. In the upper-left corner of the page, select the region of the assets that you want to protect: Chinese mainland or Outside Chinese mainland.

  2. On the Host Assets page, click the Server tab and check the Agent column of the target server to determine whether the Security Center agent is installed and running.

    Note

    The image icon indicates that the Security Center agent is installed and online.

    Agent Status

    Description

    Recommended action

    Online

    The agent is installed and running properly, and Security Center can protect the server

    No action required

    Offline

    The agent is installed but has lost its connection to Security Center, and the server is currently unprotected

    In the Actions column, choose More > Agent Diagnostics to troubleshoot; reinstall the agent if necessary

    Protection Suspended

    Agent protection is paused

    The agent status changes to Online after you resume protection

    Server Shutdown

    The server is shut down, so the agent cannot report its status

    Start the server and then check the agent status again

    Not Installed

    The Security Center agent is not installed on the server, so the server is not protected by Security Center

    Install the agent as described in the next step

Install the agent manually

If you did not select the Security Hardening option when you purchased the ECS instance, install the agent by using one of the following methods. For more installation methods and troubleshooting guidance, see Install the agent.

Install from the console

  1. Log on to the Security Center console.

  2. In the left-side navigation pane, choose System Configuration > Feature Settings. In the upper-left corner of the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.

  3. On the Agent > Agent Not Installed tab, find the server where you want to install the agent, and click Install Agent in the Actions column.

    Note

    You can also select multiple servers and click Install to install the agent in batches.

Use an installation command

  1. Log on to Security Center console.

  2. In the left-side navigation pane, choose System Configuration > Feature Settings. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  3. On the Agent > Installation Command tab, copy the installation command that corresponds to the operating system of the server.

  4. Log on to the server and run the installation command with administrator or root permissions.

Step 4: Configure the protection level

After ECS assets are onboarded, assign a protection level to them. Protection levels differ in the capabilities that they provide and in cost. For more information, see Configure protection levels for pay-as-you-go instances.

  • Default rules: After ECS instances are onboarded, Security Center automatically binds protection levels to certain assets according to the following rules:

    • ECS assets that run container environments are bound to Full Protection for Hosts and Containers. These include:

      • Nodes of Alibaba Cloud Container Service for Kubernetes (ACK) clusters.

      • Lingjun intelligent computing assets.

      • Servers in self-managed Kubernetes clusters that are already onboarded to Security Center.

    • All other ECS assets are bound to Comprehensive Host Protection.

  • Change the protection level manually:

    1. On the Overview page, in the Enable Pay-as-You-Go Service area, click Quota Management.

    2. In the Quota Management dialog box, go to the Bind Quota area, locate the ECS instance that you want to protect, select a protection version or protection level for it, and then submit the binding.

      Two binding scopes are available:

      • Bind all hosts (default): Every host under the current account is bound to the selected version, and hosts added later are bound automatically.

      • Bind specific hosts: Only the hosts that you select are bound to the specified version. Use this scope when different hosts require different protection versions.

Step 5: View and handle the security risks of ECS instances

Once a protection version is bound and the agent is online, Security Center continuously detects security risks on your ECS instances. Handle the findings promptly to eliminate potential threats.

View the security risks of ECS instances under the current account

Use either of the following methods to review the security risks of ECS instances under the current account.

  • Log on to the ECS console. On the Overview page, move the pointer over a pending task in the Security Protection section on the right, and then click Handle Now. You are redirected to the Host page of the Security Center console, where you can view and handle the detected risks. For more information, see Manage servers.

  • Log on to the Security Center console. On the Overview page, in the Security Score area, click Handle Now. The Security Score Details panel opens, where you can view and handle the detected risks. For more information, see Overview.

View the security details of an individual ECS instance

Use either of the following methods to view the security risk details of a single ECS instance.

  • Log on to the ECS console. On the Instances page, locate the target ECS instance and click the image.png icon in the Monitoring column to view the security status of the instance. If high-risk findings exist, follow the on-screen guidance to handle them promptly and avoid impact on your business.

    The color of the image.png icon varies with the security status. The color displayed in the console prevails.

  • Log on to the Security Center console and select the region of the assets that you want to protect: Chinese Mainland or Outside Chinese Mainland. Then, on the Asset Center > Host > Server tab, view the security details of the target ECS instance.

What to do next

After your ECS hosts are onboarded, refer to the following topics to apply comprehensive hardening, including host defense, vulnerability management, baseline checks, virus scanning, brute-force attack prevention, and alert notifications:

  • Configure host protection rules: Host rule management centralizes the detection and defense policies that Security Center applies to your hosts. It covers malicious behavior defense, common logon management, and brute-force protection, which together significantly reduce the risk of intrusion through brute-force attacks. For more information, see Malicious behavior defense, Defense against brute-force attacks, and Approved logon management.

  • Set alert modes and proactive defense: Enable capabilities such as malicious host behavior defense, anti-ransomware (decoy capture), and malicious network behavior defense to counter threats such as unauthorized intrusion, malware execution, ransomware attacks, and malicious outbound connections, giving your servers end-to-end protection. For more information about host protection settings, see Host protection settings.

  • Configure alert notifications: Configure notification methods in System Configuration > Notification Settings so that security risks reach the responsible personnel without delay.

  • Vulnerabilities: Use vulnerability management to detect server vulnerabilities, assess their severity, and remediate selected high-risk vulnerabilities, thereby shrinking the attack surface of your system. For more information, see Overview.

  • Baseline check: Run baseline checks against the operating system configurations of your ECS servers, covering areas such as MLPS compliance baselines, unauthorized access, security best practices, and weak passwords, to lower intrusion risk and satisfy security compliance requirements. For more information, see Configure and run baseline check policies.

  • Virus Detection and Removal: Virus scanning inspects critical system modules on your servers, such as processes, startup items, and sensitive directories, and removes the malicious threats that it finds. For more information about virus scanning, see Virus detection and removal.