To avoid the risk of contaminating your production environment by restoring virus-infected data, Cloud Backup provides the Backup Point Virus Detection feature. This topic describes the Backup Point Virus Detection feature of Cloud Backup, including an introduction, its supported scope and limitations, how it works, procedures, billing, and important notes.
Feature overview
Cloud Backup periodically backs up data from your production environment. If data in your production environment is infected with a virus, the corresponding data in the backup vault will also carry the virus. When you need to restore data from a backup vault to your production environment, restoring an infected file can re-infect the environment. This can severely impact disaster recovery and lead to greater business losses. Cloud Backup provides the Backup Point Virus Detection feature to help you select clean and secure backup points for data restoration. This feature allows you to perform:
Automatic detection based on a backup policy: When you configure a backup policy, you can enable the Backup Point Virus Detection feature. Cloud Backup will then automatically scan your backup data for viruses after each scheduled backup. This allows you to understand the risk status of files in each backup point and efficiently select secure files for restoration when needed.
On-demand manual detection: Based on your specific business needs, you can select a specific backup point in Backup History to perform virus detection, create a Backup Point Virus Detection task on the virus detection page, or use the Virus Detection During Restoration feature.
If Cloud Backup detects virus files in a backup point, it will mark the backup point as a risk. When you browse a backup point, you can see the specific risk status of the files within it.
Scope and limitations
The data sources supported by the Backup Point Virus Detection feature include ECS file backup (new version), local file backup (new version), OSS backup, Alibaba Cloud NAS backup, and on-premises NAS backup.
The Backup Point Virus Detection feature can scan only individual backup files that are no larger than 100 MB. If a single backup file exceeds 100 MB, it is skipped during the scan. You can download a list of unscannable files to view their details.
Supported regions: For more information, see Features available by region.
Supported virus types
The Backup Point Virus Detection feature of Cloud Backup supports the detection of the following virus types.
Virus type | Virus name |
Backdoor | reverse shell |
DDoS | DDoS trojan |
Downloader | downloader trojan |
Engtest | engine test program |
Hacktool | hacking tool |
Trojan | high-risk program |
Malbaseware | tainted basic software |
MalScript | malicious script |
Malware | malware |
Miner | mining program |
Proxytool | proxy tool |
ransomware | ransomware |
riskware | riskware |
Rootkit | rootkit |
Stealer | stealer |
Scanner | scanner |
Suspicious | suspicious program |
Virus | file-infecting virus |
web shell | web shell |
Worm | worm |
adware | adware |
Patcher | patcher |
Gametool | private server tool |
Usage notes
Backup Point Virus Detection is not supported for backup points in the Backup Point Virus Detection of a backup vault.
In backup replication scenarios, policy-based automatic detection is not supported for backup points in a destination backup vault, but on-demand manual detection is supported. If a virus scan was performed on the files in a backup point at the source, the scan results are displayed for the same backup point and files at the destination. You do not need to perform the scan again. For more information about on-demand virus scans, see On-demand manual detection.
After you enable Backup Point Virus Detection in a Backup Point Virus Detection, Cloud Backup performs a Backup Point Virus Detection on the first backup point. For subsequent backup points, it performs an Backup Point Virus Detection.
A Backup Point Virus Detection task cannot be canceled after it starts.
How it works
The virus detection feature seamlessly integrates with the backup service. You do not need to deploy any services or clients to scan your backup data.
Policy-based automatic detection
After you enable the Backup Point Virus Detection feature in a Backup Point Virus Detection, the backup service automatically scans the backup point for viruses after each scheduled backup completes. The scan duration depends on the number of files to be scanned.
Virus detection follows this logic:
Initial scan: A full virus scan is performed on the first backup point in the backup chain.
Subsequent scans: The service performs an incremental virus scan only on files that are new or have changed since the previous backup point.
Example:
For backup point 1, 10,000 files are scanned (full scan).
For backup point 2, only the 2,000 new files and 1,000 changed files relative to backup point 1 are scanned (a total of 3,000 incremental files).
For backup point 3, only the 2,000 changed files relative to backup point 2 are scanned (incremental scan).
On-demand manual detection
You can perform on-demand manual detection in the following ways:
In Backup History, select a backup point for a manual virus scan.
In Backup History, select a backup point to create a restore job and enable the Virus Detection During Restoration feature.
On the Restore Jobs page, select a backup point from a backup vault or a destination backup vault to create a restore job, and enable the Virus Detection During Restoration feature.
On the Virus Detection page, select a backup point from a backup vault or a destination backup vault for a manual virus scan.
On the Virus Detection page, if a backup point in a backup vault or a destination backup vault is infected, you can use the Find Secure Version for Restoration feature to scan other backup points and select a secure version for restoration.
Characteristics of on-demand manual detection:
Each backup point is scanned independently and does not inherit the detection results from other backup points in the same backup chain. This may result in the same files in different backup points being scanned multiple times.
If you perform multiple on-demand manual scans on the same backup point, the same file is scanned only once, and the results of multiple scans are automatically merged.
Example:
For backup point 1:
The /A directory contains 10,000 files, and the /A/B directory within it contains 4,000 files.
The first scan targets only the /A/B directory, scanning 4,000 files.
When scanning the /A directory for the second time, the already scanned /A/B directory is automatically skipped, and only the remaining 10,000 - 4,000 = 6,000 files are scanned.
For backup point 2: If you perform an on-demand virus scan on all files, all 12,000 files (9,000 unchanged + 1,000 changed + 2,000 added) will be scanned.
For backup point 3: If you perform an on-demand virus scan on all files, all 3,000 files (1,000 unchanged + 2,000 changed) will be scanned.
Procedures
This section uses ECS file backup as an example to describe how to access the Backup Point Virus Detection feature.
Policy-based automatic detection
On-demand manual detection
Backup point virus detection status
If the Cloud Backup service finds a virus file in a backup point during a virus scan, the backup point is marked as risky. When you browse the backup point, you can view information about the specific risky files.
In the Backup History area on the Backup Plan tab, you can view the status of each backup point on the timeline. A green dot indicates Completed, and an orange dot indicates Partially Completed (which may indicate a backup point containing high-risk files).
At the top of the backup browsing page, a red warning message is displayed, indicating when the risk was discovered and the most recent detection time. In the file list, high-risk files are marked with a red icon for easy identification.
If you attempt to restore from a backup point that contains infected files, you can choose one of the following options:
Do not restore the virus-infected files (You can find secure versions on the Virus Detection tab.)
I am aware of the risks and still want to restore all the selected items
We recommend that you go to the Virus Detection page to view the high-risk files and find a secure version for restoration. For more information, see Find Secure Version for Restoration.
Detection results
Virus detection statistics are aggregated for each backup type and cannot be viewed per source. The display location differs between the new and old versions of the UI. Refer to the description for the version you are using.
New version
The following summary cards are displayed at the top of the ECS file backup home page:
Total Number of Backup Points Detected: The total number of backup points that have been scanned.
Total Detected Files: The cumulative number of times files have been scanned. This value is used for billing.
High Risk: The total number of high-risk files or objects detected over time.
Medium Risk: The total number of medium-risk files or objects detected over time.
Low Risk: The total number of low-risk files or objects detected over time.
Secure: The total number of secure files or objects detected over time.
The high-risk file details list includes the File Name, MD5, Threat Tag, Risk Level, Detection Time, and Actions columns. Threat tags include types such as web shell, malicious script, proxy tool, mining program, and suspicious program. In the Actions column, you can click Find Secure Version for Restoration to restore a high-risk file.
Additionally, for each backup point, you can view both its historical detection result statistics and the details of specific high-risk files.
Number of Files Detected: The total number of files or objects that have been scanned for this backup point.
Total Number of Files: The total number of files or objects scheduled for detection for this backup point.
Detection Result: A statistical breakdown of the scanned files, which includes:
High Risk: The total number of high-risk files or objects detected for this backup point.
Medium Risk: The total number of medium-risk files or objects detected for this backup point.
Low Risk: The total number of low-risk files or objects detected for this backup point.
Secure: The total number of secure files or objects detected for this backup point.
Number of unscannable files: The number of files that could not be scanned due to reasons such as file size limits. This represents the total number of unscannable files or objects for this backup point.
Old version
On the Virus Detection tab, the following statistics are displayed:
Total Number of Backup Points Detected: The total number of backup points that have been scanned.
Total Detected Files: The cumulative number of times files have been scanned. This value is used for billing.
High Risk: The total number of high-risk files or objects detected over time.
Medium Risk: The total number of medium-risk files or objects detected over time.
Low Risk: The total number of low-risk files or objects detected over time.
Secure: The total number of secure files or objects detected over time.
Additionally, for each backup point, you can view both its historical detection statistics and the details of specific high-risk files. The high-risk file details list includes the File Name, MD5, Threat Tag, Risk Level, Detection Time, and Actions columns. Threat tags include types such as web shell, malicious script, proxy tool, mining program, and suspicious program. In the Actions column, you can click Find Secure Version for Restoration to restore a high-risk file.
Number of Files Detected: The total number of files or objects that have been scanned for this backup point.
Total Number of Files: The total number of files or objects scheduled for detection for this backup point.
Detection Result: A statistical breakdown of the scanned files, which includes:
High Risk: The total number of high-risk files or objects detected for this backup point.
Medium Risk: The total number of medium-risk files or objects detected for this backup point.
Low Risk: The total number of low-risk files or objects detected for this backup point.
Secure: The total number of secure files or objects detected for this backup point.
Number of unscannable files: The number of files that could not be scanned due to reasons such as file size limits. This represents the total number of unscannable files or objects for this backup point.
Related operations
On the Virus Detection page, you can click ⋮ in the Actions column to perform the following operations.
Actions | Description |
Download List of Virus Files | You can export the list of detected virus files to a local file for review. The exported file contains information such as the virus file path, MD5 hash, risk level, and virus name. |
Download List of Files That Cannot Be Detected | If a single backup file is larger than 100 MB, it is skipped during the scan. You can download the list of unscannable files to view specific backup file information. |
Forcibly Restore Current Version | Forcibly restoring high-risk files may compromise the restore destination. Proceed with caution. |
Billing
Virus detection is a paid feature. Billing is based on the Total Detected Files. For both policy-based Total Detected Files and Total Detected Files, you are charged based on the number of successfully scanned files. Files that are not scanned successfully are not charged.
Automatic detection based on a backup policy performs an incremental virus scan only on new or changed files. On-demand manual detection, however, scans each backup point independently, and these scans do not affect each other. Total Detected Files is the cumulative total of files scanned by both automatic and manual detection. For a detailed description of the billing rules, see the How it works section. For more pricing information, see .