Enhance anti-ransomware capabilities for instances

Updated at:

Ransomware is malware that encrypts your business data, causing service disruptions, data leakage, and data loss. These attacks pose significant risks to your business. This topic describes how to enhance the anti-ransomware capabilities of your instances.

Background

As technology evolves, new types of malware emerge, and ransomware has become a common threat. Alibaba Cloud uses its extensive experience in cloud security and cutting-edge security technologies to provide comprehensive security solutions. For more information about how to defend against ransomware, see Overview of the anti-ransomware service.

Symptoms

When your instance is attacked by ransomware, its system files are encrypted, and you will find a ransom note in the user's working directory. For example, on a Windows-based instance, a ransom note like the one below typically appears.

::: Greetings :::

Little FAQ:

.1.
Q: Whats Happen?
A: Your files have been encrypted. The file structure was not damaged, we did everything possible

.2.
Q: How to recover files?
A: If you wish to decrypt your files you will need to pay us.

.3.
Q: What about guarantees?
A: Its just a business. We absolutely do not care about you and your deals, except getting benefit
To check the ability of returning files, you can send to us any 2 files with SIMPLE extensions(jpg

.4.
Q: How to contact with you?
A: You can write us to our mailboxes: data***@cyberfear.com or back***@swismail.com

.5.
Q: How will the decryption process proceed after payment?
A: After payment we will send to you our scanner-decoder program and detailed instructions for use

.6.
Q: If I don't want to pay bad people like you?
A: If you will not cooperate with our service - for us, its does not matter. But you will lose you

:::BEWARE:::
DON`T try to change encrypted files by yourself!
If you will try to use any third party software for restoring your data or antivirus solutions - p
Note

After ransomware encrypts or locks system files, the instance may fail to start or you may be unable to connect to it remotely. This is often one of the first signs of an anomaly. If you are suddenly unable to connect to your instance, investigate a potential ransomware attack.

Solution overview

Although preventive measures can reduce the risk of infection, they cannot entirely eliminate it. For ransomware, data backup is your last line of defense. However, when you restore data from a backup or a snapshot, any data generated between the snapshot creation and the disk rollback is lost. Therefore, you must develop a data backup strategy suitable for your business to protect your critical data.

The following are common strategies to protect against ransomware.

You can implement these protection strategies in parallel and select the ones that best suit your business needs. For example, if your business has high requirements for business continuity, you can apply all three strategies. However, this may incur charges for backups or snapshots.

Strategy 1: Use Security Center for anti-ransomware

Workflow

image

Procedure

  1. Enable the anti-ransomware service and purchase anti-ransomware capacity.

    To use the anti-ransomware feature in Security Center, you must enable the service and purchase anti-ransomware capacity. For more information, see Enable and purchase the anti-ransomware service.

    Note

    You can purchase anti-ransomware services based on your business requirements.

  2. Create a protection policy.

    After you enable the service, follow these steps to create a protection policy.

    Create a protection policy

    Before creating a policy, verify that your server's operating system is supported. If the OS version is not supported, data cannot be backed up. See Operating systems and versions supported by anti-ransomware for servers.

    1. Log on to the Security Center console. In the top navigation bar, select the region of the asset: China or Outside China.

    2. In the left-side navigation pane, choose Protection Configuration > Host Protection > Anti-ransomware.

    3. On the Anti-ransomware for Servers tab, click Create Anti-ransomware Policy.

    4. In the Create Anti-ransomware Policy panel, configure the basic parameters.

      Elastic Compute Service (ECS) instances can span different regions in a single policy. Servers not deployed on Alibaba Cloud must all be in the same region. A server can belong to only one anti-ransomware policy.
      Parameter Description
      Policy name Name of the anti-ransomware policy
      Server type Type of server to protect
      Backup route Communication method for backup. Required only when Server type is Server Not Deployed on Alibaba Cloud. Internet: may incur bandwidth charges. Internal network: requires connectivity via virtual private clouds (VPCs), Express Connect circuits, or Cloud Enterprise Network (CEN) instances.
      Region The region where the server resides, or any region with an available anti-ransomware endpoint. Required only when Server type is Server Not Deployed on Alibaba Cloud. Make sure the server can reach the anti-ransomware endpoint in the selected region. See Anti-ransomware endpoints.
      Select asset Assets to protect. Select an asset, an asset group, or multiple assets across groups. In the Asset group section, select a group to include all assets in it, then clear assets that don't need protection in the Assets section. To find a specific asset, enter its name in the search box (fuzzy match is supported).
    5. Under Protection policies, select Recommended policy or Custom policy, then click OK.

    Recommended policy

    The recommended policy uses built-in defaults and cannot be modified:

    Setting Default value
    Directory to protect All directories
    Directory to exclude Default excluded directories
    Non-local mount path Excluded (Object Storage Service (OSS) objects and NAS file systems)
    File type to protect All file types
    First backup starts at Between 00:00 and 03:00
    Periodic backup interval One day
    Backup data retention period 7 days
    Maximum backup bandwidth 0 MB/s for Alibaba Cloud servers (no limit); 5 MB/s for servers not deployed on Alibaba Cloud

    Custom policy

    Configure the following parameters to match your requirements:

    Parameter Description
    Directory to protect Specific directory: back up only specified directories. Enter up to 20 directory paths (for example, C:\Program Files (x86)\ on Windows or /usr/bin/ on Linux). Backup jobs run in sequence per path, which limits peak resource usage. All directories: back up the entire server.
    Directory to exclude Directories to skip. Security Center pre-fills common exclusions; add or remove as needed.
    Non-local mount path Select whether to exclude non-local mount paths such as OSS or NAS mounts.
    File type to protect All file types: protect all files. Specific file types: protect only selected types (for example, Document, Picture). Multiple types can be selected.
    First backup starts at Time to start the first backup job. Schedule during off-peak hours to avoid impacting services during the initial full backup.
    Periodic backup interval Interval between backup jobs. Default: one day.
    Backup data retention period How long backup data is kept. Default: 7 days. Permanent: retained until Security Center expires, the policy is deleted, or the server is removed from the policy. Custom: 1 to 65,535 days. Set based on your recovery requirements — data outside the retention period is deleted automatically.
    Maximum backup bandwidth Maximum bandwidth for backup jobs, in MB/s (0 to unlimited). 0 MB/s means no limit for Alibaba Cloud servers. For servers not deployed on Alibaba Cloud, the default is 5 MB/s. Limit bandwidth if backup jobs affect service performance.
  3. (Optional) Restore data from a valid backup in Security Center.

    1. Create a snapshot of the system disk and data disks of the infected instance. For more information, see Create a manual snapshot.

    2. If your instance is attacked by ransomware, you can use a backup from Security Center to quickly restore your services. Follow these steps to restore your data.

      Create a restoration task

      1. Log on to Security Center console.

      2. In the left-side navigation pane, choose Protection Configuration > Host Protection > Anti-Ransomware. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

      3. On the Anti-ransomware for Servers tab, find the server for which you want to create a restore job in the policy list.

        Note

        Use the search box above the policy list to find the target server by policy name or server name.

      4. Click More actions to expand the drop-down list. Find the target server and click Restore in the Actions column.

      5. In the Create Restoration Task panel, configure the following parameters, and then click OK.

        Parameter

        Description

        Backup Version

        Select the backup version to restore. All recoverable files in the selected version are displayed in the file list. You can select files as needed.

        Files to Restore

        Select the files to restore.

        Destination Folder

        Enter the destination path on the target server. The folder must exist and have write permissions. Otherwise, the restore job fails.

        Target Server

        Select the server to restore data to. You can select any protected server in the same account, not limited to the originally attacked server.

      6. A Restoration task created. message appears. Log on to the target server and navigate to the destination folder to verify that the backup files are restored and accessible.

Strategy 2: Use automatic snapshots

Workflow

image

Procedure

Creating backups for an instance by using snapshots allows you to recover data after a ransomware attack. Note that this strategy provides only post-incident recovery capabilities and is not a substitute for proactive protection measures.

  1. Create an automatic snapshot policy for the instance. For more information, see Create an automatic snapshot policy.

  2. (Optional) Restore data from a valid snapshot that was created before the instance was infected.

    1. Create a snapshot of the system disk and data disks of the infected instance. For more information, see Create a manual snapshot.

      Important

      A disk rollback is irreversible. Data generated between the snapshot creation and the rollback is lost. To prevent data loss from accidental operations, we recommend that you create a snapshot to back up your data before you roll back a disk.

    2. For more information about how to reinitialize the system disk of an instance, see Re-initialize a system disk (reset the OS).

    3. To learn how to use a snapshot to restore data to a system disk or a data disk, see Roll back a disk by using a snapshot.

Strategy 3: Use security groups and firewalls

Workflow

image

Procedure

Security policies, such as those for security groups and firewalls, can enhance an instance's protection against ransomware. However, this requires you to have technical expertise in network security.

  1. For best practices for security group and firewall policies, see Best practices for ECS security groups (inbound rules) and Configuration guide for Windows Firewall policies.

  2. (Optional) Contact a third-party company to decrypt and restore data.

    1. Create a snapshot for the system disk and data disks of the instance that is infected with ransomware. For more information, see Create a manual snapshot.

    2. For more information about how to reinitialize the system disk of an instance, see Re-initialize a system disk (reset the OS).

    3. After you reinitialize the system disk of the compromised instance, if you have not backed up important data or created a snapshot, you can contact a third-party company to decrypt and restore the data.

      Warning

      The data decryption capabilities provided by third-party companies after a ransomware attack are independent of Alibaba Cloud. Alibaba Cloud is not responsible for the success of data recovery or any data corruption.

Related documents