Client configuration
Configure advanced features for the Security Center agent to improve security and resource usage efficiency. Enable Agent Protection to prevent malicious uninstallation and configure resource usage limits to control the CPU and memory consumption of operations such as local file detection. This topic describes the features supported by client configuration and how to configure the features.
Agent Protection
Feature overview
Agent Protection is a built-in protection mechanism that ensures the stable operation of the Security Center agent. It proactively intercepts unauthorized operations, such as uninstallation and process termination, to prevent the agent from being disabled by attackers or abnormal processes. This way, Security Center can provide continuous protection for your servers.
This feature protects only the agent itself and does not directly provide server security protection.
-
Core benefits
-
Prevent malicious uninstallation: Prevents attackers from removing the security agent after they compromise a server.
-
Ensure process stability: Protects the core processes of the agent from accidental or malicious termination.
-
Ensure protection continuity: Prevents security protection interruptions caused by agent failures.
-
-
Compatibility notes: This feature depends on specific operating systems and kernel versions. If the server environment is incompatible, the feature status is displayed as "Protection failed: incompatible kernel version" and the feature does not take effect.
Scope
-
Edition limits: This feature is available to both free and paid users of Security Center.
-
Operating system and kernel version limits: For more information, see Appendix: Operating systems and kernel versions supported by Agent Protection.
Enable Agent Protection for servers
After the defense mode of Agent Protection is enabled, Agent Protection is automatically enabled for servers on which the agent is installed and that are within the protection scope of Agent Protection.
-
Log on to Security Center console.
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
-
Select the tab. In the Agent Protection section, turn on the Defense Mode switch.
-
To the right of Protection Scope:, click Manage.
-
In the Agent Protection panel, select the servers for which you want to enable Agent Protection, and then click OK.
NoteAfter Self-Protection Status is enabled for a server, the self-protection mechanism immediately takes effect. After Agent Protection is disabled for a server, the self-protection mechanism is disabled 5 minutes later.
View the status of Agent Protection
You can use the following method to check whether Agent Protection is enabled for a server.
-
Log on to Security Center console.
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
-
Find the target server in the server list, and click the server name or click Actions in the View column.
-
On the server details page, click the tab. In the Defense Status section, view the status of Self-Protection Status.
Uninstallation notes
After Agent Protection is enabled, the uninstallation of the agent is restricted. You can uninstall the agent only in the following authorized ways:
-
Uninstall from the console: Uninstall the agent directly in the Security Center console.
-
Uninstall on the server: Disable Agent Protection for the server in the console, and then uninstall the agent on the server.
Local File Detection Engine
Feature overview
-
The local file detection engine is a local file threat detection engine developed in-house by Alibaba Cloud Security Center. This engine reduces the performance overhead caused by data uploads and cloud-based scan data exchange, and provides high detection efficiency.
-
After you enable this feature, files are scanned in dual-engine mode that combines local and cloud-based scanning. The system scans files by using the local engine first. If no threats are detected, the files are uploaded to the cloud for secondary confirmation to ensure comprehensive detection.
Scope
Subscription: Enterprise or Ultimate (If your current edition does not support this feature, upgrade).
NoteThe protection edition of the server must be set to the edition you purchased. For more information, see Bind a server protection edition.
Pay-as-you-go: Host and Container Security pay-as-you-go is activated (If not activated, purchase).
NoteThe server protection level must be set to Comprehensive Host Protection or Host and Container Security. For more information, see Bind a server protection level.
Enable local file detection
-
Log on to Security Center console.
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
-
Select the tab. In the Local File Detection Engine section, turn on the File Test switch.
-
To the right of Installation Scope, click Manage.
-
In the Local File Detection Engine panel, select the servers for which you want to enable local file detection, and then click OK.
In-depth Detection Engine
The in-depth detection engine helps you identify more in-depth security risks, such as rootkits, tunneling communication, and backdoors.
Scope
Subscription: Enterprise or Ultimate (If your current edition does not support this feature, upgrade).
NoteThe protection edition of the server must be set to the edition you purchased. For more information, see Bind a server protection edition.
Pay-as-you-go: Host and Container Security pay-as-you-go is activated (If not activated, purchase).
NoteThe server protection level must be set to Comprehensive Host Protection or Host and Container Security. For more information, see Bind a server protection level.
Enable in-depth detection
-
Log on to Security Center console.
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
-
Select the tab. In the In-depth Detection Engine section, turn on the Depth Test switch.
-
To the right of Installation Scope, click Manage.
-
In the In-depth Detection Engine panel, select the servers for which you want to enable in-depth detection, and then click OK.
Client Resource Management
The Security Center agent consumes a small amount of server resources when it runs on servers. Security Center provides three resource management modes. You can adjust the resource management mode of the agent to manage the resource consumption of the agent on servers. If you select an appropriate protection mode for your servers, you can achieve better security protection.
Resource management modes
If you select a resource management mode and the resources consumed by the agent exceed the configured maximum memory or CPU usage, the agent stops working until the CPU usage or memory usage decreases to an acceptable level. Then, the agent automatically restarts.
|
Protection mode |
Maximum memory or CPU usage |
Supported editions |
Scenarios |
|
Low Consumption Mode |
|
All editions |
Low Consumption mode is suitable for business scenarios that have low security requirements. In this mode, the agent automatically downgrades the features that consume a large amount of resources. In this case, threat detection may be delayed. We recommend that you enable Smooth mode. Note
Low Consumption mode is enabled by default for newly connected servers. |
|
Smooth Mode |
|
Anti-Virus, Advanced, Enterprise, and Ultimate editions |
Smooth mode is suitable for the security protection of critical business. In this mode, the agent consumes more resources to collect data and ensures more timely risk detection. |
|
Custom Mode |
|
Enterprise and Ultimate editions |
Custom mode is suitable for the security protection of major events. In this mode, you can flexibly control the memory and CPU usage of the agent. Important
If the resource limit threshold of the agent is too low, some detection capabilities may become ineffective. Configure the threshold with caution. |
Configure a protection mode
-
Log on to Security Center console.
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
-
Select the tab. In the Client Resource Management section, find Smooth Mode or Custom Mode, and click Manage on the right side.
-
In the Smooth Mode or Custom Mode panel, select the servers for which you want to adjust the resource management mode of the agent, and then click OK.
Each server can use only one of the following resource management modes: Smooth Mode and Custom Mode. For example, if a server currently uses Smooth Mode and you configure Custom Mode for the server, the protection mode of the server changes to Custom Mode.
NoteIn Custom Mode mode, more types of alerts are detected and the detection engine is more sensitive. More alerts are generated and the false positive rate may increase. We recommend that you monitor and handle alerts in a timely manner.
-
(Optional) If Custom mode is configured for a server, you can change the memory usage threshold and CPU usage threshold of the server.
A higher memory usage or CPU usage threshold provides more accurate protection. We recommend that you set appropriate thresholds.
Appendix: Operating systems and kernel versions supported by Agent Protection
|
Operating system |
Supported operating system versions |
Supported kernel versions |
|
Windows (64-bit) |
|
All versions |
|
CentOS (64-bit) |
|
|
|
Ubuntu (64-bit) |
|
|
|
Alibaba Cloud Linux (Alinux) (64-bit) |
Alinux 2.1903 |
|
|
Anolis (64-bit) |
All versions |
|
|
RHEL |
RHEL 6, 7, and 8 |
|