Configure protection editions or levels

更新时间:
复制 MD 格式

Host and container security quotas for Security Center refer to the number of servers and compute cores purchased in a subscription instance, or the number of servers bound to a paid protection level in a pay-as-you-go instance. After you bind a protection edition or level to a server, the server can use the corresponding security protection capabilities. Host quotas of the Security Center Enterprise edition do not distinguish between the Chinese mainland and regions outside the Chinese mainland, and billing is uniformly calculated based on the number of owned servers. Enterprise edition quotas activated in the Chinese mainland can be bound to servers in regions outside the Chinese mainland. This topic describes how to manage protection editions for subscription instances and protection levels for pay-as-you-go instances.

Subscription billing model

Prerequisites

Protection edition overview

To meet host and container security protection requirements in different scenarios, Security Center provides the Anti-virus, Advanced, Enterprise, and Ultimate editions. For more information about the capabilities and billing rules of each edition, see Features and Billing description.

Edition

Description

Cost

Basic

Only basic security detection capabilities (such as detecting abnormal server logins, DDoS, mainstream server vulnerabilities, and configuration security issues for some cloud products), with no active protection features.

Free

Anti-virus

Provides detection and removal capabilities for common host viruses.

CNY 5 per core per month

Advanced Edition

Provides host virus detection, virus removal, vulnerability detection and remediation, and security reports.

CNY 60 per instance per month

Enterprise

Meets MLPS compliance and host security requirements for intrusion prevention, identity authentication, and security auditing.

CNY 150 per instance per month

Ultimate

Provides full-stack security protection covering hosts, containers, and Intelligent Computing Lingjun servers, including Kubernetes (K8s) threat detection, container asset overview, security alerts, virus removal, vulnerability detection, asset fingerprinting, and attack chain analysis.

CNY 150 per instance per month + CNY 5 per core per month

Edition limits

A subscription instance supports only one edition. After purchase, the same edition must be bound to all servers.

Default binding rules

  • Automatic binding: When you purchase a Security Center paid edition (Anti-virus, Advanced, Enterprise, or Ultimate) subscription, if you do not perform custom on-demand binding, the system automatically and randomly binds the edition to available servers to avoid idle resources. You can remove these bindings in batches at any time.

  • LINGJUN, ACK, and connected self-managed cluster assets:

    • If your Security Center edition is the Ultimate Edition, the Ultimate Edition is bound by default and cannot be changed.

    • If your Security Center edition is Anti-virus, Advanced, or Enterprise, the Free Edition is bound by default and cannot be changed.

  • Security Center trial edition: The trial edition provides full protection and binds the current trial edition to all servers by default. This setting cannot be modified.

Container asset binding limits

Security Center identifies container assets by detecting whether a container runtime environment (such as Docker or Containerd) is installed on a server or whether container processes are running. Assets that run container workloads support only Ultimate Edition binding. The following asset types are applicable:

  • Intelligent Computing LINGJUN assets.

    Note

    On theAsset Center > Host page, on the Server tab, set the Server Type filter to LINGJUN GPU-accelerated Bare Metal Instance to view the list of LINGJUN assets under your account.

  • Container Service for Kubernetes (ACK) assets.

  • Self-managed Kubernetes cluster assets connected to Security Center.

Important

If a container asset is not within the preceding scope but is connected to Security Center and bound to the Enterprise Edition, the asset can use only the security capabilities provided by the Enterprise Edition. Container runtime security detection and protection are not supported.

Edition change limits

  • You can bind a purchased edition to a Free Edition server only when the remaining quota is greater than 0.

  • You can change the edition to the Free Edition only after the edition has been bound for 30 days and one of the following conditions is met.

    Note

    Authorizations automatically bound by using Default binding rules are not subject to the time limit when changed to the Free Edition for the first time.

    • Servers manually bound to a paid edition.

    • Paid editions bound by using the new host automatic binding method.

  • After authorization, you cannot bind another server within 30 days. The authorization is automatically unbound and reclaimed when the ECS instance is released.

  • Limits on changing the edition of assets that run container workloads:

    1. If the server does not require container protection, uninstall the container runtime components on the server or stop all container processes.

    2. Then wait for the asset information to be automatically synchronized (up to 24 hours), or manually synchronize assets in Asset Center.

    3. After the asset is no longer identified as a container environment, you can bind it to other edition authorizations such as the Enterprise Edition or Advanced Edition.

Automatic quota revocation

The corresponding quota is automatically reclaimed in the following scenarios:

  • An ECS instance is released.

  • A third-party server is unbound in the Security Center console.

  • An off-cloud host is automatically removed by a scheduled cleanup rule.

If you manually uninstall the Security Center client from a server, the asset status is displayed as Client Offline on the Host page in the Security Center console. In this case, Security Center does not automatically reclaim the corresponding quota.

Quota management entry

  • On the Overview page of the Security Center console, if a Manage entry exists on the right side of Protected Servers in the Subscription section, your Alibaba Cloud account has switched to on-demand protection mode and you can manage quotas.

  • If no quota management entry exists in the Security Center console, your account is in full protection mode.

Manage protection editions for servers

Servers connected to Security Center (which can be viewed on the Host page) support binding protection editions to enable security protection.

  1. Log on to Security Center console.

  2. In the left-side navigation pane, click Overview.

  3. In the Subscription section, click Protected Servers on the right side of Quota Management.

    Alternatively, on the Asset CenterHost page, click Manage in the Remaining Quota section.

  4. In the Quota Management dialog box, select the region where the server is located, select an edition for the server, click View Change Details, confirm that the edition is correct, and then click OK.

  5. (Optional) If you want new servers to be automatically bound to a protection edition, select Automatically Add New Servers to Security Center.

    Important

    After you select Automatically Add New Servers to Security Center, if the assets are LINGJUN, ACK, or connected self-managed cluster assets, new assets of these types are automatically bound to the Ultimate Edition when the purchased edition is the Ultimate Edition. When the purchased edition is not the Ultimate Edition, new assets of these types are automatically bound to the Free Edition.

Pay-as-you-go billing model

Prerequisites

Protection levels

Pay-as-you-go instances support binding the following protection levels to servers: Unprotected, Virus Protection, Comprehensive Host Protection, and Comprehensive Host and Container Protection. For more information about the capabilities and billing rules of each level, see Features and Billing description.

Protection level

Description

Monthly cost (30-day estimate)

Unprotected

Basic security detection capabilities only (e.g., anomalous login detection, DDoS, common server vulnerabilities, and security posture issues for select cloud services). No active protection features.

Free

Antivirus

Detects and removes common viruses on hosts.

CNY 7.5/core/month

Advanced

No longer available for new purchases or modifications.

CNY 90/server/month

Comprehensive Host Protection

Meets classified protection compliance requirements (Dengbao) and addresses host intrusion prevention, identity authentication, and security auditing requirements.

CNY 225/server/month

Hosts and Container Protection

Provides full-stack security protection for hosts, containers, and intelligent computing servers, including Kubernetes (K8s) threat detection, K8s, container asset visibility, security alerts, virus detection, vulnerability detection, asset fingerprinting, and attack chain analysis.

CNY 225/server/month + CNY 7.5/core/month

Billing rules

Security Center calculates fees based on the following factors:

  • The protection level bound.

  • The number of servers bound to the protection level.

  • The actual protection duration.

The actual protection duration is calculated only when the Security Center client is online. Fees are accumulated by the second and settled by calendar day. For more information, see Billing description.

Default binding rules

  • After you enable pay-as-you-go for Security Center host and container security, you can bind any protection level to a server at any time.

  • If you do not perform Custom Quota Binding when enabling pay-as-you-go for host and container security, Security Center automatically binds the default protection level to all servers under your Alibaba Cloud account:

    • Server assets that run container environments: Full Protection for Hosts and Containers.

      • ACK cluster nodes.

      • Intelligent Computing LINGJUN assets.

      • Servers in self-managed Kubernetes clusters connected to Security Center.

    • Other server assets: Comprehensive Host Protection.

Container asset protection limits

To ensure that risks of container assets connected to Security Center can be fully monitored, assets that run container workloads support only Full Protection for Hosts and Containers. Other protection levels cannot be bound.

This limit applies to the following container assets:

  • ACK assets.

  • Intelligent Computing LINGJUN assets.

    Note

    On the Asset Center > Host page, on the Server tab, set the Server Type filter to LINGJUN GPU-accelerated Bare Metal Instance to view the list of LINGJUN assets under your account.

  • Self-managed Kubernetes cluster assets connected to Security Center.

Important

If a container asset is not within the preceding scope but is connected to Security Center and bound to a protection level, the asset can use only the security capabilities provided by Comprehensive Host Protection. Container runtime security detection and protection are not supported.

Manage protection levels for servers

Servers connected to Security Center (which can be viewed on the Host page) support binding protection levels to enable security protection.

  1. Log on to Security Center console.

  2. In the left-side navigation pane, click Overview.

  3. In the Enable Pay-as-You-Go Service section, click Host and Container Security next to Quota Management. Alternatively, on the Asset CenterHost page, click Quota Management.

  4. In the Quota Management dialog box, select the region where the server is located, select a protection level for the server, and click OK.

    1. The optional protection levels include Unprotected, Virus Protection, Comprehensive Host Protection, and Full Protection for Hosts and Containers.

    2. In the Automatically Add New Servers to Security Center section, you can set the default protection level for new hosts.

  5. In the Automatically Add New Servers to Security Center section, select the protection level to automatically bind to new servers.

    Important

    For LINGJUN, ACK, and connected self-managed cluster assets, the Full Protection for Hosts and Containers level is bound only when the protection level selected in the Automatically Add New Servers to Security Center section is Full Protection for Hosts and Containers. Otherwise, the Unprotected level is bound to the assets.

  6. Click View Change Details, confirm that the changed protection level is correct, and then click OK.

View server protection editions

  1. Log on to Security Center console.

  2. In the left-side navigation pane, choose Asset Center > Host. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  3. On the Host page, Server tab, view the edition displayed in the Attach Status or Protection Level column of the target server.

    1. Subscription instances:

      • Anti-virus, Advanced, Enterprise, or Ultimate Edition: The server is bound to a paid protection edition and benefits from the security capabilities of the corresponding edition.

      • Free Edition: The server is not bound to a paid protection edition and uses only the security detection capabilities provided by the Free Edition. The server is in an unprotected state. For more information, see Enable Security Center Basic.

    2. Pay-as-you-go instances:

      • Virus Protection, Comprehensive Host Protection, Comprehensive Host and Container Protection, or Advanced Edition: The server is bound to a paid protection level and benefits from the security capabilities of the corresponding level.

      • Unprotected: The server is not bound to a paid protection level and uses only the free detection capabilities provided by Security Center. The server is in an unprotected state. For more information, see Enable Security Center Basic.

What to do next

After binding a protection edition, you can configure host and container protection. For more information, see Host protection settings.

FAQ

  • Why can my server only be bound to the Ultimate Edition license?

    Security Center identifies a server as a container asset when it detects a container runtime environment (such as Docker or Containerd) installed on the server, or running container processes. Container asset protection features (such as container runtime threat detection and image scanning) are supported only by the Ultimate Edition. Therefore, the server can be bound only to the Ultimate Edition license.

    If the server does not require container protection:

    1. Uninstall the container runtime components from the server, or stop all container processes.

    2. Wait for the asset information to be automatically synchronized (up to 24 hours), or manually synchronize assets in Asset Center.

    3. After the asset is no longer identified as a container environment, you can bind it to other edition licenses such as the Enterprise Edition or Advanced Edition.

  • Why do I not see the quota management entry?

    If no quota management entry exists in the Security Center console, your account is in full protection mode.

References

  • If the number of purchased authorizations is too small or too large, you can adjust the number by upgrading or downgrading your Security Center instance. For more information, see Upgrades and downgrades.

  • If you want to adjust the number of authorizations in the next purchase cycle, you can change specifications during renewal. For more information, see Renew the subscription.

  • For more information about how to view pay-as-you-go bills, see Bill details.