Manage servers

更新时间:
复制 MD 格式

When managing servers across multiple cloud environments, maintaining visibility into security posture can be challenging. Security Center provides centralized server management to help you view asset information, organize servers into groups, adjust protection states, and avoid security blind spots caused by scattered assets.

Demo video

The following video demonstrates key considerations for managing server assets in Security Center.

Synchronize assets

Security Center automatically synchronizes status changes for connected servers every minute, including agent online status and asset information. If you just finished installing the Security Center agent, new servers may not appear in the asset list immediately due to synchronization delay. Perform a manual sync to get the latest assets right away.

Note
  • Use manual sync only when you need to view new assets urgently after installing the agent. For non-urgent scenarios, wait for automatic sync.

  • Synchronizing the latest asset information takes about 1 minute.

  1. Log on to the Security Center console.

  2. In the navigation pane on the left, choose Assets > Host. In the upper-left corner of the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.

  3. On the Server tab of the Host page., and click Synchronize Assets.

  4. Security Center pulls the latest server asset information and refreshes the server list.

Add multi-cloud assets

Security Center supports protection for non-Alibaba Cloud servers, including third-party cloud servers and data center servers. Before you can protect these servers, connect them to Security Center. The following table describes the supported server types and connection procedures.

Third-party clouds (such as Tencent Cloud and AWS)

  1. Log on to the Security Center console.

  2. In the navigation pane on the left, choose Assets > Host. In the upper-left corner of the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.

  3. In the Add Multi-cloud Asset section, move the pointer over the cloud provider icon and click Add.

  4. In the Add Assets Outside Cloud panel, complete the required configurations. For more information, see Integrate third-party cloud assets.

Data centers (IDC)

  1. Log on to the Security Center console.

  2. In the navigation pane on the left, choose Assets > Host. In the upper-left corner of the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.

  3. In the Add Multi-cloud Asset section, move the pointer over the IDC access icon icon and click Add.

  4. In the Add Assets Outside Cloud panel, complete the required configurations. For more information, see Add data center assets.

Off-premises servers

  1. Log on to the Security Center console.

  2. In the navigation pane on the left, choose Assets > Host. In the upper-left corner of the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.

  3. In the Add Multi-cloud Asset section, move the pointer over the Off-premises server icon icon and click Install Agent.

  4. On the Feature Settings page, install the Security Center agent. For more information, see Install the agent.

View server information

  1. Log on to the Security Center console.

  2. In the navigation pane on the left, choose Assets > Host. In the upper-left corner of the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.

  3. On the Assets tab, view server information.

    View a single server

    Use the search component above the server list to locate a specific server by its Instance Name, Public IP Address, or Private IP Address.

    Check the Risk Status column to determine whether the server has security risks.

    Click View in the Actions column to go to the server details page.

    Tab

    Description

    Basic Information

    • Basic information

      Displays basic server information such as ID, region, group, and operating system. Supports changing the server group and performing one-click diagnostics on agent abnormal status.

      Note

      If basic information such as MAC address or kernel version is missing, return to the asset list, select the server, and choose More Operations > Asset Collection to collect the basic information.

    • Defense status

      Displays the enabled status of client self-protection, malicious network behavior defense, webshell defense, and malicious host behavior defense.

    • Vulnerability detection

      Displays vulnerability detection types and supports enabling or disabling different types of vulnerability detection for the server.

    • Brute-force attack prevention

      Displays the brute-force attack defense rules applied to the server and supports modifying these rules.

    • Logon security settings

      Displays the frequently used logon addresses, IP addresses, times, and accounts for the server. Supports configuring related alerts.

    Vulnerability Details

    Displays the vulnerability detection results for the server.

    Alert

    Displays the security alert information for the server.

    Asset Fingerprints

    Displays detailed server fingerprint information. This tab is available only when Security Center meets the following conditions.

    • Subscription: Enterprise or Ultimate (If your current edition does not support this feature, upgrade).

      Note

      The protection edition of the server must be set to the edition you purchased. For more information, see Bind a server protection edition.

    • Pay-as-you-go: Host and Container Security pay-as-you-go is activated (If not activated, purchase).

      Note

      The server protection level must be set to Host Protection or Host and Container Security. For more information, see Bind a server protection level.

    Agentless Detection

    Displays the vulnerabilities, baseline configurations, and security alerts detected by the agentless detection feature.

    Cloud Security Posture Management

    • Cloud Service Configuration Risk: Displays the cloud product configuration risk check details for the server.

    • System Baseline Risks: Displays the baseline risk check results for the server.

      Note

      This tab is available only for Security Center instances with the baseline risk check feature enabled. For more information, see Authorize and enable features.

    O&M and Monitoring

    • Remote O&M

      Displays the command list, command execution results, and file delivery results for remote O&M through Cloud Assistant.

    • Performance monitoring

      Displays CPU utilization, memory utilization, system load, network inbound and outbound rates, and TCP connection count.

    Filter by category

    The Server tab provides server categories such as At Risk, Unprotected, and Exposed for organized management.

    Category

    Description

    All Servers

    Displays all servers protected by Security Center, including all Alibaba Cloud servers and non-Alibaba Cloud servers with the Security Center agent installed.

    At Risk

    Displays servers with security risks such as vulnerabilities, Cloud Security Posture Management (CSPM) risks, or security alerts.

    Unprotected

    Displays servers whose agent status is Offline or Paused, or whose power status is Yes or Unknown.

    Important

    Security Center cannot provide security protection for servers whose agent status is Offline or Paused, or whose power status is Yes or Unknown. To enable protection, see Enable server protection.

    Unauthorized

    Displays servers whose authorized version is Basic (subscription) or whose protection level is Unprotected (pay-as-you-go for host and container security).

    Stopped

    Displays stopped servers.

    Exposed

    Displays servers exposed to the Internet (servers that can communicate over the Internet). For details, see Asset exposure analysis.

    Note

    This feature (asset exposure analysis) is available only when the protection version or level of the server meets specific requirements.

    • Subscription: Enterprise or Ultimate (If your current edition does not support this feature, upgrade).

      Note

      The protection edition of the server must be set to the edition you purchased. For more information, see Bind a server protection edition.

    • Pay-as-you-go: Host and Container Security pay-as-you-go is activated (If not activated, purchase).

      Note

      The server protection level must be set to Host Protection or Host and Container Security. For more information, see Bind a server protection level.

    If the requirements are not met, Security Center cannot provide the count of exposed servers. Exposed displays Unknown.

    Add

    Displays Alibaba Cloud ECS servers purchased within the last 15 days.

    Server Group

    Displays servers in each server group. Click a group name to view the security status of servers in that group.

    Note

    Security Center supports managing and deleting server groups. For more information, see Manage server groups.

    Server Region

    Displays servers in each region. Click a region name to view the security status of servers in that region.

    VPC

    Displays servers in each VPC. Click a VPC name to view the security status of servers in that VPC.

    Importance

    Displays servers under each asset importance level. In the Importance section, click Important, Normal, or Test to view the security status of servers at that level.

    Note

    Security Center supports classifying assets into three importance levels based on actual business needs, allowing batch management by importance.

    Tag

    Displays servers under each asset tag. Click an added tag under Tag to view the security status of servers with that tag.

    Note

    Security Center supports managing and deleting server tags. For more information, see Manage server tags.

    Search by multiple criteria

    Server categories such as All Servers and Unprotected also support one or more search conditions to filter servers.

    The following example shows how to search for servers that meet all three conditions: OS type is Linux, security alerts exist, and region is China (Hangzhou).

    1. On the All Servers tab, click Whether Alert Exists.

    2. In the search condition dropdown, configure the following conditions for OS Type, OS Type, and Region respectively:

      • OS Type: Linux

      • Whether Alert Exists: Yes

      • Region: China (Hangzhou)

      Note

      Some search conditions do not support direct selection. Select the filter condition and enter a specific value in the input field on the right.

      After configuring filter conditions, the set conditions are displayed above the server list.

    3. Click AND or OR to the left of the search conditions to switch the logical relationship between them.

      • AND: All conditions must be satisfied.

      • OR: At least one condition must be satisfied.

      After configuration, servers in the list satisfy all three conditions. Multi-condition filter

    4. Optional: To save the filter conditions for reuse, click Save to the right of the search conditions.

      After saving as a frequently used search condition, use the saved conditions to quickly find target servers.

Manage server information

The Asset Center page provides server group, importance, and tag features to manage servers from different dimensions and simplify the use of other Security Center features.

Manage server protection status

After you install the Security Center agent on a server, Security Center automatically enables protection. Modify the protection state based on your business needs.

Status descriptions

On the Host page, check the Agent column to view the protection status.

  • Agent online: The server is protected by Security Center.

  • Agent offline: The server is offline.

    Note

    When the agent is offline, Security Center cannot protect the server. Resolve the agent offline issue promptly. For more information, see Agent troubleshooting.

Procedure

  1. Log on to the Security Center console.

  2. In the navigation pane on the left, choose Assets > Host. In the upper-left corner of the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.

  3. On the server list, manage the protection status:

    • Suspend protection: Select the target server, click More Operations below the list, and select Disable Protection.

      Warning

      Servers with suspended protection are not protected by Security Center, including vulnerability detection and security alerts. Proceed with caution.

    • Enable protection: Select the target server, click More Operations below the list, and select Enable Protection.

Manage server groups

After grouping servers, use features such as anti-ransomware and baseline checks to select servers by group. Manage groups in the group section on the left side of the Servers tab.

  • Edit or delete a group

    • Edit group: Move the pointer over the target group, click the Settings icon, and modify the group name or add or remove servers in the Group Management dialog box.

    • Delete group: Move the pointer over the target group, click the Delete icon, and click OK in the Note dialog box.

      Note

      The default group Ungrouped cannot be deleted.

  • Change group

    In the Server Group section, click a group name to view the server list, select the servers to move, and click Change Group below the list to change the group.

    • Transfer to an existing group

      Select Move to Existing Group, select the target group from the New Group dropdown, and click OK.

    • Create a new group

      Select Create Group, enter a new group name in the New Group field, and click OK.

    Alternatively, select servers from the all servers list and click Change Group below the list to change the group.

Manage server importance

Server importance affects the vulnerability remediation priority score. After you mark core servers as important, Security Center prioritizes vulnerability alerts for those servers. The following table describes the relationship between server importance and the asset importance factor.For more information, see Vulnerability fix priority.

Importance

Asset importance factor

Recommendation

Important

1.5

Servers that run core business or store core data. Compromise of these servers causes significant business impact.

Normal

1

Servers that run general business. These servers are replaceable and compromise has limited impact on the overall system.

Test

0.5

Servers used for business or performance testing, or other servers with minimal business impact.

  • Batch setting

    Click Manage in the Importance section, select the importance level and servers to include, and click OK.

  • Modify classification

    Move the pointer over the target importance level (Important, Normal, or Test) in the Importance section, click the Settings icon, add or remove servers in the Asset Importance Management dialog box, and click OK.

  • Single server setting

    In the server list, click the Importance icon in the Server Information column, select the importance level, and click OK.

Verify: The importance icon updates in the server list.

Manage server tags

Use the Tag feature to assign custom tags to servers, making it easy to filter servers with the same attributes.

  • Filter by tag

    In the Tag section, click a tag name to view the list of all servers with that tag.

  • Create a tag

    In the Tag section, click Manage in the upper-right corner, enter the tag name, select the servers, and click OK.

  • Edit or delete

    • Edit: Move the pointer over the target tag, click the Settings icon, modify the tag name or add or remove servers in the Tag Management dialog box, and click OK.

    • Delete: Move the pointer over the target tag, click the Delete icon, and click OK in the Note dialog box.

  • Single server setting

    • Add tag: In the server list, click the Tag icon in the Server Information column, select the tag, and click OK.

      Note

      Multiple tags can be assigned to a single server.

    • Delete tag: In the server list, click the Delete icon to the right of the tag in the Server Information column, and click OK in the Note dialog box.

Verify: The tag appears in the Tags column for the server.

Release and unbind servers

Choose the appropriate operation based on the server type and usage status:

  • Release instance: For Alibaba Cloud servers (ECS or simple application servers) that are no longer in use. This recycles resources and stops billing. Perform the release in the corresponding cloud server console.

  • Unbind server: For non-Alibaba Cloud servers that no longer need Security Center protection. Unbinding releases quotas that can be used to protect other servers.

  • Scheduled cleanup: When the number of non-Alibaba Cloud servers is large. After you enable this feature, the system automatically cleans up offline non-Alibaba Cloud servers and reclaims quotas.

Release ECS or simple application server instances

Warning

After an instance is released, associated snapshots and custom images are also released. Data cannot be recovered.

  1. Before releasing an instance, uninstall the Security Center agent to avoid residual alerts. For more information, see Uninstall agent.

  2. Go to the corresponding cloud server console to release the instance:

  3. Return to the Security Center console and confirm the asset is removed from the server list. If not automatically removed, click Synchronize Assets.

Unbind non-Alibaba Cloud servers

When a non-Alibaba Cloud server no longer requires Security Center protection or is stopped (offline), manually unbind it. After unbinding, the released quota can be used to protect other servers.

Note

If the server no longer needs Security Center protection, Uninstall agent to completely remove the agent process and files. To re-protect the server later, Install the agent again.

Operation notes

  • Applicable to: Non-Alibaba Cloud servers only.

    Important

    Alibaba Cloud ECS servers do not require unbinding. Even after the agent is uninstalled, ECS servers remain in the asset list as "offline" and are not automatically removed.

  • Effects:

    • Quota release: The server no longer consumes Security Center quotas. Released quotas can be used to protect other servers.

    • Protection stopped: Security Center uninstalls the agent and stops protecting the server.

    • Asset removal: The server is removed from the Security Center asset list.

  • Special scenario: If the server is connected through a third-party account AK, unbinding automatically uninstalls the agent and removes the asset.

    Important

    During the next asset synchronization, the server reappears in the list but the agent is not automatically reinstalled.

Procedure

  1. Log on to the Security Center console.

  2. In the navigation pane on the left, choose Assets > Host. In the upper-left corner of the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.

  3. In the asset list, select the non-Alibaba Cloud server to unbind, and choose More Operations > Unbind below the list.

  4. In the Note dialog box, click OK.

  5. Confirm the result: After unbinding, Security Center sends an uninstall command, removes the server from the asset list, and stops protection.

    • Return to the server list and confirm the server is removed.

    • If the server still appears in the list, click the manual refresh button above the list to synchronize the latest asset information.

Scheduled cleanup for off-premises servers

If there are many non-Alibaba Cloud servers, enable scheduled cleanup to automatically clean up offline servers and reclaim quotas instead of unbinding them one by one.

Important

Scheduled cleanup applies only to non-Alibaba Cloud servers. Alibaba Cloud ECS servers are not removed even when offline.

  1. Log on to the Security Center console.

  2. In the navigation pane on the left, choose Assets > Host. In the upper-left corner of the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.

  3. In the Add Multi-cloud Asset section, move the pointer over the Scheduled cleanup icon icon and click Scheduled Cleanup.

  4. In the Scheduled Cleanup dialog box, click the Enable icon icon to enable scheduled cleanup. Under cleanup rules, click the Settings icon icon to set the offline days for host cleanup. Valid values: 1 to 30. The system automatically reclaims quotas based on the configured offline days.

FAQ

Agent and protection status

  • Why does the server still show as offline after enabling protection?

    • The Security Center agent is not installed on the server. Install the agent and Security Center automatically enables protection. For more information, see Install the agent.

    • The agent on the server is offline. Resolve the agent offline issue promptly. For more information, see Handle agent offline issues.

  • Why does the server still appear in the asset list after uninstalling the agent?

    Uninstalling the agent stops protection but does not remove the server record from the asset list. Alibaba Cloud servers continue to display as long as the instance exists. For non-Alibaba Cloud servers, manually unbind to remove from the list.

Asset synchronization and connection

  • Why do new servers still not appear after manual synchronization?

    • Confirm that the agent is installed and running on the server.

    • Confirm that the region selector in the upper-right corner of the console is set to the server's region or to all regions.

    • For non-Alibaba Cloud servers, confirm that network connectivity between the server and Security Center is normal.

  • Are host assets connected repeatedly?

    No. The system uses the MAC address to uniquely identify a host. View the MAC address on the Basic Information tab of the server details page to confirm the asset.

Release and unbind

  • Why is the quota not released immediately after unbinding a non-Alibaba Cloud server?

    After submitting the unbind request, there may be a short delay (usually 1 to 5 minutes) before the quota is released. If not released after 10 minutes, try manual synchronization.

  • Can Security Center directly release ECS or simple application server instances?

    Security Center handles server protection only, not instance lifecycle management. To release an ECS instance, go to the ECS console. In Security Center, you can only unbind non-Alibaba Cloud servers or remove Alibaba Cloud servers from the protection list.

Billing

Does host asset protection incur duplicate billing?

No. When the default features included in your subscription overlap with pay-as-you-go features, the system automatically disables the pay-as-you-go mode for those features and uses the subscription service. For more information, see Billing methods.