Purchase Application Protection

Updated at:

Application Protection is a value-added service of Security Center and must be purchased before use. You can purchase Application Protection on a subscription or pay-as-you-go basis. This topic describes how to purchase Application Protection.

7-day free trial

Security Center provides a 7-day free trial. After you activate the free trial, you can use 10 Application Protection authorizations free of charge. If you have never purchased Security Center services, you can apply for the free trial. For more information about the limits and the procedure, see Enable a 7-day Enterprise Edition free trial.

Billing

Application Protection is billed based on the number of protected processes. Protecting one application process consumes one authorization. The billing methods and prices are as follows:

  • Subscription:

    • Quotas ≤ 50: CNY 40/quota/month.

    • 50 < quotas ≤ 200: CNY 30/quota/month.

    • 200 < quotas ≤ 3,500: CNY 20/quota/month.

    • 3,500 < quotas ≤ 5,000: CNY 18/quota/month.

    • 5,000 < quotas ≤ 6,500: CNY 15/quota/month.

    • Quotas > 6,500: CNY 12/quota/month.

  • Pay-as-you-go:

    • Billing method: Metered by the number of online instances per minute (0-60 seconds).

    • Billing cycle: Settled daily.

    • Price: CNY 0.0014/instance/minute.

Application Protection is a value-added service of Security Center. The validity period of Application Protection authorizations is the same as the subscription period of the subscription-based Security Center edition. When you purchase Application Protection authorizations, the fee is prorated based on the remaining validity period of the Security Center edition.

Purchase a subscription

Application Protection can protect only Java and PHP applications that are in the Running state. Before you purchase Application Protection authorizations on a subscription basis, we recommend that you confirm the number of applications that you want to connect. For more information, see How do I view the supported applications and their quantity?

  1. Log on to Security Center console.

  2. In the left-side navigation pane, choose Protection Configuration > RASP. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  3. On the RASP page, click Enable Subscription.

  4. On the Quick Purchase tab, in the RASP area, set Purchase or Not to Yes, and specify Quantity.

    Set the purchase quantity to the number of processes that you want to protect.

    • If you do not need to purchase other security features, set Edition to Value-added Plan.

    • To purchase a Security Center edition and other value-added services, select the edition and services that you want. For more information, see Purchase Security Center.

  5. Follow the instructions on the purchase page to read and accept the product agreement, click Order Now, and complete the payment.

Enable pay-as-you-go

  1. Log on to Security Center console.

  2. In the left-side navigation pane, choose Protection Configuration > RASP. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  3. On the RASP page, click Activate Pay-as-you-go.

  4. In the dialog box that appears, click Activate Now.

    After the service is activated, full protection is enabled by default, only Java processes are connected, and the slow connection mode is used. If you do not need full protection, click Custom Quota Binding and select the servers to connect in the Quota Management dialog box. After the service is activated, you can also adjust the servers and processes to connect on the RASP > Application Configurations tab.

    For more information about automatic full provisioning, see Automatic full access (Java processes only).

Unsubscribe

If you no longer need Application Protection, you can unsubscribe from the service.

  • Subscription: On the Overview page Subscription region, clickChange Configuration > Downgrade to go to the order upgrade or downgrade page. On the Order Downgrade tab, in the RASP area, set Purchase or Not to No. For more information, see Upgrades and downgrades.

    Important

    The exact refund amount is subject to the amount displayed on the downgrade page. For more information about where the refund goes, see Refund destinations.

  • Pay-as-you-go: On the Overview page of the Security Center console, in the Enable Pay-as-You-Go Service area, turn off the RASP switch.

    Important

    After the switch is turned off, no new fees are incurred.

FAQ

What types of applications does Application Protection support?

Application Protection can connect and protect only Java applications and PHP applications. The runtime environments of Java and PHP applications must meet specific requirements. Python, Go, and .NET applications are not supported.

Can I use Application Protection for internal servers?

Yes. Internal servers (servers in third-party clouds or on-premises data centers that cannot directly connect to the Internet) can use Application Protection over a proxy connection. The servers that you want to protect must be connected to Security Center over a proxy connection first. That is, install the Security Center client on the servers, and then install the RASP agent.

Note

If no server in your internal environment can connect to the Internet and you cannot establish a network connection between your internal network and an Alibaba Cloud VPC, you cannot use the security protection capabilities provided by Security Center or use the Application Protection feature.

Limits

  • The proxy connection method supports only Java applications.

  • Prepare one or more servers that can connect to the Internet as proxy servers, or establish a network connection between your internal network and an Alibaba Cloud VPC.

Steps to connect internal servers to Application Protection over a proxy

  1. Create a proxy cluster.

  2. Deploy a proxy server.

  3. Connect the servers to protect to the proxy cluster.

  4. When you provision application protection, in the Access Management panel, on the Manual Access > Add Container tab, select Custom Installation and the corresponding proxy cluster, and then complete the installation of the RASP agent.

    For more information, see Enable application protection.

How do I view the supported applications and their quantity?

Before and after you purchase Application Protection, you can view the list and number of supported Java and PHP applications from different entry points.

  • Before purchase:

    1. Log on to Security Center console.

    2. In the left-side navigation pane, choose Protection Configuration > RASP. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

    3. In the Protection Statistics area, click Scan Now.

      After you click Scan Now, the Security Center client collects the process information of your assets.

      Note
      • Subscription services: The Free, Value-added Service Only, Anti-virus, and Advanced editions support only one scan per day. Enterprise and Ultimate edition users can perform scans without limit.

      • Pay-as-you-go services:

        • If Host and Container Security is enabled, you can perform scans unlimited times per day. Only the servers that are bound to the Comprehensive Host Protection or Comprehensive Host and Container Protection protection level can be scanned.

        • If Host and Container Security is not enabled, you can perform only one scan per day.

    4. View the number of application processes in your assets. You can click a number to view the application process list. The application process list provides the server information, process name, PID, and startup parameters of the application processes that support Application Protection.

      Important
      • Protecting one application process consumes one Application Protection authorization. The number of processes changes dynamically. The data collected is the processes that were in the Starting state at the time when the scan was performed. You can estimate the number of Application Protection authorizations to purchase based on the number.

      • If you have performed scans before, the system automatically saves and displays the scan data generated within the last seven days. Scan data older than seven days is automatically cleared. After a scan is performed, the latest collected data of the servers overwrites the existing data of the servers.

  • After purchase:

    Application processes change dynamically. After you purchase Application Protection authorizations, you can refer to the following steps to view the list of Java and PHP application processes that can be protected by RASP.

    1. Log on to Security Center console.

    2. In the left-side navigation pane, choose Protection Configuration > RASP. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

    3. On the Application Analysis tab, in the Application Access Statistics area, click Resource Statistics to the right of Remaining Quota.

    4. In the Application Processes panel, click Scan Now. After the last detection time is refreshed, view the list of application processes that support RASP protection.

      Note
      • Subscription services: The Free, Value-added Service Only, Anti-virus, and Advanced editions support only one scan per day. Enterprise and Ultimate edition users can perform scans without limit.

      • Pay-as-you-go services:

        • If Host and Container Security is enabled, you can perform scans unlimited times per day. Only the servers that are bound to the Comprehensive Host Protection or Comprehensive Host and Container Protection protection level can be scanned.

        • If Host and Container Security is not enabled, you can perform only one scan per day.

    5. In the Application Processes panel, click the number under Java or PHP to view the list of Java or PHP processes that support protection.

      • In the process list, you can view the RASP protection status of the processes in the Application Protection column, including Added, Not Added, and Failed.

      • Click the image icon to export the details of the application process list.

Does Resource Statistics display the application process list of a shut-down server?

Collected application process data is retained for seven days and automatically cleared after seven days. If a resource statistics scan was performed on a server before the server was shut down, new scans performed after the shutdown cannot collect the application process data of the server. The previously collected application process data is retained until the data is automatically cleared seven days later.