Purchase Security Center

更新时间:
复制 MD 格式

Security Center is a centralized security solution that addresses persistent threats to cloud assets, such as viruses, hacker attacks, and ransomware. It provides multiple billing models and editions to build a security protection system for cloud assets based on business scenarios and budgets.

Quick selection guide

Use case

Recommended solution

Core value and features

First-time use or evaluation

Experience comprehensive host security, including vulnerability management and intrusion prevention.

Zero-cost experience for international site users

International site free trial: Claim a USD 100 savings plan coupon.

Claim the coupon to activate all pay-as-you-go features at zero cost, with a 15-day trial period.

Hybrid cloud host security

Subscription:

  • Edition: Enterprise

  • Add-ons: Anti-ransomware, Log Analysis, CSPM, Agentic SOC (Legacy)

Unified security management that provides consistent protection policies and visual management for cloud and on-premises hosts, enabling centralized governance across environments.

Container security protection

Subscription:

  • Edition: Ultimate

  • Add-ons: Anti-ransomware, Log Analysis, Image Security Scan, CSPM

Full-stack protection from hosts to container runtime. Adding image scanning enables shift-left security in the CI/CD phase for lifecycle security.

MLPS compliance

Subscription:

  • Edition: Enterprise or Ultimate

  • Add-ons: Anti-ransomware, Log Analysis, File Tamper-Proofing, Agentic SOC (Legacy)

One-stop host security solution. Comprehensive coverage of vulnerabilities, intrusions, and baseline checks for daily security operations; adding log analysis meets MLPS compliance requirements for log retention of 180 days or more.

Major event support

Subscription:

  • Edition: Enterprise/Ultimate

  • Add-ons: Application Protection, File Tamper-Proofing, Cloud Honeypot

Beyond comprehensive protection, provides application runtime self-protection (Runtime Application Self-Protection, RASP) and tamper-proofing capabilities—critical for defending against advanced threats and ensuring core business stability.

Security incident response

Pay-as-you-go: For detailed plans, see Pay-as-you-go boarding policies and billing.

For urgent security intrusions such as servers infected with crypto-miners, viruses, or trojans, or incidents like website defacement and ransomware.

Billing methods

Security Center supports subscription, pay-as-you-go, and hybrid billing. All billing methods include the Free Edition capabilities. Choose a paid billing method only when you need enhanced features.

Important

Regardless of the billing method you choose, you retain the Free Edition capabilities, which include basic vulnerability scanning, threat detection, and abnormal logon alerts. See Key considerations for guidance on choosing a paid edition.

Item

Subscription

Pay-as-you-go

Hybrid

Payment model

Single upfront fee for a monthly or yearly term. Fixed cost simplifies budgeting.

Pay only for what you use. No upfront investment.

Package fee is fixed; additional usage beyond the package is billed on a pay-as-you-go basis. The two parts are billed independently.

Fee breakdown

Fees = Edition fee + Value-added service fee (optional).

  • Edition fee: Editions such as Anti-virus, Advanced, Enterprise, Ultimate, Value-added Plan are available. Higher-tier editions include more comprehensive features.

  • Value-added service fee: Purchase additional value-added services, such as anti-ransomware and Agentic SOC.

Note

For subscription fee details, see Subscription.

Fees = Basic service fee + Feature usage fee.

  • Basic service fee: Charged when you enable any pay-as-you-go feature. It includes services such as DingTalk Robot, security reports, and Task Hub (requires purchase or activation of vulnerability fixing).

  • Feature usage fee: Charges apply for the specific features you purchase and enable. Each feature can be enabled and billed separately.

Note

For pay-as-you-go fee details, see Pay-as-you-go.

  • Fees = Subscription quota fee + Elastic quota fee. Subscription quota fee: fixed fee charged based on the quota of the purchased edition or feature package.

  • Elastic quota fee: when actual usage exceeds the subscription quota, the excess is automatically billed on a pay-as-you-go basis.

Note

For hybrid billing fee details, see Hybrid billing.

Best for

Stable, long-term workloads with a fixed budget.

Elastic scaling, short-term projects, or frequently changing demands.

Stable long-term business needs with a fixed budget but occasional incremental demand beyond the purchased quota, where you want to avoid interruption of security protection due to quota exhaustion.

Purchase options

Security Center features are available through the following purchase methods:

  • Purchase on the Security Center page: One-stop ordering on the Security Center purchase page.

    • Subscription: The fee includes the edition service fee and add-on fees.

    • Pay-as-you-go: Basic service fee plus feature usage fees.

  • Purchase separately on dedicated pages: Some specific features can only be purchased independently with dedicated purchase pages and billing rules. Once enabled, these features are still managed centrally in the Security Center console.

Purchase on the Security Center page

Subscription

Step 1: Select an edition and add-ons

  • Edition services: Select Anti-virus, Advanced Edition, Enterprise, or Ultimate. Each edition provides different integrated protection capabilities.

  • Add-ons: Purchase add-ons separately based on your business needs, such as Anti-Ransomware and Application Protection (Runtime Application Self-Protection, RASP).

Edition services

Edition

Description

Cost

Basic

Only basic security detection capabilities (such as detecting abnormal server logins, DDoS, mainstream server vulnerabilities, and configuration security issues for some cloud products), with no active protection features.

Free

Anti-virus

Provides detection and removal capabilities for common host viruses.

CNY 5 per core per month

Advanced Edition

Provides host virus detection, virus removal, vulnerability detection and remediation, and security reports.

CNY 60 per instance per month

Enterprise

Meets MLPS compliance and host security requirements for intrusion prevention, identity authentication, and security auditing.

CNY 150 per instance per month

Ultimate

Provides full-stack security protection covering hosts, containers, and Intelligent Computing Lingjun servers, including Kubernetes (K8s) threat detection, container asset overview, security alerts, virus removal, vulnerability detection, asset fingerprinting, and attack chain analysis.

CNY 150 per instance per month + CNY 5 per core per month

Comparison of main protection capabilities across editions:

Protection capability

Basic

Anti-virus

Advanced Edition

Enterprise

Ultimate

Partial malware and cloud product threat detection

Supported

Supported

Supported

Supported

Supported

Virus removal and host intrusion detection

Unsupported

Supported

Supported

Supported

Supported

Brute-force attack prevention

Unsupported

Unsupported

Supported

Supported

Supported

Host behavior defense

Unsupported

Supported

Note

Supports only malicious MD5 process blocking.

Supported

Supported

Supported

System vulnerability check and remediation

Unsupported

Unsupported

Supported

Supported

Supported

Malicious network behavior prevention

Unsupported

Unsupported

Unsupported

Supported

Supported

Attack tracing

Unsupported

Unsupported

Unsupported

Supported

Supported

Application vulnerability detection

Unsupported

Unsupported

Unsupported

Supported

Supported

Baseline check and remediation

Unsupported

Unsupported

Supported

Note

Supports only weak password checks.

Supported

Supported

Container security

Unsupported

Unsupported

Unsupported

Unsupported

Supported

Add-ons

Anti-ransomware

  • Description: Provides anti-ransomware backup and recovery capabilities. Use backup files to restore servers and databases after a ransomware attack.

  • Purchase notes:

    • The purchase quantity represents anti-ransomware capacity, which is related to the size of files to be backed up and the backup retention period, not the number of servers.

    • Available only in select regions. Set the protected data volume as needed. For supported regions, see Supported regions for anti-ransomware.

    • If you select Set Recommended Policy, the system automatically performs regular backups of important file paths on existing servers. To adjust the strategy, go to the anti-ransomware page. For details, see Modify server anti-ransomware policies.

CSPM (CSPM)

  • Description: Provides identity and permission management, automated compliance checks, and cloud product configuration baseline detection for centralized management of multi-cloud configuration risks.

  • Purchase notes: Billed by the number of cloud product instances scanned, verified, and remediated.

    Note

    Unused quota is cleared at the end of each month. For more billing details, see CSPM billing overview.

Agentic SOC (Legacy)

  • Description:

    • Agentic SOC (Legacy): Supports unified log ingestion across clouds, accounts, and products (such as Web Application Firewall, Cloud Firewall, and VPC) for closed-loop security alert detection, event response, and incident handling. Helps improve security operations efficiency and meet MLPS compliance log audit requirements.

    • Security Operations Agent: A premium value-added service powered by Agentic AI that integrates deeply with Alibaba Cloud native security data and infrastructure. Uses Agent autonomous perception, reasoning, and execution capabilities to independently evaluate security events and enable rapid incident response.

  • Purchase notes:

    • Modular billing: billing items vary based on purchase options. For details, see Agentic SOC - Subscription.

      • Agentic SOC (Legacy): Billed separately by Log Ingestion Traffic and Agentic SOC ( Log Storage Capacity ). Purchase based on your actual needs.

        Log ingestion traffic (GB/day)

        • Use: For real-time threat detection, attack tracing, alert analysis, and other core security operations. After purchase, access most core Agentic SOC features such as threat detection and investigation response.

        • Estimating capacity:

          • Based on existing log volume

            Daily traffic (GB) = Total log storage capacity (GB) / Log retention days (TTL).

            Example: If you currently have 10,000 GB of logs retained for 90 days, daily traffic is approximately 10000 / 90 ≈ 111 GB. We recommend purchasing 200 GB/day.

          • Based on log generation rate (EPS)

            Daily traffic (GB) = EPS (log entries per second) × 86400 × Average log size (KB) / 1024

            • EPS: Log entries generated per second.

            • Average log size: Typically between 3 KB and 7 KB.

        Log storage capacity (GB)

        • Use: For long-term storage, query, and audit of logs to meet compliance requirements such as the Cybersecurity Law and MLPS 2.0, which require log retention of no less than 180 days. Also supports retrospective analysis of historical events. The log storage capacity you purchase here is the same capacity entitlement that the Log module displays and uses—these are not two separate capacity pools. Before purchasing Agentic SOC, access the Log module via Detection and Response > Log. After purchasing Agentic SOC, the entry changes to Agentic SOC > Log; this entry change does not affect your purchased capacity entitlement.

        • Estimating capacity:

          • By server count: We recommend 120 GB of log storage capacity per server.

          • By existing log analysis capacity: Set to 3 times the purchased capacity in the Security Center - Log Analysis feature.

      • Security Operations Agent: In addition to Agentic SOC, you must also purchase Intelligent Usage Analysis and Number of Managed Instances.

        • Intelligent Usage Analysis: The analysis usage consumed by Security Operations Agent for alert evaluation, event investigation, tracing, attribution, and security report generation. The purchase quantity does not support auto-fill and must match the Log Ingestion Traffic quantity.

          Note

          Intelligent Usage Analysis is cleared daily. Exceeding the limit results in automatic throttling.

        • Number of Managed Instances: Security Operations Agent supports cross-instance security operations and automated handling. Billing is based on the number of managed instances. Each invoked instance is charged, including ECS, WAF, ALB, cross-cloud products, and on-premises security vendor products.

          Note

          Cleared monthly. Each instance is counted only once with automatic deduplication.

    • If you select Access Policy, log sources from your current Alibaba Cloud account for Security Center, Web Application Firewall, Cloud Firewall, and ActionTrail are automatically ingested.

Vulnerability Fixing

  • Description: Enables one-click remediation of Linux Software Vulnerability and Windows System Vulnerability on servers from the console.

  • Purchase notes: Enter the number of vulnerability remediation attempts to purchase based on the monthly number of vulnerabilities to be remediated.

    Note

    The number of remediation attempts equals the total number of vulnerabilities remediated across all servers. For example, if 10 servers have the same named vulnerability and you use Security Center to remediate it, 10 remediation attempts are consumed.

Image Security Scan

  • Description: One-click scanning of images for system vulnerabilities, application vulnerabilities, viruses, and malicious samples, with remediation recommendations.

  • Purchase notes:

    • Enter the number of scan authorizations to purchase based on your monthly needs.

      Note

      Scan authorization: Consumes 1 authorization when an image digest is scanned for the first time. Subsequent scans of the same digest do not consume authorizations. If the image digest changes, authorization must be consumed again.

    • Available only when the edition is Advanced Edition, Enterprise Edition, Ultimate Enterprise, or Value-added Plan.

File Tamper-Proofing

  • Description: File tamper-proofing uses real-time monitoring to comprehensively track file system activities, automatically intercept unauthorized write and delete operations, and log all access behavior to form a complete audit chain, ensuring the integrity of critical files.

  • Purchase notes: Select the number of servers to protect.

Malicious File Detection

  • Description: Deep scanning and detection of malicious software, web shells, viruses, and other potential risk files hidden in server file systems.

  • Purchase notes: Set the purchase quantity to the number of files to be scanned per month.

RASP (RASP)

  • Description: Application protection is based on RASP technology, enabling applications to protect themselves at runtime by detecting and blocking attacks in real time.

  • Purchase notes: We recommend setting the purchase quantity to the total number of Java processes to protect.

    Note

    Example: If you have 2 servers each running 3 Java applications to protect, purchase 6 authorizations.

Cloud Honeypot

  • Description: Efficiently captures and traps attacker behavior, enhancing detection and protection of core assets in attack-defense scenarios.

  • Purchase notes: Cloud honeypots are billed by the number of probes. Minimum purchase: 20 probes. Maximum: 500 probes.

    Note

    For more than 500 probes, contact technical support for capacity expansion.

Security Dashboard

  • Description: Provides multiple visual dashboards for macro-level monitoring of asset security posture.

  • Available only when the edition is Advanced Edition, Enterprise Edition, or Ultimate Enterprise.

Log Analysis

  • Description: Aggregates security logs from cloud assets (including hosts and security events), provides powerful SQL search and visual reports for easy event tracing, attack investigation, and compliance auditing.

    Important

    If you also purchase the Agentic SOC ( Log Storage Capacity ) pay-as-you-go service, Security Center logs are stored twice. To avoid duplicate charges, evaluate your needs and turn off the relevant log delivery switches in the Log Analysis module from the Security Center console.

  • Purchase notes: Logs must be stored for at least 180 days as required by the Cybersecurity Law. We recommend no less than 50 GB of storage capacity per server.

Step 2: Configure and pay on the purchase page

  1. Log on and access the purchase page

    Use your Alibaba Cloud account to log on and visit the Security Center purchase page.

  2. Select an edition

    Important

    If you have already activated the pay-as-you-go Host and Container Security service, only the Value-added Plan is supported.

    • Billing Method: Select Subscription.

    • Protection Scenario: The system automatically recommends an edition and add-on configuration based on your selected protection scenario.

    • Edition: For the baseline protection capabilities of each edition, see Subscription - Step 1: Select an edition and add-ons - Edition services.

    • Protected Servers: Specify the total number of servers to protect. By default, this displays all Alibaba Cloud ECS instances and connected non-Alibaba Cloud servers under your account.

      Note

      This parameter is not required when the edition is Anti-virus or Ultimate.

    • Cores: The number of vCPUs across your servers. Defaults to the total vCPU count of all ECS instances and connected non-Alibaba Cloud servers.

      Note

      This parameter is required only when the edition is Anti-virus or Ultimate.

  3. Security Authorization

    Apply the purchased edition authorization to specific servers for protection to take effect.

    • Automatic binding (default):

      The system automatically assigns authorizations to unbound servers under your account based on the default policy. Unbind or rebind authorizations later; see Bind or unbind authorized assets.

    • Custom binding:

      1. Click Custom Quota Binding and select the region where the servers are located.

      2. Select the servers from the list and choose the corresponding edition in the Target Version column. For feature details of each edition, see Edition services.

        If you select multiple servers, click Update Version below the list to bind the same edition to all selected servers.

      3. (Optional) Select Automatically Add New Servers to Security Center to automatically bind the purchased edition to any new servers added later.

        Warning

        If not selected, you must manually bind authorizations for new servers; otherwise, they will not receive Security Center protection. For details, see Bind or unbind authorized assets.

  4. Select add-ons

    Enable the add-on modules you need by toggling Purchase or Not to Yes and completing the required configuration. For feature details of each add-on, see Subscription - Step 1: Select an edition and add-ons - Add-ons.

  5. Confirm and pay

    Read and accept the Security Center Terms of Service, then click Order Now to complete payment.

  6. Verify purchased services

    After purchase, log on to the Security Center console. Navigate to the Overview page, Subscription section to view your active services.

    Note

    Confirm the following to verify your purchase was successful:

    • The displayed edition name matches your selection.

    • The service status shows as Active.

    • All purchased add-ons appear in the value-added services list.

Pay-as-you-go

Step 1: Select the features to enable

  • Default features: Enabling any pay-as-you-go feature incurs a base service fee. The following features are included by default: DingTalk Chatbot, Security Report, and Task Center.

  • Billing features: Purchase specific protection features as needed. Each feature is billed independently.

Default features

  • DingTalk Chatbot: Configure a DingTalk bot to receive real-time threat alerts in a DingTalk group.

  • Security Report: Customize the security metrics you care about and receive periodic reports via email for real-time asset monitoring.

  • Task Center: Provides automated response orchestration to streamline security remediation workflows by creating automated policies for repetitive tasks.

    Note

    Requires the Vulnerability Fix feature to be enabled or purchased.

Billing features

Host and Container Security

Important

If you have already purchased the subscription-based Anti-virus, Advanced, Enterprise, or Ultimate, the pay-as-you-go Host and Container Security service cannot be enabled.

  • Description: Provides comprehensive detection and protection for host and container assets. After purchase, you must bind a protection level to your assets. Protection levels are described in the following table.

    Protection level

    Description

    Monthly cost (30-day estimate)

    Unprotected

    Basic security detection capabilities only (e.g., anomalous login detection, DDoS, common server vulnerabilities, and security posture issues for select cloud services). No active protection features.

    Free

    Antivirus

    Detects and removes common viruses on hosts.

    CNY 7.5/core/month

    Advanced

    No longer available for new purchases or modifications.

    CNY 90/server/month

    Comprehensive Host Protection

    Meets classified protection compliance requirements (Dengbao) and addresses host intrusion prevention, identity authentication, and security auditing requirements.

    CNY 225/server/month

    Hosts and Container Protection

    Provides full-stack security protection for hosts, containers, and intelligent computing servers, including Kubernetes (K8s) threat detection, K8s, container asset visibility, security alerts, virus detection, vulnerability detection, asset fingerprinting, and attack chain analysis.

    CNY 225/server/month + CNY 7.5/core/month

    Key protection capabilities by level:

    Protection capability

    Unprotected

    Antivirus

    Comprehensive Host Protection

    Hosts and Container Protection

    Malware and cloud product threat detection

    Supported

    Supported

    Supported

    Supported

    Virus detection and host intrusion detection

    Unsupported

    Supported

    Supported

    Supported

    Brute-force attack prevention

    Unsupported

    Unsupported

    Supported

    Supported

    Host behavior defense

    Unsupported

    Supported

    Note

    Only supports blocking malicious MD5 processes.

    Supported

    Supported

    Malicious network behavior defense

    Unsupported

    Unsupported

    Supported

    Supported

    Attack tracing

    Unsupported

    Unsupported

    Supported

    Supported

    Application vulnerability detection

    Unsupported

    Unsupported

    Supported

    Supported

    Container security

    Unsupported

    Unsupported

    Unsupported

    Supported

  • Purchase notes: After enabling this feature, you must authorize it on specific assets for it to take effect. Custom asset binding is supported during purchase.

    Important

    Default binding rules:

    • Servers running container environments (including Alibaba Cloud ACK cluster nodes, intelligent computing servers, and servers connected via self-managed Kubernetes clusters): Hosts and Container Protection.

    • Other assets: Comprehensive Host Protection.

    • Newly added servers: Hosts and Container Protection.

CSPM (CSPM)

  • Description: Provides identity and permission management, automated compliance checks, and cloud product configuration baseline detection for centralized management of multi-cloud configuration risks.

  • Purchase notes: Billed by the number of cloud product instances scanned, verified, and remediated.

Vulnerability Fixing

  • Description: Enables one-click remediation of Linux Software Vulnerability and Windows System Vulnerability on servers from the console.

  • Purchase notes: Enter the number of vulnerability remediation attempts to purchase based on the monthly number of vulnerabilities to be remediated.

    Note

    The number of remediation attempts equals the total number of vulnerabilities remediated across all servers. For example, if 10 servers have the same named vulnerability and you use Security Center to remediate it, 10 remediation attempts are consumed.

Image Security Scan

  • Description: Scans images for system vulnerabilities, application vulnerabilities, viruses, and malicious samples, and provides remediation recommendations.

  • Purchase notes: Billed per scan. CNY 0.75/scan. The first scan of a unique image digest consumes one authorization; subsequent scans of the same digest are free. If the image digest changes, a new authorization is required.

  • This feature is available only when the edition is Advanced Edition, Enterprise Edition, Value-added Plan, or Ultimate Enterprise.

Agentic SOC (Legacy)

  • Description:

    • Agentic SOC (Legacy): Supports unified log ingestion across clouds, accounts, and products (such as Web Application Firewall, Cloud Firewall, and VPC) for closed-loop security alert detection, event response, and incident handling. Helps improve security operations efficiency and meet MLPS compliance log audit requirements.

    • Security Operations Agent: A premium value-added service powered by Agentic AI that integrates deeply with Alibaba Cloud native security data and infrastructure. Uses Agent autonomous perception, reasoning, and execution capabilities to independently evaluate security events and enable rapid incident response.

  • Purchase notes:

    • Billing items vary based on your selection. For details, see Agentic SOC - Pay-as-you-go.

      • Agentic SOC (Legacy): Tiered pricing based on Log Ingestion Traffic. The higher the volume, the lower the unit price.

        Important

        In pay-as-you-go mode, Agentic SOC ( Log Storage Capacity ) is not supported, so query and audit logs cannot be stored.

      • Security Operations Agent: In addition to the Log Ingestion Traffic base fee for Agentic SOC (Legacy), additional charges for Intelligent Usage Analysis and Number of Managed Instances apply.

        • Intelligent Usage Analysis: Analysis consumption incurred by Security Operations Agent for alert triage, incident investigation, tracing, attribution, and security report generation.

        • Number of Managed Instances: Security Operations Agent supports cross-instance security operations and automated remediation. Billing is based on the number of managed instances. Each invoked instance (e.g., ECS, WAF, ALB, cross-cloud products, on-premises security vendor products) is counted.

          Note

          Each instance is counted only once (deduplicated).

    • If you select Access Policy, logs from Security Center, Web Application Firewall, Cloud Firewall, and ActionTrail under the current Alibaba Cloud account are automatically connected.

Anti-ransomware

  • Description: Provides anti-ransomware backup and recovery capabilities. Restore servers and databases using backup files after a ransomware attack.

  • Purchase notes:

File Tamper-Proofing

  • Description: File tamper-proofing uses real-time monitoring to comprehensively track file system activities, automatically intercept unauthorized write and delete operations, and log all access behavior to form a complete audit chain, ensuring the integrity of critical files.

  • Purchase notes: Billed based on actual protection duration (seconds) multiplied by the number of protected servers. Servers meeting the following criteria are automatically counted:

    • Servers bound to interception protection rules.

    • Servers bound to alerting protection rules where the server protection edition is below Advanced or the protection level is below Comprehensive Host Protection.

Application Protection

  • Description: Application protection is based on RASP technology, enabling applications to protect themselves at runtime by detecting and blocking attacks in real time.

  • Purchase notes: Authorize this feature on specific assets after enabling for it to take effect. Custom asset binding is supported during purchase.

    Important

    By default, full protection is enabled with slow-rate connection.

Agentless Detection

  • Description: Perform vulnerability scanning and comprehensive risk checks without installing an agent on your servers.

  • Purchase notes: Billed based on the volume of scanned data.

Serverless Assets

  • Provides intrusion detection and vulnerability scanning for Serverless assets (such as Elastic Container Instances). For more information, see Serverless security - Pay-as-you-go.

  • Purchase notes: After enabling this feature, you must authorize it on specific assets for it to take effect. Custom asset binding is supported during purchase.

    Important

    By default, Serverless Assets protection is enabled for all Serverless assets.

Malicious File Detection

  • Description: File tamper-proofing uses real-time monitoring to comprehensively track file system activities, automatically intercept unauthorized write and delete operations, and log all access behavior to form a complete audit chain, ensuring the integrity of critical files.

  • Purchase notes: Billed based on the number of scanned files. For pricing details, see Malicious File Detection - Pay-as-you-go.

Log Management

  • Description: Log Management is built on Alibaba Cloud Log Service (SLS) and provides log auditing and analysis capabilities. Leveraging Security Center's detection and defense capabilities and the Agentic SOC module, it offers unified log auditing, built-in security reports, SQL-based analysis and tracing, and flexible storage policies.

    Important

    If you have also purchased the subscription-based Log Analysis service, Security Center logs will be stored twice. To avoid duplicate charges, evaluate your needs and disable the relevant log delivery switches in the Log Analysis module from the Security Center console.

  • Purchase notes: You must configure a log storage region.

Agentic EDR

  • Description: Provides hosts with intelligent business profiling, behavior baseline establishment, baseline deviation alerts, intelligent detection/alert analysis, and automated response capabilities.

  • Purchase notes: Each host binding consumes one seat authorization. No unsubscription required. For pricing details, see Agentic EDR - Pay-as-you-go.

Attack Management

  • Description: Provides hosts with intelligent business profiling, behavior baseline establishment, baseline deviation alerts, intelligent detection/alert analysis, and automated response capabilities.

  • Purchase notes: Billed based on the number of protected assets and scanning Credits consumed. For pricing details, see Attack Surface Management - Pay-as-you-go.

Step 2: Configure and pay on the purchase page

  1. Log on and access the purchase page

    Use your Alibaba Cloud account to log on and visit the Security Center purchase page.

  2. Select services

    Enable the add-on modules you need by toggling Purchase or Not to Yes and completing the required configuration. For feature details, see Pay-as-you-go - Step 1: Select the features to enable - Billing features.

  3. Authorization and binding

    For some services, you must authorize them on specific assets after enabling for them to take effect. Configuration steps:

    • Host and Container Security: Supports custom binding of host assets. Steps:

      Important

      If not configured, the system binds host assets using default rules:

      • Servers running container environments (including Alibaba Cloud ACK cluster nodes, intelligent computing servers, and self-managed Kubernetes clusters): Hosts and Container Protection.

      • Other assets: Comprehensive Host Protection.

      • Newly added servers: Hosts and Container Protection.

      1. On the purchase page, click Custom Quota Binding and select the server region.

      2. Select the servers from the list and choose the corresponding protection level in the Protection Level column.

        After selecting multiple servers, click Change Protection Level to batch modify the protection level.

      3. In the Automatically Add New Servers to Security Center section, set the default protection level for newly added servers.

    • Serverless Assets: Supports custom binding of assets. Steps:

      Important

      If not configured, the system enables Serverless Assets protection for all Serverless assets by default.

      1. Click Custom Quota Binding, select the server region, and check the corresponding assets.

      2. Select Automatically Add New Assets to automatically enable Serverless Assets protection for newly added Serverless assets.

        Warning

        If not selected, you must manually bind the authorization; otherwise, newly added Serverless assets will not receive Security Center protection. For details, see Bind or Unbind Authorized Assets.

    • Application Protection: Supports custom binding of assets. Steps:

      Important
      • If not configured, the system enables full protection with slow-rate connection by default.

      • Configure this after purchase in the console under Application Protection > Application Configurations, in the Access Management section.

      1. Click Custom Quota Binding and select the server region.

      2. Select the corresponding assets and click OK.

  4. Confirm and pay

    Read and accept the Security Center Terms of Service, then click Order Now to complete payment.

  5. Verify purchased services

    After purchase, log on to the console. Navigate to the Overview page, Enable Pay-as-You-Go Service section to view your active services.

    Note

    Confirm the following to verify your purchase was successful:

    • Enabled services match your selections.

    • Assets are properly bound with the correct protection levels.

Purchase separately on dedicated pages

Agentic EDR

  • Description: Provides hosts with intelligent business profiling, behavior baseline establishment, baseline deviation alerts, intelligent detection/alert analysis, and automated response capabilities for streamlined security operations.

  • Purchase notes: Seat authorization is the billing unit. Each host binding consumes one seat authorization. The authorization model is consistent with add-ons such as Anti-Ransomware. For pricing details, see Agentic EDR - Subscription.

  • Purchase steps:

    Subscription
    1. Go to the Agentic EDR or buy page and complete the following configurations:

      • Intelligent Host Detection and Response: Select the number of regular authorization seats to purchase.

      • Duration: The service duration.

        Note

        We recommend that you select "Auto-renewal upon expiration" to avoid service interruption or resource release due to expiration. After you enable auto-renewal, the renewal cycle is monthly, and the system automatically deducts fees at the real-time price before the instance expires. You can cancel auto-renewal at any time. Configure or cancel auto-renewal.

    2. After the configuration is complete, click Buy Now.

    Pay-as-you-go
    1. Go to the Security Center console - Overview page.

    2. In the Enable Pay-as-You-Go Service section, turn on the Agentic EDR switch.

Attack Management

  • Description: Provides external attack surface management capabilities. Automatically discovers internet-exposed assets (domains, IPs, certificates), identifies attack paths and critical nodes, helping organizations understand their security exposure and reduce attack risk.

  • Purchase notes: Protected assets are the billing unit. Each asset authorization includes a certain amount of Credits for attack surface scanning.

    Important

    After enabling Full Protection, if you exceed the Credits included in the subscription plan, pay-as-you-go mode is automatically enabled for additional Credits. For pricing details, see Attack Surface Management - Hybrid Billing.

  • Purchase steps:

    Subscription
    1. Visit the Attack Surface Management purchase page and complete the following configuration:

      • Attack Surface Management edition: Only Basic Edition is currently supported.

      • Assets: The number of authorizations for protected assets. One asset consumes one authorization (includes 6,000 credits).

      • Duration: Service duration.

    2. After you complete the configuration, click Buy Now.

    Pay-as-you-go
    1. Visit the Attack Surface Management purchase page.

    2. Select the Pay-as-you-go billing method and click Create Now.

AgenticBAS (AgenticBAS)

  • Description: AI Penetration Testing (Agentic BAS) is an intelligent intrusion attack simulation based on multi-agent collaboration. It focuses on validating security effectiveness, continuously evaluating protection capabilities through intelligent means, and driving security operations improvements.

  • Purchase notes: AgenticBAS uses a hybrid billing model of subscription-based base service (monthly) plus pay-as-you-go Credits. After activation, 1 million Credits are included (expiring monthly). Once the monthly quota is exceeded, pay-as-you-go mode is automatically enabled.

    Important

    The pay-as-you-go mode for AgenticBAS cannot be turned off separately (not affected by the Burstable Protection toggle). It is automatically disabled upon subscription expiration or unsubscription.

  • Purchase steps:

    1. Visit the purchase page.

    2. Select the subscription duration, then click Buy Now to complete payment.

SecOpsAgent

  • Description: Security Operations Agent (SecOpsAgent) is an intelligent security operations service provided by Security Center. It enables you to complete daily security operations such as alert investigation and handling, vulnerability remediation, asset investigation, and report generation through natural language conversations.

  • Purchase notes: Subscription-based base service fee + overage Credits fee (pay-as-you-go). The base subscription includes 30,000 Credits (expiring monthly). Once the monthly quota is exceeded, pay-as-you-go mode is automatically enabled.

    Important

    The pay-as-you-go mode for AgenticBAS cannot be turned off separately (not affected by the Burstable Protection toggle). It is automatically disabled upon subscription expiration or unsubscription.

  • Purchase steps:

    1. Visit the Security Operations Agent subscription page.

    2. Complete the purchase configuration as follows.

      • Number of seats: Only one seat can be purchased.

      • Subscription duration: 1 month or 12 months.

        Note

        30,000 Credits are pre-allocated each month. Unused Credits expire at the end of the month and do not roll over.

    3. Review the relevant agreements, then click Buy Now to complete payment.

Enable elastic protection (enabled by default)

When you activate subscription-based services that support elastic protection, such as base edition services, Anti-Ransomware, Agentic EDR (Intelligent Host Detection and Response), and Attack Management, the system enables elastic protection by default. When the actual usage of a feature exceeds the subscription quota, the excess is automatically billed at pay-as-you-go rates. This eliminates the need for frequent manual scaling and ensures uninterrupted security protection. For more information, see Enable elastic protection,Disable elastic protection.

Important

Pay-as-you-go bills for excess usage are pushed the next day. For more billing details, see Billing overview.

Rules and limitations

Billing model limitations

  • Subscription: Each Alibaba Cloud account can purchase only one edition at a time. Upgrading to a higher edition is supported at any time.

  • Enable Pay-as-You-Go Service: Select different protection levels for different assets and purchase multiple add-on features simultaneously.

  • Switching billing models: To change the billing model for a feature, you must first unsubscribe from or disable the current billing service, then activate the other model.

Feature purchase and model limitations

  • Feature exclusivity

    • Subscription editions (Anti-virus, Advanced, Enterprise, Ultimate) and the pay-as-you-go Host and Container Security service are mutually exclusive. Select only one; they cannot be purchased or used simultaneously.

    • Subscription-based add-ons (such as Agentic SOC (Legacy)) and the same features under pay-as-you-go cannot be purchased or used simultaneously.

  • Cross-module flexibility

    A single account supports selecting different billing models across different feature modules.

    Note

    Example: Select subscription for Vulnerability Fix and pay-as-you-go for Agentic SOC.

Edition purchase limitations (container protection)

Servers running container environments (including ACK cluster nodes, self-managed Kubernetes, and Lingjun assets) require specific editions to access container protection capabilities. Edition limitations:

  • Subscription: You must purchase the Ultimate and bind the Ultimate to your assets.

  • Enable Pay-as-You-Go Service: You must purchase Host and Container Security and bind the Hosts and Container Protection protection level to your assets.

Edition change limitations

Effective September 11, 2025, Security Center will no longer support new purchases or changes to the Advanced Edition. Existing Advanced Edition users are not affected.

FAQ

Billing model questions

  • Will subscription and pay-as-you-go services be billed redundantly?

    No. Security Center has built-in anti-redundant billing mechanisms:

    • Single billing per feature: The same feature supports only one billing model at any time. See Feature purchase and model limitations.

    • Automatic switching: If the edition services included in your subscription purchase overlap with existing pay-as-you-go services, the system automatically disables the overlapping pay-as-you-go features and uses the subscription service instead.

      Note

      Example: If you have pay-as-you-go Vulnerability Fix and then purchase the Advanced Edition or above, Security Center automatically disables pay-as-you-go Vulnerability Fix, and subsequent vulnerability fixes will not incur additional charges.

  • Can pay-as-you-go services be converted to subscription?

    No. Pay-as-you-go services cannot be directly converted to subscription. Disable the relevant services first, then follow the Subscription - Step 2: Configure and pay on the purchase page to purchase a new subscription.

  • Can subscription and pay-as-you-go be used simultaneously?

    Yes. Both billing models can be used under a single account. Combine them based on asset importance and lifecycle.

  • Why am I still being charged after the trial resource package is exhausted?

    The trial resource package covers only specific billing items and quotas. After the package is exhausted, the corresponding pay-as-you-go features continue to run and incur charges. To avoid unexpected charges, we recommend:

    • Regularly check remaining package quota: Log on to the resource package management page to check remaining quota and expiration time.

    • Disable pay-as-you-go services promptly if no longer needed after the package is exhausted; see Disable pay-as-you-go services.

    • Set spending alerts: Configure budget alerts in the Billing Center to receive SMS, email, or in-site notifications when your account balance falls below a threshold.

  • How do I view Security Center bills?

    View Security Center billing details as follows:

    1. Log on to the billing details page.

    2. In the filter conditions, set Product Name to Security Center to view usage and costs for each billing item.

    For bills with multiple products, check resource package consumption on the resource package management page; see Query Resource Package Usage.

  • Why is the actual amount on the purchase page higher than the product pricing?

    The final order amount depends on multiple factors. The base price typically refers to the cost for a single server per month. The total is affected by:

    • Number of protected assets: The final cost is multiplied by the total number of protected servers under your account (including cloud ECS and non-cloud servers with the agent installed).

    • Add-on selections: The system may preselect add-ons such as Log Analysis and Anti-Ransomware. If not needed, set their capacity to 0 before placing your order.

  • Why does the console show more instances than my ECS instances?

    The total instance count shown in the Security Center console consists of two parts:

    • Pay-as-you-go instances: Protected assets that have pay-as-you-go services enabled.

    • Resource package instances: Billing instances for resource packages such as Vulnerability Fix, basic service, virus protection, and cloud security posture management (CSPM).

    A resource package is how these features are metered. It is a billing unit, not a standalone server instance. On the Overview page, in the Enable Pay-as-You-Go Service area, features such as Vulnerability Fix, cloud security posture management (CSPM), and Anti-Ransomware appear as service switches rather than as individual server instances. A total instance count higher than the number of ECS instances in your account is therefore expected and does not indicate redundant billing.

    Resource package instances do not need to be, and cannot be, deleted; the resource package management page provides no delete option. To cancel a resource package, go to the resource refund page in the Billing Center and unsubscribe from the corresponding resource package order. After the unsubscription takes effect, products that were previously covered by the resource package switch to pay-as-you-go billing. If you no longer want to incur charges, also disable the relevant pay-as-you-go services; see Disable pay-as-you-go services.

Free services and trials

  • How do I get free services?

  • What is the difference between the Free Edition and the Enterprise Edition free trial?

    Feature

    Free Edition

    Enterprise Edition free trial

    Eligible accounts

    All Alibaba Cloud accounts that have completed real-name verification.

    Accounts that have not previously trialed or purchased the Enterprise Edition.

    Protection capabilities

    Provides permanent baseline security capabilities.

    Short-term access to the full features of the paid Enterprise Edition.

    Duration

    Permanent.

    7 days.

    Core capabilities

    Anomalous login detection, mining/DDoS trojan detection, mainstream vulnerability scanning, and more.

    All Enterprise Edition capabilities, including virus detection, advanced threat detection, vulnerability fixing, and more.

    Eligibility

    Automatically activated; no application required.

    One trial per account; cannot be repeated.

  • Can I cancel and reapply for the Enterprise Edition free trial?

    Yes. On the Overview page, click Release Trial to cancel the free trial. However, each Alibaba Cloud account has only one free trial opportunity. After cancellation, you cannot apply again.

  • Are configurations retained after the Enterprise Edition free trial expires?

    After the trial expires, configurations and data are retained for 7 days and then automatically cleared.

  • Why is there no "Free Trial" entry on the Overview page?

    • Reason 1: The account has already applied for the 7-day free trial.

    • Reason 2: The account has already purchased a paid edition.