Anti-Ransomware Security
AWS Backup Vault Lock
AWS Backup Vault Lock enforces immutable, WORM-style retention on a backup vault so that recovery points cannot be deleted or modified by any user, including root, for the lock's retention period. It is a control-plane compliance guardrail layered on AWS Backup's data plane, decoupled from host-level detection, and is configured per vault via lock mode, retention window, and minimum retention parameters.
AWS
Service information
Shortname: Vault Lock
Huawei equivalent shortnames: HSS, CBR
Keywords: ransomware, immutable backup, security, protection
Differences vs Huawei
Huawei splits the AWS Backup Vault Lock concept across two services with separate control planes. CBR owns the backup data plane and now offers vault backup locking (WORM) plus access isolation to prevent deletion or tampering of recovery points, the closest analog to Vault Lock's immutability guardrail. HSS (Premium edition and above) owns host-level ransomware detection, dynamic honeypots, and process blocking. Unlike AWS Backup Vault Lock, which is a pure retention/compliance control independent of workload type, CBR's lock is bound to CBR vaults (ECS, EVS, SFS Turbo, Workspace) and HSS's prevention is bound to protected hosts, so the WORM guarantee and threat surface are enforced at different layers and over different scopes.
API and operational models differ materially. AWS exposes Vault Lock through the AWS Backup API (PutBackupVaultLockConfiguration, retention parameters) as a declarative, account-scoped compliance setting; immutability is enforced service-side regardless of client. Huawei CBR exposes backup locking as a vault-level feature and ransomware response as HSS-triggered automatic backups, coupling the immutability control to a detection workflow rather than a standalone declarative policy. There is no documented single API that mirrors AWS's compliance-only lock semantics, and cross-region replication in CBR provides physical isolation but is not equivalent to AWS's compliance-mode legal-hold/retention guarantees.
Scaling, integration, and cost attribution diverge. AWS Backup Vault Lock scales with AWS Backup's multi-service, multi-account (AWS Organizations) backup fabric and is billed on protected storage and backup jobs. HSS is billed per protected device per edition (Basic to Web Tamper Protection), regardless of backup volume, while CBR is billed per GB/month of vault storage plus cross-region replication traffic. For customers, the immutable-retention cost therefore follows different units and a migration must recompute TCO on devices plus storage rather than on backup vault size alone, and operational responsibility for prevention remains on the HSS agent side rather than the backup service.
Migration to Huawei
Start with assessment and target decomposition: inventory every AWS Backup Vault Lock policy (lock mode, min/max retention, legal holds) and the resources governed by it, then map the immutability requirement to CBR backup locking and the anti-ransomware workflow to HSS Premium or higher. Confirm per workload that CBR supports the resource type (ECS, EVS, SFS Turbo, Workspace desktops, supported databases), because AWS Backup covers a broader set of independent backup plans; resources outside CBR's scope will need an alternate Huawei backup or will not receive a Vault Lock-equivalent guarantee.
Rebuild policy on the target: enable CBR backup locking on target vaults to approximate WORM retention, configure CBR backup policies (period and retention) to match the original retention envelope, and enable HSS ransomware prevention with automatic CBR backup triggering so detection drives capture. Note that HSS+CBR is a coupled detection-to-backup pattern, not a one-click conversion of AWS Vault Lock; you must explicitly set the lock parameters on each CBR vault and verify the WORM behavior, including whether retention tuning and unlock paths match AWS compliance-mode expectations.
Validate and cut over with restore drills: run periodic recovery drills from locked CBR backups to confirm immutability prevents both accidental and malicious deletion, and test cross-region replication for physical isolation. Because Huawei's prevention response depends on the HSS agent being healthy on each host, include agent-failure and detection-latency scenarios in the test plan; AWS Vault Lock by contrast is agentless and purely retention-driven, so document this operational dependency as a residual risk and brief operators on the different failure modes.
Close gaps and recalibrate cost: services such as SecMaster can aggregate HSS alerts, CBR events, and governance, but do not substitute for Vault Lock's compliance guarantee. Recompute TCO using HSS edition price per device, CBR vault capacity and storage tier, and cross-region replication traffic at peak, since AWS's storage-and-job pricing model does not map line-for-line to Huawei's per-device plus per-GB model. Retain legal/compliance sign-off that CBR backup locking satisfies the specific regulatory immutability requirement that AWS Backup Vault Lock was selected to meet, as feature parity at the control-plane level is not formally documented.
Huawei Cloud
Huawei equivalent service
Shortname: HSS
General function: Anti-Ransomware Security
Server host security detection and protection.
Keywords: host security, endpoint, protection
Huawei equivalent service
Shortname: CBR
General function: Backup and Recovery
Unified backup and recovery service.
Keywords: backup, recovery, snapshot