Anti-Ransomware Security
Backup and DR (Immutable Protection)
Google Cloud Backup and DR (Immutable Protection) hardens backups against ransomware by combining a managed backup/appliance data plane with WORM-style retention locks, access isolation, and policy-driven scheduling. It positions immutability as a backup control enforced on the protected resource and backup copy, with retention that resists deletion or tampering for a defined period. Detection and response are typically delivered through adjacent security tooling rather than the backup service itself.
Google Cloud
Service information
Shortname: Immutable Backup
Huawei equivalent shortnames: HSS, CBR
Keywords: ransomware, immutable backup, security, protection
Differences vs Huawei
On Huawei Cloud, anti-ransomware posture is split across two services with separate control planes. CBR owns the backup data plane—server, disk, SFS Turbo, and database vaults with scheduled policies, cross-region replication, and backup locking (WORM) on vaults—while HSS owns the detection/prevention plane via an agent on each host with edition-gated ransomware blocking (Premium, Container, or Web Tamper Protection). Google's offering merges immutability and protection orchestration more tightly inside one backup product; Huawei requires explicit integration between CBR and HSS so a detection event can trigger or benefit from locked, isolated backups.
API and data-model boundaries differ materially. CBR exposes vault-centric backup APIs scoped to ECS, EVS, SFS Turbo, Workspace, and cloud databases, with immutability expressed as a vault-level backup lock rather than per-copy retention tags. HSS is billed and configured per device and edition, with ransomware prevention features only enabled at Premium and above; entry Basic/Professional editions lack ransomware blocking. Architects must therefore map GCP retention-lock policies to CBR backup lock configuration plus the correct HSS edition tier, not treat either service as a drop-in equivalent.
Scaling, HA, and operational responsibility diverge. CBR relies on multi-AZ redundancy and cross-region replication for remote copies, with Instant Restore for minute-level RTO; HSS depends on agent health and the chosen edition's detection coverage (claimed 99%+ of known ransomware families). Operational accountability is shared: backup operators own CBR vault/lock/replication policy, while security operators own HSS agent rollout, edition selection, alarm handling, and SecMaster correlation. There is no single console giving the unified immutable-protection view GCP's product presents.
Migration to Huawei
Start with an assessment that inventories GCP protected resources, retention-lock durations, scheduling, and any detection/response workflows tied to immutable copies. Decide target placement per workload type: ECS/backups map to CBR vaults (server, disk, SFS Turbo, or database backup vaults), host-level ransomware blocking maps to HSS Premium or Container edition per workload shape. Confirm required CBR vault locking and cross-region replication for the recovery RTO/RPO and retention period; do not assume feature parity until each control is verified.
Migrate configuration, not data directly. Rebuild backup policies in CBR matching GCP schedules, retention tiers, and lock durations using the backup-lock feature on target vaults. Deploy the HSS agent on every target ECS/BMS/container host and select the edition that enables ransomware prevention (Premium or higher; Container for CCE clusters). Establish triggering between HSS alarms and CBR backup actions if such automation fits the GCP source workflow, and configure SecMaster cross-service correlation where centralized detection/response was used on GCP.
Validate before cutover with restore drills: perform application-consistent restores from CBR backups into new ECS, confirm locked backups cannot be deleted before retention expires, and run ransomware-detection tests against representative hosts to confirm HSS blocking and isolation behavior. Replay alarm-to-backup workflows end-to-end. Cutover only after each protected workload has a verified restore path, locked-retention evidence, and HSS edition-confirmed detection coverage.
Account for cost-model and gap changes. CBR bills per vault capacity (USD/GB/month) plus replication traffic; HSS bills per device and edition, so total cost scales with both backup storage and protected-host count/edition—different from GCP's policy/protected-resource and request/scan volumetric model. Recalculate TCO with peak capacity, retention length, cross-region replication, and HSS edition tier. Document gaps the source service covered but Huawei does not (for example, certain source-side appliance features or GCP-specific retention-tag semantics) and address them with complementary Huawei services or runbook controls.
Huawei Cloud
Huawei equivalent service
Shortname: HSS
General function: Anti-Ransomware Security
Server host security detection and protection.
Keywords: host security, endpoint, protection
Huawei equivalent service
Shortname: CBR
General function: Backup and Recovery
Unified backup and recovery service.
Keywords: backup, recovery, snapshot