tencent cloud

Feedback

Protection Overview

Last updated: 2022-02-22 16:40:03

    Protection Overview

    The protection overview page of the Anti-DDoS console shows you complete, real-time indicators for basic protection, Anti-DDoS Pro, and Anti-DDoS Advanced applications, including the protection status and DDoS attack events, which can be used for analysis and source tracing.

    Viewing attack statistics

    1. Log in to the new Anti-DDoS console, and select Overview on the left sidebar to enter the Protection Overview page.
    2. In the "Attacks" module, you can view the application security status, the latest attack and the attack type. To obtain higher protection, you can click Upgrade Protection.
    3. This module also displays the details of the following data.

    Field description:

    • Attacked IPs: the total number of attacked application IPs of basic protection, Anti-DDoS Pro and Anti-DDoS Advanced.
    • Protected IPs: the total number of protected application IPs of Anti-DDoS Pro and Anti-DDoS Advanced.
    • Blocked IPs: the total number of blocked IPs of basic protection, Anti-DDoS Pro and Anti-DDoS Advanced.
    • Attacked domain names: the total number of domain names of attacked Anti-DDoS Advanced instances and ports.
    • Protected domain names: the number of domain names connected to Anti-DDoS Advanced instances.
    • Peak attack bandwidth: the maximum attack bandwidth of the current attack events.

    Viewing defense statistics

    1. Log in to the new Anti-DDoS console, and select Overview on the left sidebar to enter the Protection Overview page.
    2. In the "Defense" module, you can easily see the application IP security status.

    Field description:

    • Total IPs: the total number of application IPs, including IPs of basic protection, Anti-DDoS Pro and Anti-DDoS Advanced.
    • Protected IPs: the total number of protected application IPs of Anti-DDoS Pro and Anti-DDoS Advanced.
    • Blocked IPs: the total number of blocked IPs of basic protection, Anti-DDoS Pro and Anti-DDoS Advanced.
    1. This module also displays the total number of attacks on your applications, giving you a picture of the distribution of attacks.
    2. Meanwhile, this module provides recommended actions for the attacked IPs connected to basic protection, allowing you to quickly upgrade your Anti-DDoS service.

    Viewing instance statistics

    1. Log in to the new Anti-DDoS console, and select Overview on the left sidebar to enter the Protection Overview page.
    2. The "Anti-DDoS Instances" module visualizes the Anti-DDoS instance status data, providing an easy and complete way to know the distribution of insecure applications.

    Viewing recent events

    1. Log in to the new Anti-DDoS console, and select Overview on the left sidebar to enter the Protection Overview page.
    2. The "Recent Events" module shows you all the recent attack events. For attack analysis and source tracing, click View Details to enter the event details page.
    3. In the "Attack Information" module of the event details page, you can view the detailed attack information for the selected period, including the attacked IP, status, attack type (which is sampled data), peak attack bandwidth and attack packet rate, and attack start and end time.
    4. In the "Attack Trend" module of the event details page, you can view the trend of attack bandwidth and attack packet rate and easily find the peak spikes.
      Note:

      This module provides complete, real-time data in the attack period.


    5. In the "Attack Statistics" module of the event details page, you can view how attacks distribute over different attack traffic protocols and attack types.

    Note:

    This module provides sampled data in the attack period.


    Field description:

    • Attack traffic protocol distribution: displays how attacks on the selected Anti-DDoS Pro instance distribute over different attack traffic protocols within the queried period.
    • Attack type distribution: displays how attacks on the selected Anti-DDoS Pro instance distribute over different attack types within the queried period.
    1. The "Top 5" modules of the event details page displays the top 5 attacker IP addresses and the top 5 attacker regions, which is helpful to precise protection configuration.
      Note:

      This module provides sampled data in the attack period.


    7. In the "Attacker Information" module of the event details page, you can view the sampled data of the attack period, including the attacker IP, region, total attack traffic, and total attack packets.

    Note:

    This module provides sampled data in the attack period.

    Anti-DDoS Pro Overview

    After an IP address is bound to an Anti-DDoS Pro instance, when you receive a DDoS attack alarm message or notice any issue with your business, you need to view the attack details in the console, including the attack traffic and current protection effect. Enough information is critical for you to take measures to keep your business running smoothly.

    Viewing DDoS protection details

    1. Log in to the new Anti-DDoS console, select Overview on the left sidebar and then open the Anti-DDoS Pro tab.
    2. On the DDoS Attack tab, select a query period, target region, and an instance to check whether the instance has been attacked. The complete attack data is displayed by default.
      Note:

      You can query attack traffic and DDoS attack events in the past 180 days.


    2. View the information of attacks suffered by the selected Anti-DDoS Pro instance within the queried period, such as the trends of attack traffic bandwidth/attack packet rate.

    3. You can view the recent DDoS attacks in the Recent Events section.

    • Select an event and click View Details. You will see the attacker IP, source region, generated attack traffic, and attack packet size on the right, which can be used for attack and source analyses.
    • Select an event and click Packet Download. In the pop-up packet list, select an ID, and click Download to download the attack packet sample data, with which you can create a protection plan.
    1. In the Attack Statistics section, you can view how the attacks distribute across different attack traffic protocols, attack packet protocols, and attack types.

    Field description:

    • Attack traffic protocol distribution: displays how attacks on the selected Anti-DDoS Pro instance distribute over different attack traffic protocols within the queried period.
    • Attack packet protocol distribution: displays how the attacks suffered by the selected Anti-DDoS Pro instance distribute across different attack packet protocols within the queried period.
    • Attack type distribution: displays how attacks on the selected Anti-DDoS Pro instance distribute over different attack types within the queried period.
    1. In the attack source section, you can view the distribution of DDoS attack sources in and outside the Chinese mainland within the queried period, so that you can take further protective measures.

    Viewing CC protection details

    1. On the CC Protection tab, select a query period, target region, and an instance to check whether the instance has been attacked.
    2. You can select Today to view the following data to identify the impact of attacks on your business.

    Field description:

    • Total request rate: the rate of total traffic (in QPS).
    • Attack request rate: the rate of attack traffic (in QPS).
    • Total requests: the total number of requests received.
    • Attack requests: the number of attack requests received.
    1. You can view recent CC attacks in the Recent Events section. Click View Details on the right of an event to display the attack start and end time, attacked domain name, total request peak, attack request peak, and attacker IP. You can also check the attack information, attack trends, and detailed CC records.
    Contact Us

    Contact our sales team or business advisors to help your business.

    Technical Support

    Open a ticket if you're looking for further assistance. Our Ticket is 7x24 avaliable.

    7x24 Phone Support