tencent cloud

Anti-DDoS

Attack FAQs

Download
Focus Mode
Font Size
Last updated: 2026-09-22 11:33:07
AI-Translated
Note:
Customers onboarded after September 10, 2026 are subject to the following instructions. If you are an existing Anti-DDoS Pro or Anti-DDoS Advanced customer, see historical documentation.

Will Notifications Be Sent When a DDoS Attack Occurs?

Yes. When a resource is under a DDoS attack, the system pushes an alarm notification.

Why Do Resources Not Exposed to the Internet Still Suffer DDoS Attacks?

A DDoS attack is a type of attack in which attackers use a large number of zombie hosts to launch attacks simultaneously, with the goal of disrupting access for legitimate users. The attack target is usually your resource IP address or domain name, rather than a specific usage scenario.
A resource is at risk of DDoS attacks as long as it has public network access or exposes an IP address or domain name, regardless of whether it actually carries business traffic.

Why Are Attacks Still Occurring After a DDoS Defender Plan Is Bound?

As long as a resource exposes public network access, it is at risk of being attacked. This risk cannot be completely eliminated by any protective measure.
The purpose of DDoS protection service is to keep your business unaffected and maintain normal access as much as possible during an attack, rather than preventing the attack itself from occurring.

What Are the Common Types of DDoS Attacks?

Network-layer (L3/4) attacks: Common types include UDP Flood, SYN Flood, TCP Flood, ICMP Flood, and DNS/NTP/SSDP reflection attacks, which consume server bandwidth or connection resources to render servers unable to provide normal services.
Application-layer (L7) CC attacks: Common types include HTTP/HTTPS Flood, which consume server processing performance to render servers unable to provide normal services.
For details, see the "Multi-layer Anti-DDoS protection" section in Product Overview.

Where Can I View Attack Logs and Attack Sources for Resources?

On the Attack Analysis page in the console, you can view the list and details of attack events, including attack source information, attack source region, attack traffic volume, and attack packet volume.

How Much Attack Traffic Is Required to Be Considered "Under Attack"?

As long as traffic is detected as containing attack characteristics, it is determined to be under attack, regardless of the traffic volume.

Why Can an IP Address Still Access the Business After Being Added to the Blocklist?

After an IP address is added to the blocklist, traffic from that source is not immediately limited. When traffic exceeds the cleaning threshold, an IP address in the blocklist is directly blocked only if it continues to send requests.

Can DDoS Protection Be Enabled for Only Some Resources?

Yes. You can associate cloud resources, EO domains, and EO Layer 4 proxy instances with protection instances individually as needed. Resources that are not associated are not affected by the protection instance.

Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback