Viewing Statistics Reports

Last updated: 2020-02-27 15:28:32

PDF

When users receive DDoS attack reminders or find business anomalies, they need to quickly understand the attack, including the size of Traffic, the current protection effect, and so on. After mastering enough information, they can adopt more effective processing methods to ensure normal business for the first time.
The statistical reports of the DDoS High Defense IP Management console provide a wealth of information to help users quickly understand the current business or attacks.

Check the protection against DDoS attacks

  1. Login DDoS Protection Management console .
  2. Navigate to [DDoS High Defense IP] > [Statistical report].
  3. On the * * DDoS attack Protection * * tab, set the query time range, select the region and route, and select the destination instance and high defense IP, to check whether there is an attack.

Support querying attack Traffic information and DDoS attacks within a maximum of 180 days.

  • View the attacks on the selected high-defense IP within this time frame, including the network Attack Traffic bandwidth / attack packet rate Trends. When attacked, the peak of the attack on Traffic can be clearly seen in the Traffic trend chart.
  • The attack distribution under these three data dimensions is viewed through the attack Traffic Protocol distribution, the attack packet Protocol distribution and the attack type distribution.
    • Attack Traffic Protocol distribution Check the proportion of Protocol's total attack Traffic in the selected high defense IP attacks within this time range.
    • Protocol distribution of attack packet View the proportion of the total number of Protocol attack packets in the selected high defense IP attack events within this time range.
    • Attack type distribution Check the percentage of the total number of attacks suffered by the selected high-defense IP in this time range.
      • Distribution of attack sources: check the domestic and global distribution of attack sources of DDoS attacks within this time range in the "attack Source Distribution" area, so as to facilitate users to clearly understand the attack sources and provide a basis for further protective measures.
  • Check the DDoS attacks suffered within this time range in the [DDoS attack record] area to learn about the attack (start) time, duration, attack type and attack status of each attack event.
    • Support attack package download for DDoS attack analysis and traceability support.
    • Click "attack details" to learn about the maximum packet rate, maximum attack Traffic bandwidth and total cleaning Traffic in DDoS attacks.
    • Click * * attack Source Information * * to view the attack source IP address, source region, attack Traffic generated and attack packet size within this time range.

The attack source information is sampled data, that is, random packet capture statistics, and the data will not be displayed until about 2 hours after the end of the attack.

Check the protection against CC attacks

  1. Login DDoS Protection Management console .

  2. Select [DDoS High Defense IP] > [Statistical report].

  3. Click the * * CC attack Protection * * tab, set the query time range, select the region and line, and select the destination instance and high defense IP, to check whether there is a CC attack.

    You can query the number of attack requests and CC attacks within 180 days at most.

    • users can select [Today] to view the trend of attack requests for the selected high defense IP. Observe whether the total request value is much higher than the normal business visit (QPS), and check whether the attack QPS has a value and the value is too large.
    • if there is a CC attack, the system records the start time, end time, attacked domain name, attacked url, total request peak, attack request peak and attack source of the attack.
      • Peak total request:count the peak of total request traffic received by High Defense IP when attacked.
      • Peak attack request: count the peak number of requests blocked by the high defense system when an attack occurs.

Check the situation of Traffic in the business.

  1. Login DDoS Protection Management console .
  2. Select [DDoS High Defense IP] > [Statistical report].
  3. Click the * * Business * * tab, set the query time range, select the region and line, and select the destination instance and high defense IP, to view the values within the selected time range. Traffic bandwidth trend of inbound / outbound businessTrend of inbound / outbound packet rate And The trend of the number of Create connections or Concurrence connections . At the same time, you can also view the peak bandwidth of Traffic in the inbound / outbound direction and the peak packet rate in the inbound / outbound direction.
    • Concurrent connections The number of established full connections that the system has in a point in time.
    • New public network connections The number of TCP connections established by the system in 1 second.

You can query business information within 180 days at most.