After adding your assets to an Anti-DDoS Native instance for protection, you can go to the Attack Analysis page to query the records and details of DDoS attack events on those assets. This provides a transparent view of the protection process and improves your ability to analyze attacks. This topic describes how to view attack event details.
Prerequisites
The assets to be protected are added to the Anti-DDoS Native instance.
Procedure
Log on to the Traffic Security console. In the left-side navigation pane, choose DDoS.
In the left-side navigation pane, choose .
On the Attack Analysis page, select a time range and query for attack records.
NoteIf you enabled multi-account management and are using a management account, you can also select an account scope.
All accounts: View DDoS attack events against public IP assets under the management account and member accounts. The public IP assets must be added as objects for protection for instances of the management account.
Single member account: View DDoS attack events on the public IP assets of the member account. The public IP assets must be added as objects for protection to an instance of the management account.
For more information about the multi-account management feature, see Multi-account management.
You can query attack events that occurred in the last six months.
Attack Types: Only Volumetric Attack is supported.
Attack Target: The asset that was attacked.
Start / End Time: The start and end time of the attack.
Owner Account of Event: The Alibaba Cloud account to which the asset belongs.
Peak Attack Throughput: The peak bandwidth of attack traffic in bps and the peak packet forwarding rate in pps.
View the details of an attack event.
Find an attack event and click View Details in the Actions column. On the Event Details page, you can view detailed information about the event and perform related operations.
The Event Details page contains the following information:
The top of the page displays the Attack Time, Attack Target, Attack Traffic Peak in bit/s, and Scrubbing Traffic Peak in bit/s.
Attack Traffic Peak in bit/s indicates the peak bandwidth (in bps) and packet forwarding rate (in pps) of the attack detected by the Anti-DDoS Native instance. Scrubbing Traffic Peak in bit/s indicates the peak bandwidth (in bps) and packet forwarding rate (in pps) of the traffic scrubbed by the Anti-DDoS Native instance.
Attack Mitigation Details: This section displays time-series charts that show the bandwidth trends (in bps) of inbound traffic and scrubbed traffic, and the packet forwarding rate trends (in pps) of inbound packets and scrubbed packets during the attack.
Source IP Addresses (Top 10): This section displays a list of source IP addresses and their locations. The list shows the top 10 source IPs. Click More to view the top 100 source IPs.
NoteThis data includes both attack requests and normal service requests.
Source Ports (Top 10): This section lists the top 10 source ports and their associated protocols. Click More to view the top 100 source ports.
NoteThis data includes both attack requests and normal service requests.
Attack Target Ports: Displays a distribution chart of destination ports for requests. Click More to view the percentage of requests for each destination port.
NoteThis data includes both attack requests and normal service requests.
Attack Source Locations: This section displays a chart that shows the distribution of attack source locations. Click More to view the request percentage for different source locations.
Attack Type: This section displays a chart that shows the distribution of attack types. Click More to view the request percentage for different attack types.
Attack Source ISPs: This section displays a chart that shows the distribution of attack source ISPs. Click More to view the request percentage for different ISPs.