This topic describes the billing of burstable clean bandwidth for Anti-DDoS Proxy instances.
What is burstable clean bandwidth
The burstable clean bandwidth defines the maximum capacity of an Anti-DDoS Proxy instance to defend against DDoS attacks. You must set a burstable clean bandwidth that is greater than your basic protection bandwidth. If the burstable clean bandwidth equals the basic protection bandwidth, the feature is disabled for the instance, and no pay-as-you-go bills are generated.
Differences between basic protection bandwidth and burstable clean bandwidth
Basic protection bandwidth and burstable clean bandwidth work together to provide layered DDoS mitigation:
Basic protection bandwidth (also known as the basic mitigation threshold) is the baseline mitigation capacity that is always in effect for an Anti-DDoS Proxy instance. Basic protection bandwidth is billed on a subscription (prepaid) basis and does not expire or deplete based on individual attacks. Your instance continuously provides mitigation up to the basic protection bandwidth throughout the subscription period.
Burstable clean bandwidth is the extended mitigation ceiling that handles traffic bursts that exceed the basic protection bandwidth. Burstable clean bandwidth is billed on a pay-as-you-go (postpaid) basis per day. The burstable protection feature is triggered only when attack traffic exceeds the basic protection bandwidth but does not exceed the burstable clean bandwidth.
If attack traffic exceeds the burstable clean bandwidth, the instance cannot mitigate the attack, and the public IP address of the attacked asset enters a blackhole state. In this case, no burstable protection fees are incurred.
Basic protection bandwidth is not a one-time mitigation quota. It remains available for the entire subscription period. Burstable clean bandwidth is not unlimited automatic scaling. It defines a hard ceiling beyond which the instance enters blackhole status.
Supported instance types
Anti-DDoS Proxy (Chinese Mainland): Professional edition
Billing conditions
Burstable protection fees are incurred only when the peak inbound traffic to a protected public IP is greater than the basic protection bandwidth but less than or equal to the burstable clean bandwidth.
If the peak inbound traffic is less than or equal to the basic protection bandwidth or greater than the burstable clean bandwidth, the burstable protection feature is not triggered, and no costs are incurred.
If the peak inbound traffic exceeds the burstable clean bandwidth, the instance cannot mitigate the attack. As a result, the public IP of the attacked asset is routed to a blackhole. For more information, see Alibaba Cloud blackhole policy.
How costs are calculated
To determine the daily cost, first calculate the difference between the peak inbound traffic and the basic protection bandwidth. Then, find the corresponding pricing tier in the table below.
If burstable protection is triggered multiple times on a single day, the daily cost is based on the highest peak inbound traffic recorded for that day, regardless of the number of attacks.
Pricing tier | Burstable fee (Unit: USD/day) |
(0 Gbps, 5 Gbps] | 120 |
(5 Gbps, 10 Gbps] | 180 |
(10 Gbps, 20 Gbps] | 330 |
(20 Gbps, 30 Gbps] | 540 |
(30 Gbps, 40 Gbps] | 730 |
(40 Gbps, 50 Gbps] | 960 |
(50 Gbps, 60 Gbps] | 1,170 |
(60 Gbps, 70 Gbps] | 1,380 |
(70 Gbps, 80 Gbps] | 1,590 |
(80 Gbps, 100 Gbps] | 1,770 |
(100 Gbps, 150 Gbps] | 2,190 |
(150 Gbps, 200 Gbps] | 3,240 |
(200 Gbps, 300 Gbps] | 4,200 |
(300 Gbps, 400 Gbps] | 6,000 |
(400 Gbps, 500 Gbps] | 7,510 |
(500 Gbps, 600 Gbps] | 9,010 |
(600 Gbps, 700 Gbps] | 10,510 |
(700 Gbps, 800 Gbps] | 12,010 |
(800 Gbps, 900 Gbps] | 13,510 |
(900 Gbps, 1000 Gbps] | 15,010 |
(1000 Gbps, 1100 Gbps] | 16,510 |
(1100 Gbps, 1200 Gbps] | 18,010 |
(1200 Gbps, 1300 Gbps] | 19,510 |
(1300 Gbps, 1400 Gbps] | 21,010 |
(1400 Gbps, 2000 Gbps] | 22,520 |
Billing cycle
This pay-as-you-go service is billed daily. The bill for each day is generated the following day between 08:00 and 09:00 (UTC+8).
Billing example
Assume you have an Anti-DDoS Proxy instance with a basic protection bandwidth of 30 Gbps and a burstable clean bandwidth of 100 Gbps. On a given day, four DDoS attacks target the instance with the following peak inbound traffic: 20 Gbps, 80 Gbps, 40 Gbps, and 120 Gbps.
Cost analysis:
Peak inbound traffic is 20 Gbps: This is less than or equal to the 30 Gbps basic protection bandwidth. Burstable protection is not triggered, so no cost is incurred.
Peak inbound traffic is 80 Gbps: This is greater than the 30 Gbps basic protection bandwidth and less than or equal to the 100 Gbps burstable clean bandwidth. Burstable protection is triggered, and costs are incurred.
Peak inbound traffic is 40 Gbps: This is greater than the 30 Gbps basic protection bandwidth and less than or equal to the 100 Gbps burstable clean bandwidth. Burstable protection is triggered, and costs are incurred.
Peak inbound traffic is 120 Gbps: This exceeds the 100 Gbps burstable clean bandwidth. The instance cannot mitigate the attack, and the public IP is routed to a blackhole. Burstable protection is not triggered, so no cost is incurred.
Calculation: The daily cost is based on the highest peak inbound traffic that triggered burstable protection, which is 80 Gbps. The billable bandwidth is the peak traffic minus the basic protection bandwidth (80 Gbps - 30 Gbps = 50 Gbps). This falls into the (40 Gbps, 50 Gbps] pricing tier. Therefore, the total cost for the day is USD 960.
Enable burstable clean bandwidth
During purchase
Go to the Anti-DDoS Proxy (Chinese Mainland) buy page. When you purchase an instance, configure the burstable clean bandwidth. Make sure that the burstable clean bandwidth is greater than the basic protection bandwidth.
The basic protection bandwidth is billed on a subscription basis. The burstable clean bandwidth is the maximum protection capacity. If the burstable clean bandwidth is the same as the basic protection bandwidth, no pay-as-you-go fees are generated. If it is greater, any usage beyond the basic protection bandwidth is billed on a pay-as-you-go basis.
After purchase
Log on to the Instances page in the Anti-DDoS Proxy console.
On the Instances page, in the Protection Bandwidth: section, modify the burstable clean bandwidth. Make sure that the burstable clean bandwidth is greater than the basic protection bandwidth.
FAQ
How do I choose a DDoS mitigation plan and evaluate burstable protection requirements based on current attack traffic?
When you evaluate DDoS mitigation plans and assess whether to enable burstable protection, we recommend the following approach:
Start with a basic protection bandwidth plan. Purchase an Anti-DDoS Proxy instance with a basic protection bandwidth that covers your typical attack traffic volume. The basic protection bandwidth provides continuous mitigation on a subscription basis.
Enable burstable clean bandwidth to handle traffic spikes. If your business may experience sudden attack surges that exceed the basic protection bandwidth, enable burstable clean bandwidth to extend the mitigation ceiling. Burstable protection incurs additional pay-as-you-go fees based on the peak traffic that exceeds the basic protection bandwidth, so evaluate the potential costs against your budget.
Upgrade if attacks consistently exceed the burstable clean bandwidth. If attack traffic frequently exceeds the burstable clean bandwidth and triggers blackhole status, consider upgrading to a higher basic protection bandwidth tier or increasing the burstable clean bandwidth to maintain service availability.
What do I do if high traffic persists after I adjust the bandwidth and restrict suspicious IP addresses?
If you still observe excessive traffic after adjusting bandwidth settings and restricting suspicious IP addresses, follow these steps:
Verify whether the traffic is legitimate business traffic. Check whether the traffic spike is caused by a genuine increase in business traffic rather than an attack. You can analyze traffic patterns on the monitoring page of the Anti-DDoS Proxy console to distinguish between normal traffic growth and attack traffic.
Upgrade bandwidth specifications for legitimate traffic growth. If the traffic is confirmed to be legitimate business traffic, upgrade the basic protection bandwidth or burstable clean bandwidth to accommodate the increased traffic volume.
Use Web Application Firewall (WAF) for application-layer attacks. If you suspect the traffic is caused by application-layer (L7) attacks such as HTTP flood attacks, consider using the pay-as-you-go edition of Web Application Firewall (WAF) for testing and mitigation. WAF can identify and block malicious requests at the application layer, which complements the network- and transport-layer (L3/L4) mitigation provided by Anti-DDoS Proxy.