All Products
Search
Document Center

Anti-DDoS:Security overview

Last Updated:Jun 25, 2026

This topic describes how to view service data and DDoS attack details for your instances and domain names in the Anti-DDoS Proxy console after adding your services to Anti-DDoS Proxy. This helps you quickly understand the DDoS protection status of your assets so you can adjust your DDoS protection policies accordingly.

Overview

Anti-DDoS Proxy allows you to view data from the last 30 days. On the Security Overview page, you can click Traffic Relationships and Description in the upper-right corner to understand the key traffic concepts of Anti-DDoS Proxy.

Prerequisites

Protection overview for instances

Anti-DDoS Proxy displays service information and DDoS attack details for each instance.

  1. Log on to the Anti-DDoS Proxy console.

  2. In the top navigation bar, select the region of your instance.

    • Anti-DDoS Proxy (Chinese Mainland): Choose the Chinese Mainland region.

    • Anti-DDoS Proxy (Outside Chinese Mainland): Choose the Outside Chinese Mainland region.

  3. In the left-side navigation pane, click Security Overview. On the Security Overview page, click the Instance tab to view the following information.

    Feature

    Description

    Bandwidth

    • Anti-DDoS Proxy (Chinese Mainland): Provides a Bandwidth trend chart that displays the trends of inbound traffic, outbound traffic, attack traffic, and throttling traffic on an instance within a specified time period in bps or pps.

    • Anti-DDoS Proxy (Outside Chinese Mainland) provides three tabs: Overview (same as the bandwidth trend chart), Inbound Traffic Distribution (distribution of inbound traffic), and Outbound Traffic Distribution (distribution of outbound traffic).

    Connections

    • Concurrent Connections: The number of TCP connections established between clients and Anti-DDoS Proxy at the same time.

      • Active connection: The number of TCP connections that are in the Established state.

      • Inactive connection: The number of TCP connections that are in any state other than Established.

    • New Connections: The number of new TCP connections established per second between clients and Anti-DDoS Proxy.

    Network Layer Attack Events, Alert on Exceeded Upper Limits, and Destination Rate Limit Events

    • Network Layer Attack Events:

      Hover over an attacked IP address or port to view details, such as the attack type, peak, and mitigation result.

    • Alerts on Exceeded Upper Limits:

      Event types include service bandwidth, new connections, and concurrent connections. An alert is triggered if a metric exceeds the limits of your plan. Although this does not affect your services, we recommend upgrading your instance. For more information, see Upgrade an instance.

      You can click Details in the Status column to go to the System Logs page for more information.

      Note

      Data for these alerts, which covers the previous day, is updated every Monday at 10:00 (GMT+8). If you have configured notifications, you receive them at the same time.

    • Destination Rate Limit Events

      When metrics such as new connections, concurrent connections, or service bandwidth significantly exceed the instance's specifications, a rate-limiting policy is triggered. This affects your service and generates a destination rate limit event.

      • If rate limiting is triggered by normal service traffic, upgrade your instance as soon as possible. For more information, see Upgrade an instance.

      • If rate limiting is triggered by a DDoS attack, promptly adjust your protection policies. For more information, see Protection settings.

      You can click Details in the Status column to go to the System Logs page for more information.

    Service Distribution by Location and Service Distribution by ISP

    • Service Distribution by Location: The distribution of source regions for normal service traffic.

    • Service Distribution by ISP: The distribution of Internet Service Providers (ISPs) for normal service traffic.

Protection overview for domain names

Anti-DDoS Proxy displays service information and DDoS attack event details for each domain name.

  1. Log on to the Anti-DDoS Proxy console.

  2. In the top navigation bar, select the region of your instance.

    • Anti-DDoS Proxy (Chinese Mainland): Choose the Chinese Mainland region.

    • Anti-DDoS Proxy (Outside Chinese Mainland): Choose the Outside Chinese Mainland region.

  3. In the left-side navigation pane, click Security Overview. On the Security Overview page, click the Websites tab to view the following information.

    • Viewing total QPS by instance

      In the All Domain Names drop-down list, click Total QPS by Instance, select the exclusive IP addresses, and then click OK.

      Feature

      Description

      Request Rate (QPS)

      Displays the request rate trend for each Anti-DDoS Proxy instance. The time granularity varies based on the specified time range.

      Status Codes and Requests

      Displays the cumulative count of response codes that the Anti-DDoS Proxy instance returned in each time interval.

      • 2XX: The request was successfully received, understood, and accepted by the server.

        Note

        The 2XX category includes all response codes from 200 to 299.

      • 3XX: The client must take further action to complete the request. These status codes are usually used for redirection.

      • 4XX: An error may have occurred on the client that prevents the server from processing the request.

      • 5XX: An error or exception occurred while the server was processing the request.

    • Viewing QPS by domain name

      In the All Domain Names drop-down list, click QPS by Domain, select the domain names, and then click OK.

      Feature

      Description

      Request Rate (QPS)

      Displays the request rate trend for each domain name. The time granularity varies based on the specified time range.

      Bandwidth

      Displays the trend of peak inbound and outbound bandwidth for the domain name.

      Note

      Only the payload field is counted. This may cause a deviation from the instance-level bps trend chart.

      Status Codes and Requests

      Includes response codes from both Anti-DDoS Proxy and the origin server. The recorded count is the cumulative value within each time-granularity interval. The following list describes the response codes:

      • 2XX: The request was successfully received, understood, and accepted by the server.

        Note

        2XX includes all status codes from 200 to 299.

      • 200: The request succeeded.

      • 3XX: The client must take further action to complete the request. These status codes are usually used for redirection.

      • 4XX: An error may have occurred on the client that prevents the server from processing the request.

        Note

        4XX includes all status codes from 400 to 499.

      • 403: The server understood the client's request but refused to fulfill it.

      • 404: The server could not find the resource requested by the client.

      • 405: The server understood the resource path of the client's request, but the HTTP method used in the request, such as GET, POST, PUT, or DELETE, is not allowed for that resource.

      • 410: The requested resource has been permanently deleted from the server.

      • 499: The client canceled the request before the server finished processing it.

      • 5XX: An error or exception occurred while the server was processing the request.

        Note

        5XX includes all status codes from 500 to 599.

      • 502: Anti-DDoS Proxy, acting as a proxy server, received an invalid response from the upstream server when attempting to fulfill the request.

      • 503: The server is currently unable to handle the request, possibly due to temporary server maintenance or overload.

      • 504: Anti-DDoS Proxy, acting as a proxy server, did not receive a timely response from the upstream server when attempting to fulfill the request.

      URI Requests, URI Response Time, etc.

      Displays the top 5 data for the corresponding metrics. You can click More to view more data. The metrics include URI request count, URI response time, User-Agent, Referer, HTTP-Method, client TLS fingerprint, HTTP/2.0 fingerprint, JA3 fingerprint, and JA4 fingerprint. For more information about each metric, see Appendix 1: Supported HTTP request fields.

      Note

      URI Response Time is the time, in milliseconds, from when Anti-DDoS Proxy receives a request until it returns a response. The value shown is the maximum response time recorded for a URI within the selected time period.

      Application Layer Scrubbing Events

      Hover over a domain name to view attack details, such as the attack peak and type.

      Source Location

      The distribution of access source regions.

      Cache Hit Ratio

      This metric is available only if the static page cache feature is enabled. For more information, see DDoS Protection Lab.

Set an alert threshold

To prevent excessive alerts during high-volume DDoS attacks, Anti-DDoS Proxy's default policy generates an alert only when inbound traffic is 500 Mbps or higher and scrubbing traffic exceeds 100 Mbps. If your service has low traffic, you can set a custom alert threshold to receive notifications for attacks that fall below the default limits. This can resolve issues where you see scrubbing traffic in the console but no corresponding attack event is generated.

  1. Log on to the Anti-DDoS Proxy console.

  2. In the top navigation bar, select the region of your instance.

    • Anti-DDoS Proxy (Chinese Mainland): Choose the Chinese Mainland region.

    • Anti-DDoS Proxy (Outside Chinese Mainland): Choose the Outside Chinese Mainland region.

  3. In the left-side navigation pane, click Security Overview. In the Set Alert Threshold area of the Security Overview page, configure a custom attack alert threshold.

    In the Set Alert Threshold dialog box, set Attack Type to DDoS High-Volume Attack. For Alert Threshold, select Default or Inbound Bandwidth. If you select Inbound Bandwidth, enter a threshold from 100 to 10,000 Mbps.

    • The threshold applies to the total inbound bandwidth received by a single IP address of the Anti-DDoS Proxy instance.

    • Inbound traffic includes both attack traffic and service traffic.

    • An alert event is generated when the inbound traffic is greater than or equal to the custom threshold and the scrubbing traffic is greater than 100 Mbps.

    • This setting applies to all IPv4 addresses of the Anti-DDoS Proxy instance. You cannot set a custom threshold for IPv6 addresses.