This topic describes how to view DDoS attack events (scrubbing or blackhole) and related statistics for your Alibaba Cloud public IP assets.
Procedure
Log on to the Traffic Security console,In the left-side navigation pane, choose DDoS.
In the left-side navigation pane, click Event Center.
-
At the top of the page, set a time range for Attack Start Time. You can select a preset option, such as Last 30 Days, or specify a custom start and end date. The page contains the following sections:
-
Ongoing: Lists ongoing attacks and their protection status. If no attacks are in progress, this section displays the security status, the time of the last attack, and security recommendations.
-
Statistics: Shows the total number of events, blackhole events, and scrubbing events within the specified time range.
Use the following filters to refine the event list.
Filter
Description
Event Type
Filter by event type. Options: Scrubbing or Blackhole.
-
scrubbing: Traffic scrubbing is triggered when the traffic rate reaches the threshold in bits per second (bps) or packets per second (pps). For more information, see Cancel traffic scrubbing.
-
blackhole: A blackhole is triggered when traffic exceeds the maximum DDoS protection threshold of the asset's public IP address. For more information, see Alibaba Cloud blackhole policy.
Asset Type
Filter by asset type. Options: ECS, SLB, EIP, NAT, IPv6 gateway, simple application server, WAF, GA, and AnycastEIP.
Event status
Filter by event status. Options: In Progress or Ended.
IP Address
Enter the public IP address of an asset to search for related events.
The following table describes the columns in the event list.
Column
Description
Asset
Information about the asset under a DDoS attack, including its public IP address and instance ID.
Event
The attack type, such as volumetric, and the event type (scrubbing or blackhole).
Time
The start time, end time, and duration of the attack event.
Attack Metrics
The trigger value and peak value (bps/pps) of the attack event.
DDoS Plan
The Anti-DDoS package used by the asset.
-
-
(Optional) In the Actions column, click View Details to open the Event Details panel and view the following information:
-
Basic Information: Displays the target IP address, event type (scrubbing or blackhole) and status, attack type, Anti-DDoS package and protection capability assessment, trigger value (bps/pps), and start and end times. For scrubbing events, the attack peak value is also displayed.
-
Traffic: Displays a trend graph of traffic during the attack event.
Note-
If an asset has been released, the message You cannot view traffic details because the asset is removed from the current account. appears.
-
Trend graphs are not available for attack events that occurred more than 7 days ago (for IPv4 assets) or 3 hours ago (for IPv6 assets).
-
Trend graphs in event details are not supported for AnycastEIP assets.
-
-
Mitigate: Displays the mitigation result for the attack event.
-
For blackhole events: This section shows the blackhole duration and the blackhole threshold for Anti-DDoS Basic. You can click Upgrade Anti-DDoS Plan to increase your protection capability.
-
For scrubbing events: This section shows the attack duration, peak scrubbing bandwidth, and mitigation result.
-
-
Attack Event Analysis: Provides an AI-generated analysis (for reference only) that includes a summary of the attack type, an explanation of its principles, and protection suggestions. Use this analysis to understand attack characteristics and develop targeted protection strategies.
-
FAQ
Do multiple attack events belong to the same attack?
The DDoS platform treats each attack, from start to finish, as a separate event. Events are recorded individually, regardless of the time interval between them.
How can I determine if multiple attack events are part of the same attack wave?
Download the pcap files for each event and compare the destination ports and attack types, such as SYN Flood and NTP reflection attacks. If the attack types are identical, the events are likely part of the same attack wave.