This topic describes the release notes for Anti-DDoS Pro, Anti-DDoS Premium, and Anti-DDoS Origin and provides links to the relevant references.

2022

Release dateApplicable serviceFeatureDescriptionReferences
2022-04-27Anti-DDoS Pro and Anti-DDoS PremiumProvisioningNew SSL cipher suites are provided for Anti-DDoS Pro and Anti-DDoS Premium instances that use the Standard function plan. The new SSL cipher suites do not use weak encryption algorithms. This enhances security. Configure a custom TLS security policy
2022-04-15Anti-DDoS ProProvisioningAnti-DDoS Pro instances allow you to add IPv6 services and forward IPv6 service traffic. The instances also support intelligent protection and custom protection for IPv6 services. What are Anti-DDoS Pro and Anti-DDoS Premium?
2022-04-12Anti-DDoS ProProvisioningSM Certificates are supported for HTTPS services. This improves security compliance. Upload an HTTPS certificate
2022-03-17Anti-DDoS ProProvisioningAnti-DDoS Pro instances that support IPv6 are available for purchase. This type of instance can protect both IPv4 and IPv6 services. Purchase an Anti-DDoS Pro or Anti-DDoS Premium instance

2021

Release dateApplicable serviceFeatureDescriptionReferences
2021-12-29Anti-DDoS PremiumAssetsAn Anti-DDoS Premium instance of the Secure Chinese Mainland Acceleration (Sec-CMA) mitigation plan provides two advanced mitigation sessions free of charge per month. If the two advanced mitigation sessions are exhausted, you can purchase global advanced mitigation sessions to ensure service security. Purchase global advanced mitigation sessions
2021-11-12Anti-DDoS Pro and Anti-DDoS PremiumAssetsThe burstable clean bandwidth feature that is billed based on the 95th percentile bandwidth is supported. Bills are generated based on the actual usage of the burstable clean bandwidth. This helps reduce costs. Configure the burstable clean bandwidth feature
2021-10-18Anti-DDoS ProInvestigationOperation logs within the previous 180 days instead of 30 days can be queried. You can use the logs to track and analyze important operations. Query operation logs
2021-09-30Anti-DDoS Pro and Anti-DDoS PremiumProvisioningPorts in the range from port 80 to port 65535 can be added. This extends protection for services over different ports. Add a website
2021-09-30Anti-DDoS Pro and Anti-DDoS PremiumProvisioningOnline Certificate Status Protocol (OCSP) can be enabled when you add a domain name to Anti-DDoS Pro or Anti-DDoS Premium.

If you enable OCSP for an HTTPS service that is added to Anti-DDoS Pro or Anti-DDoS Premium, Anti-DDoS Pro or Anti-DDoS Premium runs OCSP queries and caches the query results. When a client initiates a Transport Layer Security (TLS) handshake with the origin server, Anti-DDoS Pro or Anti-DDoS Premium returns the OCSP details and the certificate chain to the client. This prevents the blocking issues that are caused by OCSP queries from the client and makes access to the HTTPS service more efficient.

Add a website
2021-09-17Anti-DDoS Pro and Anti-DDoS PremiumInvestigationThe details about connection flood attacks can be queried on the Attack Analysis tab.

You can query the details about connection flood attacks to obtain the trend of attack traffic and the details about traffic scrubbing. You can also view the rankings of the source IP addresses from which attacks are initiated and the distribution of source regions from which attacks originate. Then, you can optimize mitigation policies and track and analyze the attacks based on the details.

View information on the Attack Analysis page
2021-08-20Anti-DDoS Pro and Anti-DDoS PremiumProvisioningDescriptions can be configured for the added forwarding rules. This allows O&M personnel to locate the required services in an efficient manner when they manage protection policies. This makes O&M operations more efficient. Create forwarding rules
2021-08-20Anti-DDoS Pro and Anti-DDoS PremiumProvisioningThe origin redundancy feature is supported.

The origin redundancy feature allows you to configure primary and secondary origin servers. If an origin server is unavailable, you can switch to the other origin server with a few clicks. This way, the disaster recovery capabilities are improved when Anti-DDoS Pro or Anti-DDoS Premium forwards traffic to origin servers. This also ensures service availability.

Modify the back-to-origin settings for a port
2021-08-18Anti-DDoS Pro and Anti-DDoS PremiumInvestigationAttack analysis reports can be exported.

You can export the details about a DDoS attack event to your computer in the PNG or PDF format. This way, you can report and store the details about the attack event.

View information on the Attack Analysis page
2021-07-28Anti-DDoS Pro and Anti-DDoS PremiumInvestigationThe details about web resource exhaustion attacks can be queried on the Attack Analysis tab.

You can get an idea of the scrubbing capabilities of Anti-DDoS Pro or Anti-DDoS Premium, accurately evaluate the impacts of attacks on your services, and promptly adjust protection policies based on the details about the web resource exhaustion attacks.

View information on the Attack Analysis page
2021-07-10Anti-DDoS Pro and Anti-DDoS PremiumInvestigationLog collection can be enabled or disabled for multiple domain names on the Log Analysis page at a time. Quick start
2021-07-07Anti-DDoS Pro and Anti-DDoS PremiumSec-Traffic ManagerSwitch to DDoS is supported for the interaction rules of Sec-Traffic Manager.

After you create an interaction rule, service traffic is automatically switched to your Anti-DDoS Pro or Anti-DDoS Premium instance for scrubbing only when blackhole filtering is triggered. You can also manually switch service traffic to your instance for scrubbing before blackhole filtering is triggered based on the protection requirements of your services. This reduces the adverse impacts caused by blackhole filtering and traffic switchover.

Create a cloud service interaction rule

Create a tiered protection rule

Create a CDN or DCDN interaction rule

Create a network acceleration rule

2021-06-01Anti-DDoS ProAssetsIPv6 addresses are supported for Anti-DDoS Pro instances.

You can apply for an IPv6 address for an Anti-DDoS Pro instance. This way, IPv4 traffic and IPv6 traffic can be forwarded to the same origin server that uses IPv4 addresses or to the respective origin servers that use IPv4 and IPv6 addresses.

Purchase an Anti-DDoS Pro or Anti-DDoS Premium instance
2021-05-24Anti-DDoS Pro and Anti-DDoS PremiumInvestigationIn addition to blackhole filtering events and traffic scrubbing events that are detected in Anti-DDoS Pro or Anti-DDoS Premium, the events of flood attacks at Layer 4 and the events of HTTP flood attacks at Layer 7 can also be monitored by CloudMonitor. This feature provides comprehensive information about the security events that are detected in Anti-DDoS Pro or Anti-DDoS Premium.

You can configure alert rules for events that are detected in Anti-DDoS Pro or Anti-DDoS Premium. This way, if an attack event is detected, CloudMonitor can send alert notifications in a timely manner.

Configure alert rules for attack events
2021-05-15Anti-DDoS Pro and Anti-DDoS PremiumProvisioningThe features that are used to add domain names and ports are supported by Terraform. For more information, see Terraform. You can use Terraform to manage configurations in a centralized manner. This makes O&M more efficient. Terraform documentation
2021-04-30Anti-DDoS PremiumProvisioningThe access configurations of multiple domain names can be modified at a time in Anti-DDoS Premium.
Note Anti-DDoS Pro supports this feature before Anti-DDoS Premium does.
Modify website configurations
2021-04-27Anti-DDoS PremiumInvestigationAttack analysis reports can be queried in Anti-DDoS Premium. This way, you can obtain information, such as the attack trend charts, analysis results of attack sources, and geographical distribution of attack sources.
Note Anti-DDoS Pro supports this feature before Anti-DDoS Premium does.
View information on the Attack Analysis page
2021-04-22Anti-DDoS Pro and Anti-DDoS PremiumMitigation SettingsThe mitigation settings for UDP reflection attacks can be configured on the Protection for Infrastructure tab.

You can configure filtering policies based on the source ports of UDP traffic. You can enable one-click filtering for the source ports of common UDP reflection attacks. You can also customize filtering policies for the source ports of new types of UDP reflection attacks. This allows you to respond to UDP reflection attacks at the earliest opportunity and ensure the availability of UDP services.

Use the feature of UDP Reflection Attacks Protection
2021-04-15Anti-DDoS Pro and Anti-DDoS PremiumInvestigationThe entry point to the Cloud monitor alerts page is added to the Investigation module in the left-side navigation pane.

On the Cloud monitor alerts page, you can view the types of alerts supported by Anti-DDoS Pro and Anti-DDoS Premium. You can also click the required button to go to the CloudMonitor console and enable alerting for Anti-DDoS Pro and Anti-DDoS Premium.

Use the alert monitoring feature of CloudMonitor
2021-03-31Anti-DDoS PremiumSec-Traffic ManagerNetwork acceleration policies are optimized for Anti-DDoS Premium.

The waiting time that is required for automatic switchback during network acceleration is reduced from 30 minutes to 10 minutes.

Create a network acceleration rule
2021-03-26Anti-DDoS Pro and Anti-DDoS PremiumWebsite ConfigCustom combinations of cipher suites are supported in Transport Layer Security (TLS) policies.

After you add the domain name of a website to your Anti-DDoS Pro or Anti-DDoS Premium instance, you can specify the cipher suite based on your business requirements.

Configure a custom TLS security policy
2021-03-26Anti-DDoS Pro and Anti-DDoS PremiumWebsite ConfigMultiple domain names are supported to forward back-to-origin requests.

When you add a website to your Anti-DDoS Pro or Anti-DDoS Premium instance, you can specify more than one domain name that is mapped to your origin servers to forward back-to-origin requests. If you specify more than one IP address or domain name, Anti-DDoS Pro and Anti-DDoS Premium use IP hash load balancing to forward website traffic to the origin servers.

You can specify multiple domain names to forward back-to-origin requests in distributed business scenarios. This way, you can use Anti-DDoS Pro or Anti-DDoS Premium together with your network, and the workload on a single origin server is reduced. This improves service stability and disaster recovery.

Add a website
2021-03-26Anti-DDoS Pro and Anti-DDoS PremiumWebsite ConfigRemarks can be specified for a website.

After you add the domain name of a website to your Anti-DDoS Pro or Anti-DDoS Premium instance, you can specify remarks for the website. If you add multiple websites to your Anti-DDoS Pro or Anti-DDoS Premium instance, you can identify services based on the remarks. This makes O&M more efficient.

Add a website
2021-03-26Anti-DDoS Pro and Anti-DDoS PremiumWebsite ConfigCustom header fields and field values are supported to label requests.

When you add the domain name of a website to your Anti-DDoS Pro or Anti-DDoS Premium instance, you can specify a custom header field and the value of the field for the domain name. When the instance processes the requests of this domain name, the instance adds the custom header field to these requests. This allows you to collect statistics on and analyze the back-to-origin data. For example, you can accurately count the actual source ports of the requests.

Mark back-to-origin requests
2021-03-26Anti-DDoS Pro and Anti-DDoS PremiumStatic Page CachingManual cache refreshing is supported for static page caching.

If you create custom rules for static page caching and the source content of the cached page changes, you can forcibly refresh the page cache in Anti-DDoS Pro or Anti-DDoS Premium to synchronize the latest content in time.

Anti-DDoS Lab

2020

Release dateApplicable serviceFeatureDescriptionReferences
2020-12-15Anti-DDoS Pro and Anti-DDoS PremiumWebsite ConfigThe configurations of Enable HTTPS Routing and Enable HTTP are provided.

When you add the domain name of a website to your Anti-DDoS Pro or Anti-DDoS Premium instance, you can configure the Enable HTTPS Routing or Enable HTTP setting for the website. If you turn on Enable HTTPS Routing, all HTTP requests from clients to the instance are redirected to HTTPS requests, which enhances service security. If you turn on Enable HTTP, HTTPS requests to the instance are redirected to HTTP requests and then the HTTP requests are forwarded to the origin servers. This reduces the workload required to process HTTPS requests on the origin servers. These features allow the instance to authenticate inbound requests and help reduce the workload on downstream links and hosts.

Add a website
2020-11-05Anti-DDoS Pro and Anti-DDoS PremiumAlert RulesMultiple domain name metrics, such as queries per second (QPS) and abnormal status codes, are supported by alert rules. You can use these metrics to monitor the websites that are protected by your Anti-DDoS Pro or Anti-DDoS Premium instance and identify exceptions at the earliest opportunity. Configure an alert rule for Anti-DDoS Pro or Anti-DDoS Premium
2020-10-27Anti-DDoS Pro and Anti-DDoS PremiumMitigation Settings > Custom PoliciesCustom policies are supported. You can customize policies based on the IP address of your Anti-DDoS Pro or Anti-DDoS Premium instance and apply these custom policies to the instance. Create custom mitigation policies for specific scenarios
2020-09-24Anti-DDoS ProAttack AnalysisAttack Analysis is supported only for Anti-DDoS Pro.

The entry point to the Attack Analysis page is added to the left-side navigation pane of the Anti-DDoS Pro console. The Attack Analysis page displays the details about attack events to provide a clear view of the process and details about protection against DDoS attacks. The details include an attack trend chart, attack source analysis, and protection flowchart.

View information on the Attack Analysis page
2020-09-08Anti-DDoS PremiumSecurity OverviewTraffic information about Sec-CMA is provided on the Security Overview page.

On the Security Overview page, you can query the inbound, outbound, and attack traffic of Sec-CMA. This way, you can understand the traffic, attack mitigation effects, and the deduction of protection quotas for Sec-CMA.

Security Overview
2020-07-09Anti-DDoS Pro and Anti-DDoS PremiumMitigation SettingsMajor changes:
  • The Blocking Time option is provided for you to set the duration for IP addresses to be retained in a blacklist when you configure a Blacklist and Whitelist (Instance IP) policy for your Anti-DDoS Pro instance.
  • In the Anti-DDoS Premium console, the Blacklist and Whitelist (Instance IP) settings are provided on the Protection for Infrastructure tab, and the Intelligent protection settings are provided on the Protection for Non-website Services tab.
Configure the IP address blacklist and whitelist for an Anti-DDoS Pro or Anti-DDoS Premium instance

Configure intelligent protection

2020-06-22Anti-DDoS PremiumSec-Traffic Manager >

Sec-MCA

The Sec-CMA feature in Anti-DDoS Premium provides protection at both Layer 4 and Layer 7. This feature accelerates network access for your services outside the Chinese Mainland and protects your assets against DDoS attacks. Configure Anti-DDoS Premium Sec-CMA
2020-05-19Anti-DDoS Pro and Anti-DDoS PremiumSec-Traffic Manager >

CDN/DCDN Interaction

Anti-DDoS Pro and Anti-DDoS Premium can work with Dynamic Route for CDN (DCDN) to scrub malicious traffic and accelerate content delivery:
  • If no attacks are detected, DCDN accelerates traffic of your workloads.
  • If attacks are detected, traffic of your workloads is automatically redirected to Anti-DDoS Pro or Anti-DDoS Premium for scrubbing. This ensures service availability.
  • After the attacks stop, traffic of your workloads is automatically redirected to DCDN.
Create a CDN or DCDN interaction rule
2020-04-30Anti-DDoS Pro and Anti-DDoS PremiumSec-Traffic Manager >

CDN Interaction

If attacks are detected, CDN-accelerated domain names that integrate with Anti-DDoS Pro or Anti-DDoS Premium are added to a sandbox. The traffic of the domain names is redirected to Anti-DDoS Pro or Anti-DDoS Premium for scrubbing. This ensures service availability. Overview
2020-04-22Anti-DDoS Pro and Anti-DDoS PremiumSec-Traffic Manager >

General

You can set the waiting time that is required for traffic switchback in general scheduling rules. Before the waiting time elapses, you can also manually switch traffic from Anti-DDoS Pro or Anti-DDoS Premium back to cloud resources. Overview
2020-04-01Anti-DDoS Pro and Anti-DDoS PremiumNew API operationsNew API operations are provided for you to manage and integrate Anti-DDoS Pro and Anti-DDoS Premium instances. List of operations by function
2020-03-03Anti-DDoS PremiumAnti-DDoS Premium interacting with CloudMonitorAnti-DDoS Premium allows you to view basic O&M data in CloudMonitor. You can customize alert rules for Anti-DDoS Premium in the CloudMonitor console based on your business requirements. Configure an alert rule for Anti-DDoS Pro or Anti-DDoS Premium

Configure alert rules for attack events

2020-02-18Anti-DDoS Pro and Anti-DDoS PremiumIntegrated console and region selection The consoles of Anti-DDoS Pro and Anti-DDoS Premium are integrated.
  • In the console, you can select Chinese Mainland for Anti-DDoS Pro or Outside Chinese Mainland for Anti-DDoS Premium.
  • You can access Anti-DDoS Pro and Anti-DDoS Premium in the same console. The Anti-DDoS Premium console is updated to provide a graphical user interface that is similar to that of the Anti-DDoS Pro console.
Differences between the features of Anti-DDoS Pro and Anti-DDoS Premium

2019

Release dateApplicable serviceFeatureDescriptionReferences
2019-12-18Anti-DDoS OriginConsoleA new version of the console is available.
  • In the left-side navigation pane, Anti-DDoS Basic is changed to Anti-DDoS Services.
  • In the left-side navigation pane, the Basic Protection > Instances page is changed to the Assets page. On the Assets page, the content of DDoS Attack Protection Information is updated.
  • In the left-side navigation pane, the Protection Package > Security Report, Protection Package > Protection Packages, Protection Package > Traffic Packages, and Protection Package > Operation Logs pages are changed to the Anti-DDoS Origin > Manage Instances page.
  • In the left-side navigation pane, the following entry points are added:
    • Anti-DDoS Services > Anti-DDoS Pro: directs you to the Anti-DDoS Pro console.
    • Anti-DDoS Services > Anti-DDoS Premium: directs you to the Anti-DDoS Premium console.
    • Industry-specific > Game Shield: directs you to the GameShield console.
    • How to Choose: directs you to a topic named Select an Anti-DDoS service based on the protection scenario.
View the Assets page
2019-12-18Anti-DDoS OriginAssetsThe Basic Protection > Instances page is changed to the Assets page.

The Assets page displays the protection status of activated assets within your Alibaba Cloud account. The page provides a quick overview of security risks for your assets from DDoS attacks. On the page, you can also increase the protection capacity for a specific asset. Supported assets include Elastic Compute Service (ECS) instances, Server Load Balancer (SLB) instances, and elastic IP addresses (EIPs).

View the Assets page