Dynamic Route for CDN (DCDN) can integrate with Web Application Firewall (WAF) to provide security services on DCDN nodes. WAF can identify and filter out malicious requests. Only legitimate requests can be redirected to origin servers. WAF can protect web servers against intrusions, secure business-critical data, and prevent server anomalies caused by attacks.
Prerequisites
DCDN is upgraded to secure DCDN. For more information about the upgrade, see Enable secure DCDN.
Features
DCDN can integrate with WAF to protect resources on DCDN nodes. For more information about the features of WAF, see What is WAF?
Feature | Business Edition |
---|---|
Scan protection | Supported |
Account security | Supported |
HTTP flood protection | Supported |
IP blacklist | Supported |
Rate limiting | Supported |
Bot threat intelligence rules | Supported |
JavaScript validation | Supported |
Crawler whitelist | Supported |
Web application protection | Supported |
Zero-day attack protection | Supported |
Block and warning modes | Supported |
Decoding and analytics of request data in specified formats | Supported |
Custom rule groups | Supported |
HTTP access control list (ACL) policies | Supported |
Log service | Supported with a storage capacity up to 3 TB |
Configure WAF for one domain name
- Log on to the DCDN console.
- In the left-side navigation pane, click Domain Names.
- On the Domain Names page, find the domain name that you want to manage and click Configure in the Actions column.
- Click Security Settings and select the WAF tab.
- Turn on WAF - Mainland China or WAF - Outside Mainland China.
- Configure protection.
- Click Modify Configurations.
- Follow the on-screen instructions to configure the security features, such as web security and bot management, based on your business requirements. For more information, see Add website protection configurations.
Configure WAF for multiple domain names
- Log on to the DCDN console.
- In the left-side navigation pane, choose .
- On the top of the Configurations page, select Mainland China or Outside Mainland China.
- Add the domain names for which you want to enable WAF.
- Configure protection.
- On the Configurations page, find the domain name that you want to manage and click Configure Protection in the Actions column.
- Follow the on-screen instructions to configure the security features, such as web security and bot management, based on your business requirements. For more information, see Add website protection configurations.
Add website protection configurations
Web security
Feature | Parameter | Description |
---|---|---|
Web Intrusion Prevention | Status | You can turn on or turn off Web Intrusion Prevention. |
Mode | Web Intrusion Prevention supports the following protection modes:
|
|
Protection Rule Group | Web Intrusion Prevention supports the following protection rule groups:
|
|
Decoding Settings | You can specify the formats of data that needs to be decoded and analyzed by the RegEx
protection engine.
Note To enhance protection, the RegEx protection engine decodes and analyzes the request
content in all formats by default. If the RegEx protection engine blocks requests
that contain content in formats that you do not want to block, you can clear the formats
to reduce the false positive rate.
|
|
Advanced Protection | Status | You can turn on or turn off Positive Security Model. |
Mode |
|
Bot management
Feature | Parameter | Description |
---|---|---|
Allowed Crawlers | Status | You can turn on or turn off Allowed Crawlers.
Note This feature allows you to set a whitelist that contains authorized search engines,
such as Google, Bing, Baidu, Sougou, 360, and Yandex. The crawlers of the search engines
included in the whitelist are allowed to access all accelerated domain names. You
can click Settings to enable or disable allowed crawlers based on your business requirements.
|
Typical Bot Behavior Identification | Status | You can turn on or turn off Typical Bot Behavior Identification.
Note This feature provides general algorithms to identify typical crawler behaviors. You
can set relevant parameters and thresholds to prevent advanced crawlers. You can click
Settings to add algorithm rules based on your business requirements.
|
Bot Threat Intelligence | Status | You can turn on or turn off Bot Threat Intelligence.
Note This feature provides information about suspicious IP addresses of dialers, data centers,
and malicious scanners based on the computing capabilities of Alibaba Cloud. This
feature also maintains a dynamic IP library of malicious crawlers and prevents crawlers
from accessing specific domain names or paths. You can click Settings to edit intelligence rules based on your business requirements.
|
App Protection | Status | You can turn on or turn off App Protection.
Note This feature provides secure connectivity and anti-bot protection for native apps.
You must integrate the Alibaba Cloud SDK.
|
Access control and throttling
Feature | Parameter | Description |
---|---|---|
HTTP Flood Protection | Status | You can turn on or turn off HTTP Flood Protection.
Note After you enable this feature, WAF helps you defend against HTTP flood attacks and
provides protection policies in different modes.
|
Mode |
|
|
Scan Protection | Blocking IPs Initiating High-frequency Web Attacks | You can turn on or turn off Blocking IPs Initiating High-frequency Web Attacks.
After you enable this feature, client IP addresses that initiate multiple attacks
on your website in a short period of time are automatically blocked.
|
Directory Traversal Protection | You can turn on or turn off Directory Traversal Protection.
After you enable this feature, client IP addresses that initiate multiple directory
traversal attacks on your website in a short period of time are automatically blocked.
|
|
Scanning Tool Blocking | You can turn on or turn off Scanning Tool Blocking. After you enable this feature, access requests from IP addresses of common scanners are automatically blocked. | |
Collaborative Defense | You can turn on or turn off Collaborative Defense. After you enable this feature, access requests from the IP addresses in the Alibaba Cloud malicious IP library are automatically blocked. | |
Blacklists | Status | You can turn on or turn off Blacklists.
This feature allows you to block requests from specified IP addresses or CIDR blocks, or limit requests from IP addresses in specified regions. Note You can click Settings to add IP addresses or regions to the blacklist.
|
Custom Protection Policy | Status | You can turn on or turn off Custom Protection Policy.
This feature allows you to create an access control rule and apply the access control rule to a specific object. Note You can click Settings to add an access control rule.
|
View WAF logs and reports
After you add your website to WAF, you can view the information about attacks on a specific domain name and the protection results in the reports. For more information about logs and reports, see View WAF logs and reports.