All Products
Search
Document Center

Edge Security Acceleration:Prevent unexpected charges

Last Updated:Aug 26, 2026

Sudden spikes in bandwidth and data transfer caused by malicious attacks or traffic abuse can push your bill well above your usual spending. Such charges cannot be waived or refunded. You can avoid these risks by configuring security protection and managing traffic.

Risk of high bills from malicious activity

  • When an attack or traffic abuse causes a sudden bandwidth spike, ESA bandwidth resources are actually consumed. You are responsible for all resulting bandwidth and data transfer costs.

Consequence: charges may exceed your account balance

Malicious attacks and traffic abuse can easily result in high bills. The knock-on risk is that the billed amount often exceeds your available account balance.

Important

After you use up the prepaid traffic for ESA, the service switches to pay-as-you-go and generates bills. The service cannot be suspended immediately when your account balance reaches zero. This gap is caused by factors such as the billing cycle (for example, hourly, daily, or monthly billing) and billing processing delays. For example, Alibaba Cloud ESA has a billing delay of 3 to 4 hours. As a result, your account may have an outstanding balance, or the outstanding balance on a single bill may exceed your overdraft limit.

Alibaba Cloud provides a service suspension protection feature. If you enable this feature and your account has an overdue payment, you are granted an overdraft limit or a grace period to continue using cloud services. The allowance is based on factors such as your customer level and spending history, and it is automatically calculated and updated each month.

Investigate unexpected charges

High bills are primarily caused by traffic spikes from malicious access, which drive costs far above normal levels. If your bill is higher than expected, use the following steps to trace the source of the charges and confirm the affected time range and billable items.

  1. Log on to the Alibaba Cloud console. In the top navigation bar, choose Billing > Billing Management to view the bill details. Select a billing cycle, and identify the affected time range and the corresponding billable items.

  2. Log on to the ESA console. In the left navigation pane, choose Billing Management > Usage Inquiry, and compare the actual usage of each metering item. Confirm whether the usage data for the affected time range matches the bill.

  3. To narrow the investigation down to a single domain name, open the resource monitoring page in the same console, select the target domain name, and query its usage data. This confirms which domain name is the source of the abnormal traffic.

Identify the cause of a traffic spike

If an abnormal traffic spike occurs, first check the Analytics page to identify the cause of the abnormal traffic (for example, the top client IP addresses or top referers). You can also use Analyze real-time logs to determine the cause of the bandwidth spike.

Investigation method

Description

Analytics

Edge Security Acceleration (ESA) packages standard logs hourly. Download site access logs for any time period within the past 31 days and save them locally to optimize acceleration policies, diagnose issues, and analyze user behavior.

real-time log

Collect real-time logs from systems, applications, or devices and deliver them to a destination of your choice for security monitoring, troubleshooting, and performance optimization.

Solutions

Alibaba Cloud ESA detects bandwidth spikes. If abnormal traffic is detected, it evaluates your normal business traffic and the overall load of the abnormal traffic. Based on this evaluation, it decides whether to apply measures such as rate limiting the burst traffic or converging it to specific ESA nodes. These measures maintain stability for all users on the network. Rate limiting and convergence to specific ESA nodes are not triggered in every case. For more information, see Burst bandwidth and QPS rate limiting rules in the usage limits. Alibaba Cloud is not liable for any availability issues that result from these measures.

To keep your services running as expected and avoid high bills, enable the protection features or configure access control for your traffic as described in the following sections.

Configure security protection

Protection measure

Description

Configure WAF custom rules

If your website requires custom access control policies, you can create custom rules. A custom rule allows you to define match conditions for incoming requests and specify an action, such as block or monitor, for matching requests. This gives you flexible control over the content users can access.

Configure WAF rate limiting rules

Rate limiting rules in control the rate of incoming requests that match specific conditions. When a client exceeds the configured request threshold, rate limiting enforces actions such as slider CAPTCHA verification or temporary IP blacklisting.

Configure WAF managed rules

Managed rules are intelligent built-in ESA protection rules that defend against OWASP attacks and the latest origin server vulnerabilities, including SQL injection, XSS, code execution, CRLF, remote file inclusion, and WebShell. Enable protection without manual rule configuration or updates.

Configure WAF scan protection rules

Scan protection identifies scanner behavior and signatures to block large-scale scans against your website, then blocks or blacklists the attack source to reduce intrusion risk and unwanted traffic.

Configure WAF allowlist rules

Whitelist rules let specific requests bypass all or selected WAF protection modules, preventing false positives from internal services or known partners.

Create a Bots ruleset

ESA provides two modes, Smart Mode and Professional Mode, for different protection needs.

Configure DDoS protection

ESA monitors traffic in real time to identify attack patterns like SYN floods, ACK floods, and CC attacks. When it detects unusual traffic, ESA promptly blocks malicious requests while allowing legitimate traffic to pass, ensuring business continuity.

Manage traffic

Use CloudMonitor to set bandwidth monitoring rules at the service level or the domain name level. This keeps you informed about data transfer and bandwidth usage and sends alerts for abnormal activity. If an abnormal bandwidth spike occurs, you can also configure policies such as bandwidth throttling and request rate limiting for the domain name.

Traffic management feature

Description

Set bandwidth throttling

If you need to apply bandwidth throttling to ESA bandwidth and your daily peak bandwidth is at least 10 Gbps, you can submit a ticket to request this configuration.

Important

Bandwidth throttling sets the total network-wide bandwidth limit for a domain name. To keep throttling accurate, the bandwidth throttling value must be at least 10 Gbps. After the bandwidth limit (for example, 10 Gbps) is reached, ESA throttles the domain name. Access speed then drops for users (every request slows down), and packet loss may occur. Bandwidth throttling is triggered by real-time monitoring data for the domain name, and that data has a delay of about 10 minutes. As a result, the domain name is throttled about 10 minutes after its actual bandwidth reaches the threshold, and by then the actual bandwidth is likely higher than the threshold.

Set real-time monitoring

To monitor the peak bandwidth of a domain name in real time, use the Cloud Product Monitoring feature of CloudMonitor to monitor the peak bandwidth of a specific domain name under ESA. When the configured peak bandwidth is reached, an alert is sent to the administrator by SMS, email, or DingTalk, so that you detect potential risks sooner. For more information, see product page of CloudMonitor.

Set spending alerts

In the top navigation bar of the console, choose Billing > Billing Management. Use the following features to control the spending on your account and avoid excessive bills. Available balance alert: Configure an SMS alert that is sent when your account balance falls below a specified amount. Service suspension protection: You can disable this feature so that your services stop as soon as a payment becomes overdue, which prevents further charges.For more information, see . High bill alert: Enable an SMS alert that is sent when the daily bill for a service exceeds the alert threshold.

Note

To keep metering data complete and bills accurate, ESA generates the actual bill approximately 3 to 4 hours after the end of a billing cycle.