All Products
Search
Document Center

Edge Security Acceleration:Configure high bill alerts

Last Updated:Jan 03, 2025

If your domain name is subjected to malicious attacks or data transmission abuse, resulting in unexpected bandwidth usage and traffic consumption, you may incur high bills that are not eligible for refunding or waiving. This topic introduces strategies to mitigate such risks.

Potential risks: high bills caused by attacks or attack-like activities

  • If an attack occurs, you are charged for the bandwidth resources and data transfer.

  • If your domain name is abused for data transmission, high bandwidth values or traffic spikes may occur. This is similar to an attack, and you are charged for bandwidth resources and data transfer.

Potential consequences: bills that are higher than expected

If your domain name is under attack or abused for data transmission, the bills may be higher than expected and your account balance may be exhausted.

Important

Edge Security Acceleration (ESA) uses the pay-as-you-go billing method. In some cases, ESA may not be suspended when the account balance reaches 0 due to different billing cycles (by hour, by day, or by month) or bill delays. Bills are generated 3 to 4 hours after each billing cycle ends. Overdue payments may occur, including those whose amount due is higher than the value specified in the grace period policy.

Alibaba Cloud provides service suspension protection. If you enable this feature, ESA is not suspended before the grace period ends. The grace period or overdraft limit is determined based on your account tier and purchase history. The overdraft limit is reset every month.

Troubleshooting methods

Note
  • High bills are often the result of traffic spikes caused by malicious access, which can lead to significantly higher costs than normal. The following section describes how to troubleshoot traffic spikes. This helps you identify the causes. For more information, see Solutions.

  • If a traffic spike occurs, we recommend that you go to the Analytics page to see more information, such as the top IP addresses of abnormal clients and referers. You can also analyze real-time logs to determine the cause of the bandwidth spikes. Then, configure security protection measures for the domain name in the console based on the specific reasons to avoid unnecessary traffic bandwidth consumption.

Troubleshooting methods

Description

Standard logs

ESA offers standard logs that are packaged on an hourly basis. You can download access logs of your website within the last 31 days to your local PC. Standard logs can help you optimize acceleration policies, monitor your website, detect potential risks, and learn user behavior.

Real-time log

You can enable the real-time log delivery feature of ESA to collect system logs, application logs, or device operation logs in real time and deliver the collected logs to specified destinations for storage and analysis. This helps monitor your business and protect your data. You can troubleshoot issues and improve content delivery performance based on real-time logs.

Solutions

  • By default, ESA does not provide access control or security protection capabilities. ESA detects bandwidth usage spikes. If abnormal traffic is detected, Alibaba Cloud evaluates whether to throttle traffic, add the domain name to a sandbox, or take other measures based on the normal service traffic and the overall abnormal traffic. For more information, see Burst bandwidth/QPS throttling rules. This ensures service stability for other users. Alibaba Cloud is not responsible for availability issues caused in those situations.

  • To ensure that the system runs as expected and prevent unexpected high bills, we recommend that you enable security features or perform access control.

Configure security settings

Protection

Feature description

Configure custom WAF rules

Custom rules allow you to control user access to resources on your website. To create a custom rule for your website, specify the match conditions and action such as block or monitor that you want to perform on incoming requests that meet the conditions.

Configure WAF rate limiting rules

You can create rate limiting rules via Edge Security Acceleration (ESA) to limit the rate of requests that match specific conditions. For example, if an IP address visits your website at a high frequency within a specific period of time, you can create a rate limiting rule to specify a request rate limit, and enable slider CAPTCHA verification or add the IP address to the blacklist for a period of time when the configured limit is reached.

Configure WAF managed rules

Intrusion attacks such as SQL injection, cross-site scripting (XSS), code execution, CRLF injection, remote file inclusion, and webshells pose high risks but are usually difficult to detect by using custom rules and rate limiting rules. To address this issue, Edge Security Acceleration (ESA) offers built-in intelligent managed rules to defend against OWASP attacks and the latest origin vulnerabilities. You can enable protection against various types of attacks without manual configurations and updates.

Configure WAF scan protection rules

The scan protection module detects the behavior and characteristics of automated scanners to prevent attackers or scanners from scanning websites. Attack sources are blocked or added to the blacklist. This reduces the risk of intrusions into web services and prevents undesired traffic generated by malicious scanners.

Configure WAF whitelist rules

You can configure whitelist rules to allow requests with the specified characteristics, exempting them from all or certain rules, including custom rules, rate limiting rules, managed rules, scan protection rules, and bot management rules.

Create a Bots rule set

Bot management rules can be used to protect your websites or native iOS and Android apps against crawlers. To use the anti-crawler feature on your native iOS and Android apps, you must integrate the Anti-Bot SDK. You can create different anti-crawler rules for requests that have different characteristics. You can also use the built-in crawler libraries such as search engine crawler library, AI protection, bot threat intelligence library, data center blacklist, and fake spider list. This frees you from manual updates and analysis of crawler characteristics.

DDoS

If your website is under a DDoS attack, Edge Security Acceleration (ESA) will continue to accelerate and protect your website, unlike some other proxy services that may disable acceleration in such cases. ESA provides built-in DDoS protection features for your website based on your plan.

Manage traffic

We recommend that you use CloudMonitor to configure bandwidth alert rules by service or domain name to monitor the traffic and bandwidth usage, and send alerts. For more information, see Configure alert rules. In case of unexpected bandwidth surges, you can also configure policies, such as bandwidth throttling and traffic throttling for individual requests, for domain names.

Feature

Feature description

Real-time monitoring

If you want to monitor the peak bandwidth of domain names in real time, you can use CloudMonitor. After the bandwidth of a domain name reaches the specified threshold, you are notified of the potential risks by text message, email, or DingTalk message. For more information, visit the product page of CloudMonitor.

Spending management and alerts

You can use the following features to monitor and limit the expenses. To configure the features, move your pointer over Expenses in the top navigation bar of the console and select Expenses and Costs.

  • High bill alerts: If you enable this feature, the system sends an alert by text message when a daily bill exceeds the alert threshold that you specified.

  • Service suspension protection: If you disable this feature, the service immediately stops running after a payment becomes overdue to prevent high overdue payments.

  • High bill alerts: After this feature is enabled, notifications are sent to you by text message if a daily bill reaches a specified amount.

Note

To ensure the integrity of the statistics and billing accuracy, ESA issues the bill approximately 3 hours after a billing cycle ends.