The critical event protection feature provides customized, precise protection for major events during specific periods. This topic describes how to enable and use critical event protection.
Billing
Product and service prices are subject to change. The final price is based on your Alibaba Cloud bill.
Feature | Description |
Billing method | Critical event protection is a prepaid service with a minimum subscription period of 30 days. You are billed based on the duration you select. |
Validity period | Critical event protection takes effect immediately upon purchase. The validity period corresponds to the Duration you select. After the validity period expires, critical event protection automatically stops. |
Renewal | This feature does not support direct renewal. To continue using critical event protection, purchase it again after it expires. |
Refund policy | After you purchase critical event protection, you cannot unsubscribe or receive a refund for any reason, including the five-day money-back guarantee. Evaluate your business needs before you purchase. |
Prerequisites
You have activated WAF 3.0. For more information, see Purchase a subscription WAF 3.0 instance and Activate a pay-as-you-go WAF 3.0 instance.
The method for enabling critical event protection varies by WAF instance edition.
WAF instance edition
Enabled by default
Description
subscription Ultimate Edition
Yes
You can use this feature directly without enabling it separately.
subscription Pro Edition, subscription Enterprise Edition, and pay-as-you-go
No. You must enable it by performing a temporary upgrade.
Upgrade your instance to Ultimate Edition. For more information, see Upgrade an instance.
Enable critical event protection through a temporary upgrade. For more information, see Enable critical event protection.
subscription Basic Edition
No, and this edition does not support this feature.
Upgrade your instance to Ultimate Edition. For more information, see Upgrade an instance.
Upgrade your instance to Pro Edition or Enterprise Edition, and then enable critical event protection through a temporary upgrade. For more information, see Enable critical event protection.
You have added your web services to WAF 3.0 by using the CNAME record mode or by integrating with a cloud service such as Classic Load Balancer (CLB) (HTTP/HTTPS), CLB (TCP), or Elastic Compute Service (ECS). For more information, see Overview of adding a website.
NoteThis feature is not supported for protected objects that are added to WAF through ALB, MSE, or FC.
Enable critical event protection
Subscription WAF instances
-
Log on to the Web Application Firewall 3.0 console. From the top menu bar, select the resource group and region (Chinese Mainland or Outside Chinese Mainland) for the WAF instance.
-
In the navigation pane on the left, choose .
Click Enable Protection for Critical Events. In the Enable Protection for Critical Events panel, turn on the Protection for Major Events switch and set the Restore Time.
Read and agree to the Terms of Service, and then click Purchase Now to complete the payment.
After you enable critical event protection, you can view the plan's specifications on the Critical Event Protection page in the Protection Plan for Critical Events card.
Pay-as-you-go WAF instances
-
Log on to the Web Application Firewall 3.0 console. From the top menu bar, select the resource group and region (Chinese Mainland or Outside Chinese Mainland) for the WAF instance.
-
In the navigation pane on the left, choose .
Click Enable Protection for Critical Events. In the Enable Protection for Critical Events panel, select a Duration.
Read and agree to the Terms of Service, and then click Buy Now to complete the payment.
After you enable critical event protection, you can view the plan's specifications on the Critical Event Protection page in the Protection Plan for Critical Events card.
Create a critical event rule template
When you first configure critical event protection, you must create a rule template. You can create up to 20 templates.
-
Log on to the Web Application Firewall 3.0 console. From the top menu bar, select the resource group and region (Chinese Mainland or Outside Chinese Mainland) for the WAF instance.
-
In the navigation pane on the left, choose .
On the Protection Templates tab, click Create Template.
In the Create Protection Template for Critical Events panel, configure the following settings.
Configure the basic information, and then click Next.
Parameter
Description
Template Name
Specify a name for the template.
The name must be 1 to 255 characters in length and can contain Chinese characters, uppercase and lowercase letters, digits, periods (.), underscores (_), and hyphens (-).
Protection rules
Select the protection rules to apply and configure the rule action for each.
Critical Event Threat Intelligence: Uses a threat intelligence library of malicious IP addresses to accurately identify attackers. This rule is enabled by default, and its rule action is set to Monitor.
Critical Event Protection Rule Group: Generates a precise set of protection rules for your services based on an intelligent protection model. This rule is enabled by default, and its rule action is set to Monitor.
IP Address Blacklist for Protection for Critical Events: When enabled, WAF monitors or blocks requests from specific IP addresses or address ranges. You can add up to 50,000 custom IP addresses or CIDR blocks to the blacklist.
Shiro Deserialization Vulnerability Prevention: When enabled, WAF uses cookie encryption to protect against Apache Shiro Java deserialization vulnerabilities.
Apply To
From the configured protected objects and protected object groups, select the ones to which you want to apply this template.
If you enabled the IP Address Blacklist for Protection for Critical Events rule, you must configure the IP address blacklist as described below. When you finish, click Next.
Parameter
Actions
Add IP Address Blacklist
Click Add IP Address Blacklist to manually add IP addresses to the blacklist.
In the IP Address Blacklist text box, enter the IP addresses to add. Separate multiple entries with line breaks.
NoteYou can enter up to 500 IP addresses or CIDR blocks. IPv6 addresses are supported. Separate multiple entries with a line break or a comma (,).
Set an expiration time. Options:
Permanently Effective.
Custom. If you select this option, click the time picker to specify an expiration date and time.
In the Remarks text box, enter a note and click OK.
After the IP addresses are added, you can view them in the Configure IP Address Blacklist panel.
Import IP Address Blacklist
Click Import IP Address Blacklist to import IP addresses in bulk.
Click Upload File and select the IP address blacklist file to import.
ImportantOnly CSV files are supported.
IPv4 and IPv6 addresses and CIDR blocks are supported.
You can import one file at a time. Each file can contain up to 2,000 entries. A CIDR block counts as one entry. The file size cannot exceed 1 MB.
If you have a large number of IP addresses to import, you can import them in batches.
Set an expiration time. Options:
Permanently Effective.
Custom. If you select this option, click the time picker to specify an expiration date and time.
In the Remarks text box, enter a note and click OK.
After the IP addresses are added, you can view them in the Configure IP Address Blacklist panel.
Delete All IP Addresses
To remove all IP addresses from the blacklist, click Delete All IP Addresses.
Delete Expired IP Addresses
If some IP addresses in the blacklist have expired, click Delete Expired IP Addresses to remove them.
Click Complete.
The new rule template is enabled by default. In the rule template list, you can perform the following actions:
View the number of Protection Features and associated Protected Object/Group for a template.
Use the switch to Enable or Close a template.
Edit, Delete, or Copy a rule template.
If a template has the IP Address Blacklist for Protection for Critical Events rule enabled, click Edit IP Address Blacklist to add or modify the blacklist.
View critical event protection data
-
Log on to the Web Application Firewall 3.0 console. From the top menu bar, select the resource group and region (Chinese Mainland or Outside Chinese Mainland) for the WAF instance.
-
In the navigation pane on the left, choose .
You can view the following information.
In the Statistics card, view the Total Requests, the Blocked Requests, and a pie chart showing the distribution of protection rule types for the specified time range.
In the Protection Plan for Critical Events card, view the number of Protection Rules for Critical Events, Threat Intelligence Rules, and Added IP Addresses In Blacklist/Total within the specified time range.
On the Security Reports tab, select a protected object and a time range to view the corresponding security report.
Protected object: By default, All is selected, which retrieves data for all WAF-protected objects. You can select a specific object.
Time range: By default, data for Today is displayed. You can also select Yesterday, Today, Last 7 days, Last 30 days, or a custom time range within the last 30 days.
The following table describes the data in the security report.
Type
Description
Supported actions
Attack statistics (labeled ① in the figure)
Displays statistical analysis of attacks on the protected object for the specified time range, including:
Distribution of Attack Types:
A pie chart showing the distribution of attack types.
Top 5 Attacks:
Lists the top five most frequently attacked objects on the Attacked Object tab and the top five attacker IP addresses on the Attacker IP Address tab. The results are sorted in descending order by the number of attacks.
None
Attack event logs (labeled ② in the figure)
Lists attack requests that triggered core web protection rules.
The list includes the following information:
Attacker IP Address: The source IP address of the attack request.
Area: The region where the attacker IP address is located.
Attack Time: The time when the attack started.
Attack Type: The type of attack, such as SQL Injection or Code Execution.
Rule Type: The type of rule that was triggered, such as Protection Rule Group for Critical Events or Threat Intelligence for Protection for Critical Events.
Rule Action: The action taken by WAF. Block: WAF blocked the request. Log: WAF logged the attack but did not block the request.
Filter attack events
Use the following fields above the attack event table to filter events:
Attack Type: By default, All is selected. Other options include SQL Injection, XSS, Code Execution, Local File Inclusion, Remote File Inclusion, Webshell, and Others.
Rule Type: By default, All is selected. Other options include Critical Event Protection Rule Group, Critical Event Threat Intelligence, IP Address Blacklist for Protection for Critical Events, and Shiro Deserialization Vulnerability Prevention.
Rule action: By default, All is selected. Other options are Block and Monitor.
View attack details
In the Actions column for an event, click View Details to view more information about the attack and the triggered rule, such as the Rule ID, Rule Name, Rule Description, Rule Action, and Attack Type.
Real-time threat intelligence (labeled ③ in the figure)
Displays real-time threat intelligence for attacker IP addresses, including:
The attacker IP address and its attributes.
The region of the attacker IP address.
The number of attacks in the last hour.
The attack type.
Query real-time threat intelligence for an attacker IP address
Enter an IP address in the search box and click the
icon to query its threat intelligence.