DDoS Attack
A Distributed Denial of Service (DDoS) attack refers to an attacker remotely controlling a large number of zombie hosts over the network to send a large number of attack requests to one or more targets, blocking the network bandwidth of the target server or exhausting its system resources, making it unresponsive to normal Service requests.
Network Layer DDoS Attack
A network layer DDoS attack mainly refers to an attack method where attackers use high-traffic attacks to congest the network bandwidth of the target server, consume server system layer resources, and cause the target server to be unable to normally respond to customer access.
Common attack types include SYN Flood, ACK Flood, UDP Flood, ICMP Flood, and DNS/NTP/SSDP/memcached reflection attacks.
CC Attack
A CC attack mainly refers to an attack method that maliciously occupies application layer resources of the target server, consumes processing performance, and causes it unable to provide services properly.
Common attack types include HTTP/HTTPS-based GET/POST Flood, Layer-4 CC, and Connection Flood.
Protection Capability
Protection capability refers to the ability to resist DDoS attacks. The Anti-DDoS service commitment provides full protection according to the maximum Anti-DDoS protection capability of Tencent Cloud in the current region.
Scrubbing
When the public network traffic of the target IP exceeds the set protection threshold, the Tencent Cloud Anti-DDoS protection system will automatically scrub the inbound public network traffic of this IP. Through the BGP routing protocol, the traffic is redirected from the original network path to the Tencent Cloud Anti-DDoS cleaning equipment. The cleaning equipment identifies the traffic of this IP, discards the attack traffic, and forwards the normal traffic to the target IP.
Normally, cleaning will not affect normal access. It may impact normal access only in special scenarios or when the cleaning strategy configuration is incorrect. When the traffic continues for a specified period (determined dynamically according to the attack situation) without exceptions, the cleaning system will deem the attack ended and stop cleaning.
Block
When the attack traffic received by the target IP exceeds its blocking threshold, Tencent Cloud will block all public network access of this IP through the operator's service blocking to protect other users on the cloud platform from being affected. In short, when the attack traffic received by your certain IP exceeds the maximum protection capability of Tencent Cloud in the current region, Tencent Cloud will block all public network access of this IP. When your protected IP is blocked, you can log in to the management console to perform self-service unblocking.
Blocking Threshold
The blocking threshold of the protected IP of the DDoS High Protection Instance is equal to the maximum protection capability of the current region.
Blocking Duration
The blocking duration defaults to 2 hours. The actual blocking duration is related to the trigger count and peak value of blockings on that day, and can be up to 24 hours at most. The blocking duration is mainly affected by the following factors:
Whether the attack continues: If the attack continues, the blocking time will be extended, and the blocking time will be recalculated starting from the moment of extension.
Whether the attack is frequent: The probability of continuous attacks for users who are frequently attacked is large, and the blocking time will be automatically extended.
Traffic size of the attack: The blocking time will be automatically extended for users who are under ultra-large traffic attacks.
Note:
For individual users with excessively frequent blocking, Tencent Cloud reserves the right to prolong the blocking duration and lower the blocking threshold.
Why Perform Blocking
Tencent Cloud reduces cloud cost by sharing infrastructure. All users share Tencent Cloud's public egress IP address. When a high-traffic attack occurs, in addition to affecting the attacked object, the entire Tencent Cloud network may be affected. To prevent attacks from affecting other users who are not attacked and guarantee the stability of the entire cloud platform network, blocking needs to be performed.
Protection Bandwidth
Protection bandwidth is divided into baseline protection bandwidth and elastic protection bandwidth.
Baseline protection bandwidth: Refers to the base protection capability of a high-defense IP instance. The guaranteed part is prepaid by year/month.
Elastic protection bandwidth: Refers to the maximum elastic protection capability of a high-defense IP instance. The elastic part is paid after daily usage.
If Elastic Protection is not enabled, the baseline protection bandwidth is the highest protection capability of the high-defense IP instance. If Elastic Protection is enabled, the elastic protection bandwidth serves as the highest protection capability of the high-defense IP instance. Blocking is triggered when the attack traffic exceeds the highest protection capability of the high-defense IP instance.
Note:
Elastic Protection is disabled by default. To enable it, please self-enable it after acknowledging the relevant billing details. Users can adjust the elastic protection bandwidth at any time based on their business needs.
Protection bandwidth is only supported for High-defense IP and High-defense IP Overseas Enterprise Edition.
Role of Elastic Protection Bandwidth
After you enable Elastic Protection, when the attack traffic exceeds the purchased base protection capability and is within the scope of the elastic protection capability, Tencent Cloud Anti-DDoS Advanced can continue to provide protection for users, guaranteeing the continuity of business access.
How Is Elastic Protection Charged
After enabling Elastic Protection, when the attack traffic exceeds the base protection capability, Elastic Protection will be triggered and fees will be charged. Billing will be based on the interval corresponding to the highest peak value of actual attack generated on the day, and the bill will be generated on the next day.
For example, if the guaranteed protection you have purchased is 20 Gbps and the elastic protection you have set is 50 Gbps. If the actual peak attack bandwidth on the day is 35 Gbps, you need to pay for the elastic protection fee in the 10 Gbps - 20 Gbps interval.
Full Protection Times (Applicable to Anti-DDoS Pro (Standard Version 2.0) - 2 Times Protection Edition)
When the attack traffic exceeds basic protection capability (see in the table below), the attack duration will start to accumulate and count as one protection. When the cumulative duration of a single protection exceeds 30 minutes, the next protection will be enabled.
If an attack event causes IP blocking, the protection times will not be consumed.
When the number of Full Protection instances reaches 0, the assets bound to Anti-DDoS Pro will be protected according to the Basic Protection capability (see table below).
Protection Type | Basic Protection Capability |
Anti-DDoS Pro (standard version 2.0) 2 times of protection | 10 Gbps |
High Defense Insurance Protection Times
When the attack traffic exceeds basic protection capability (see table below), the attack duration starts accumulating and is counted as one protection instance. The duration of a single protection ranges from 5 to 30 minutes.
Regardless of whether Anti-DDoS High Defense Insurance successfully defends against attacks, the number of protections will be deducted each time protection is triggered.
When the number of protections of Anti-DDoS High Defense Insurance protection reaches 0, the assets bound to Anti-DDoS High Defense Insurance will be protected according to the Basic Protection capability (see table below).
Protection Type | Basic Protection Capability |
Anti-DDoS High Defense Insurance | 2 Gbps (Anti-DDoS Basic) |