The content of this page has been automatically translated by AI. If you encounter any problems while reading, you can view the corresponding content in Chinese.
Help & Documentation>Web Application Firewall

Bot Traffic Details

Last updated: 2024-10-24 22:11:13

Background

With bot traffic analysis, you can collect data from bot traffic management and quickly understand how a selected domain name with bot traffic analysis enabled is affected by bots. You can also view the bot classification trend, action trend, bot score distribution, top statistics by request count, and list of URLs vulnerable to attacks. Additionally, you can click View Details to see details about the corresponding source of access, discover access characteristics, and understand bot anomalies.
In the Bot Traffic Details section, you can quickly identify the top 10 sources of access for enabled bot traffic analysis features. If session settings are configured, you can also view session access information for the top 10 access sources, quickly navigate to the details and logs of the selected source of access. You can also perform targeted searches for information on specific sources of access/IPs.

Prerequisites

After purchasing WAF and Bot Traffic Management, enable bot traffic analysis.

Directions

1. Log in to the WAF console and select Bot Traffic Analysis > Bot Traffic Details from the left sidebar.
2. On the Bot Traffic Details page, click the "All Domains" dropdown in the upper left corner and select the domain name you want to view.
3. On the Bot Traffic Details page, you can search for the top 10 traffic information for all domains or a specific domain by time or filter and quickly navigate to the relevant logs.

4. On the Bot Traffic Details page, select the desired source of access and click View Details to access the details page for that source.


View Overview

In the Overview module of the Details page, it displays the source of access risk value and hit policy information. You can also quickly target the source by viewing access logs, adding to the allowlist, blocklist, or defining custom rules.

Field Descriptions:
IP address and Tag: Basic information of the source IP and the hit Tag information.
Last request score: The score identified by the Bot during the last access of this source and the current access risk situation.
Number of sessions: Displays the total number of visits to the website by this source in the most recent continuous session. The total count may differ from the Bot action statistics on the right. This shows the session count of the current access source during the latest visit session.
Access destination: Displays the domain name accessed by the source.
Abnormal features: Displays the modules where abnormal features of the access source appeared.
Hit module: The module that triggered the action during the last disposal action.
Policy ID: Displays the policy ID hit by this source of access.
View access logs: Redirect to the access logs page to view the detailed access information of this source.
Add to allowlist: Add this source of access to the allowlist.
Add to blocklist: Add this source of access to the blocklist.
Add custom rules: Add custom rules for this access source.

View Bot score and proportion

In the Bot score and proportion module on the details page, it displays the Bot action proportion and Bot score distribution during the selected access time period. Through the Bot score distribution, you can quickly find the overall threat level of the current access source.


View Bot Information

In the detailed page of the Bot Information module, the basic characteristics, request features, threat intelligence, AI evaluation, smart statistics, and session features of the source of access bots are displayed. Through these features, you can quickly identify anomalies in current access requests, discover differences among various access sources, and swiftly handle such bots.

Basic Session Information

In the Basic Session Information tab, the basic IP information and session information of the current source of access are displayed. When the dimension displayed is the session ID, the basic IP information is not shown.

Field Descriptions:
IP Basic Information
Source IP: The IP address of the current source of access.
City: The city where the current source of access belongs.
IP Region: The country where the current source of access belongs.
IP Type: The type of IP of the current source of access.
IP Owner: The owner of the IP of the current source of access.
Session Basic Information
Average Session Speed: The average session speed of the current source of access in the latest session, calculated as the total number of session requests divided by the session duration, in requests per minute.
Total Number of Sessions: The total number of sessions in the latest session of the current source of access.
Robots.txt Access: Whether the current source of access has accessed the Robots.txt file in the latest session. Sessions that access this file are typically those of crawler bots.
Session Duration: The duration of the latest session of the current source of access.

Request Feature Information

On the request feature information tab, display the request feature information, Cookie information, User-Agent information, Referer information, and Query information of the current session request.

Field Descriptions:
Information Type
Information Name
Information Details
Request Feature Information
URL Repetition Ratio
The URL repetition ratio in session requests, ranging from 0 to 1. Parameter configuration is based on actual business conditions. A ratio that is too high or too low is considered suspicious (judgment based on actual conditions).
Total URL Types
The number of deduped URLs in session requests. The number of deduped URLs in session requests.
URL Minimum Depth
The minimum level of URL in session requests. The minimum category level of URL in session requests.
URL Maximum Depth
The maximum number of URL levels in session requests. The maximum category level of URL in session requests.
URL Average Depth
The average number of URL levels in session requests. The average category level of URL in session requests.
URL Quantity
The total number of accessed URLs in session requests (not deduplicated).
Cookie Information
Whether cookies are abused
Different UAs use the same cookie.
Cookie Existence
Whether cookies exist in session requests.
Cookie Repetition
The repetition proportion of cookies in session requests, ranging from 0 to 1.
Cookie Efficiency
The proportion of cookies that can be parsed correctly in session requests.
Most Frequent Cookie
The most frequent cookie in session requests.
Proportion of Most Frequent Cookie
The proportion of the most frequent cookie in session requests.
User-Agent information
User-Agent Type
The type of User-Agent for accessing users in session requests.
User-Agent Existence
In session requests, check if the User-Agent field exists in the HTTP header.
User-Agent Randomness Index
The random distribution of UA in session requests, ranging from 0 to 1. The higher the index, the more abnormal it is. Reference threshold: suspected abnormal if exceeding 0.6, confirmed abnormal if exceeding 0.92.
User-Agent Category
The deduplicated number of UAs in session requests. Excessive number may indicate suspected abnormal (to be judged based on actual conditions), applicable to non-agent IPs.
User-Agent Effective Rate
The existence ratio of UA in session requests, ranging from 0 to 1. Too low indicates suspected abnormal (to be judged based on actual conditions).
Most Frequent User-Agent
In session requests, the most frequent value of the HTTP User-Agent field.
The Proportion of the Most Frequent User-Agent
In session requests, the proportion of the most frequent value of the HTTP User-Agent field in the overall traffic.
User-Agent Similarity Ratio
The similarity ratio between the most frequent value of the HTTP User-Agent field and other access requests in session requests.
Referer information
Referer Repetition Ratio
The repetition ratio of Referer in session requests, ranging from 0 to 1, applicable to browser visits. Excessively high indicates suspected abnormal (to be judged based on actual conditions).
Referer Existence Ratio
The existence ratio of Referer in session requests, ranging from 0 to 1, applicable to browser visits. Too low indicates suspected abnormal (to be judged based on actual conditions).
Referer Effective Rate
The effective ratio of Referer in session requests, ranging from 0 to 1, applicable to browser visits. Too low indicates suspected abnormal (to be judged based on actual conditions).
Whether Referer is Abused
Various different UAs using the same Referer in the same session request.
Most Frequent Referer
In session requests, the most frequent value of the HTTP Referer field.
Proportion of Most Frequent Referer
In session requests, the proportion of the most frequent value of the HTTP Referer field in the requests.
Query Information
Request Parameter Ratio
The repetition ratio of GET request parameters (Query Content) or POST request parameters (Body Content) in session requests, ranging from 0 to 1. Parameters should be configured based on actual business conditions. Excessively high or too low indicates suspected abnormal (to be judged based on actual conditions).
Request Parameter Category
The most frequent session request parameters, including GET Request Parameters (Query Content) or POST Request Parameters (Body Content).

Threat Intelligence Module

In the Threat Intelligence tab, if the current Access Source IP/Session ID matches relevant threat intelligence information, it will display IDC Details of the access source and the matched threat intelligence information.
IDC Details: If the access source information includes IDC, it will display the current IDC information.
Threat Intelligence: If the Access Source IP information includes threat intelligence information, it will display the Tags of the matched threat intelligence and their corresponding explanations.

AI Evaluation Module

In the AI Evaluation tab, it will display the anomaly degree and corresponding Metric Feature Value of each dimension's anomaly feature information in the current session request. The displayed content includes Request Feature Anomaly Information, Cookie Anomaly Information, User-Agent Anomaly Information, Referer Anomaly Information, and Query Anomaly Information. If the AI derived anomaly degree is greater than 0, it indicates that the AI evaluation has found anomalous feature parameters.


Bot Flow Statistics Module

In the Bot Flow Statistics tab, it will display the latest anomaly feature information of each dimension and the current eigenvalue of the corresponding features in the current session request, as well as the normal client's Feature Threshold.

Field Descriptions:
Information Name
Information Details
Session Average Speed Anomaly
The current session's Average Rate Feature Value is anomalous. If there is a session average speed anomaly, it will display the number of anomalies in the current session and the Critical Value of this feature in the current domain for abnormal access sessions.
User-Agent Category Anomaly
An abnormal Value has been detected for the User-Agent Type Feature of the current session. If the session's User-Agent type is anomalous, the number of abnormal User-Agent type values in the current session will be displayed, along with the threshold value for this feature in the overall dashboard of abnormal access sessions.
URL Type Anomaly
An abnormal value has been detected for the URL Type Feature of the current session. If the session's URL type is anomalous, the number of abnormal URL type values in the current session will be displayed, along with the threshold value for this feature in the overall dashboard of abnormal access sessions.
Session Duration Anomaly
An abnormal value has been detected for the Duration Feature of the current session. If the session duration is anomalous, the duration of abnormal values in the current session will be displayed, along with the threshold value for this feature in the overall dashboard of abnormal access sessions.
Session Total Count Anomaly
An abnormal value has been detected for the Total Count Feature of the current session. If the session total count is anomalous, the number of abnormal access counts in the current session will be displayed, along with the threshold value for this feature in the overall dashboard of abnormal access sessions.

Session Management

On the Session Management tab, the IP addresses accessed by the current session and the number of accesses per IP address will be displayed. You can also view the access logs of historical access IPs for the current Session ID using the current access information.
Note:
When session settings are configured and the traffic contains the content of the session settings, the session management options will be displayed.