配置通知以实时接收(约 1 分钟内)有关您的互联网资产上遭受的 L3/4 和 L7 DDoS 攻击的警报,具体取决于您的套餐和订阅的服务。您可以选择不同的发送方式。
每封通知电子邮件都包含以下信息:
- 描述 (Description)
- 检测到并缓解攻击的时间 (Detection and mitigation time of attack)
- 攻击类型 (Attack type)
- 攻击的最大速率 (Maximum rate of attack)
- 攻击目标(区域、主机或 IP 地址)(Attack target)
- 匹配该攻击的规则(ID 和描述)(Rule that matched the attack)
- 规则重写(如果有)(Rule override, if any)
Cloudflare 会自动向 Magic Transit 和 Spectrum BYOIP 客户发送每周检测到并缓解的 DDoS 攻击摘要。WAF/CDN 客户可以获取月度应用安全报告。更多信息请参阅 DDoS 报告 (DDoS reports)。
要设置通知:
-
在 Cloudflare 仪表板中,前往 Notifications(通知) 页面。
Go to Notifications ↗ -
选择 Add(添加)。
-
根据你的套餐和服务,选择可用的 DDoS 警报之一:
- HTTP DDoS Attack Alert
- Layer 3/4 DDoS Attack Alert
- Advanced HTTP DDoS Attack Alert
- Advanced Layer 3/4 DDoS Attack Alert
-
输入通知名称,以及(可选)描述。
-
为通知配置投递方式。可用的投递方式取决于你的 Cloudflare 套餐。更多信息请参阅 Cloudflare Notifications。
-
如果你正在为某个高级 DDoS 攻击警报创建通知,请选择 Next(下一步),并定义将用于筛选你将收到的通知的参数。
-
选择 Save(保存)。
要编辑、删除或禁用通知,请前往您的账户通知页面 ↗。
Cloudflare 可以针对不同类型的 DDoS 攻击警报发布通知。
HTTP DDoS Attack Alert
Who is it for?WAF or CDN customers who want to receive a notification when Cloudflare has mitigated HTTP attacks that generate more than 100 requests per second.
Other options / filtersNone.
Included withAll Cloudflare plans.
What should you do if you receive one?No action needed. Refer to DDoS alerts for more information.
Layer 3/4 DDoS Attack Alert
Who is it for?BYOIP and Spectrum customers with Network Analytics who want to receive a notification when Cloudflare has mitigated attacks that generate an average of at least 12,000 packets per second over a five-second period, with a duration of one minute or more.
Other options / filtersNone.
Included withPurchase of Magic Transit and/or BYOIP.
What should you do if you receive one?No action needed. Refer to DDoS alerts for more information.
高级 DDoS 攻击警报支持附加的配置,允许您过滤想要接收的通知。
Advanced HTTP DDoS Attack Alert
Who is it for?WAF or CDN customers with the Advanced DDoS Protection subscription who want to receive a notification when Cloudflare has mitigated attacks that generate more than the configured number of requests per second (100 rps by default).
Other options / filtersYou can choose when to trigger a notification.
Available filters include:
- The zones in the account for which you wish to receive notifications.
- The specific hostnames for which you wish to receive notifications.
- The minimum requests-per-second rate that will trigger the alert (100 rps by default).
Enterprise plans with the Advanced DDoS Protection add-on.
What should you do if you receive one?No action needed. Refer to DDoS alerts for more information.
Advanced Layer 3/4 DDoS Attack Alert
Who is it for?BYOIP and Magic Transit customers with Network Analytics who want to receive a notification when Cloudflare has mitigated attacks that generate more than the configured number of packets per second (12,000 pps by default).
Other options / filtersYou can choose when to trigger a notification.
Available filters include:
- The IP prefixes for which you wish to receive notifications.
- The specific IP addresses for which you wish to receive notifications.
- The minimum packets-per-second rate that will trigger the alert (12,000 pps by default).
- The minimum megabits-per-second rate that will trigger the alert.
- The protocols for which you wish to receive notifications (all protocols by default).
If you specify multiple filters, Cloudflare applies an AND logic. This means the alert will only trigger if all filters you set are true. Keep this in mind when setting up this alert with more than one filter.
Purchase of Magic Transit and/or BYOIP (Enterprise plans).
What should you do if you receive one?No action needed. Refer to DDoS alerts for more information.
您还会收到针对具有 Log(记录) 操作之规则的警报,其中包含有关触发该警报内容的信息。
可用的警报取决于您的 Cloudflare 套餐和订阅的服务:
| 警报类型 | WAF/CDN | Spectrum | Spectrum BYOIP | Magic Transit |
|---|---|---|---|---|
| HTTP DDoS Attack Alert | 是 | – | – | – |
| Advanced HTTP DDoS Attack Alert | 是1 | – | – | – |
| Layer 3/4 DDoS Attack Alert | – | 是2, 3 | 是 | 是3 |
| Advanced Layer 3/4 DDoS Attack Alert | – | – | 是2 | 是2 |
1 仅适用于订阅了高级 DDoS 防护的 Enterprise 客户。
2 仅适用于 Enterprise 计划。
3 请参阅终注与补充说明获取其他注意事项。
下图显示了通过电子邮件发送的通知示例:
要调查可能正在进行的攻击,请选择 View Dashboard(查看仪表板)。要前往 Cloudflare 仪表板中的规则详情,请选择 View Rule(查看规则)。
- 使用分配的 Cloudflare IP 地址的 Spectrum 和 Magic Transit 客户将收到网络层(L3/4)DDoS 攻击警报,其中被攻击的目标是 Cloudflare IP 或前缀。如果您已将您自己的 IP (BYOIP) 接入 Cloudflare Spectrum 或 Magic Transit,您将看到您自己的 IP 地址或前缀作为被攻击的目标。
- 在某些情况下,HTTP DDoS 攻击警报将引用被攻击的区域 (zone) 名称,而不是被攻击的主机名。当攻击指纹不包含有关被攻击主机名的信息时会发生这种情况,因为主机名不是识别攻击请求的强指标。有关攻击指纹的更多信息,请参阅DDoS 防护工作原理。
- DDoS 警报目前仅适用于由 DDoS 托管规则集 检测并缓解的 DDoS 攻击。目前,由高级 TCP 防护、高级 DNS 防护或可编程流防护系统检测并缓解的 DDoS 攻击尚不支持警报。
- 您在同一一小时时间段内不会收到重复的 DDoS 警报。
- 如果您针对同一种类的攻击配置了多个警报类型(例如,同时配置了 HTTP DDoS Attack Alert 和 Advanced HTTP DDoS Attack Alert),您可能会在发生攻击时收到多条通知。为了避免收到重复的通知,请删除其中一个已配置的警报。