Application attack protection
Configure application protection rules around common web threats such as SQL injection, XSS, and file inclusion to filter abnormal requests.
Combine application attack protection, access rules and SCDN acceleration to configure protection before the request reaches the origin server, making security fit the actual business.
Standard and higher plans on every network include WAF. Personal and Basic do not.
From request content to access source, set appropriate rules for different business paths.
Configure application protection rules around common web threats such as SQL injection, XSS, and file inclusion to filter abnormal requests.
Combining rules based on URL, IP, Referer, region, User-Agent and other conditions, and working with black and white lists to refine the access scope.
Combine application request inspection with CC protection policies, and configure processing methods for page access, login portals, and interface calls respectively.
Manage domain names, origin servers, caches and security rules through SCDN, allowing content distribution and application protection to work along the same access path.
Configure rules around key paths such as login, order, and payment callback to verify that normal transaction requests can be completed.
View the solutionDistinguish between user access and system calls, set access control and exceptions by interface, and retain the business's own account and permission verification.
View the solutionConfigure application protection for the official website, event pages and web login interface; game client communication can be combined with SDK shield or DDoS-protected IP solution.
View the solutionSelect a line based on the business access area, and then choose a plan that includes WAF.
| SCDN network | WAF not included | WAF included |
|---|---|---|
| Mainland China | Personal, Basic | Standard, Professional, Business |
| Overseas Optimized | Overseas Personal, Overseas Basic | Overseas Standard, Overseas Professional |
| Asia-Pacific Optimized | Asia-Pacific Personal, Asia-Pacific Basic | Asia-Pacific Standard, Asia-Pacific Professional, Asia-Pacific Business |
Choose Mainland China, Overseas Optimized or Asia-Pacific Optimized routes according to user distribution, and choose Standard and higher plans.
Fill in the domain name and origin server, and configure the resolution according to the console prompts; then set the rules according to the website path, access source and business requirements.
Check login, order placement, interface calls and third-party callbacks; adjust rules and necessary exceptions based on business results.
WAF is included with Standard and higher SCDN plans on every network. Personal and Basic do not include WAF. Check the eligibility marks in the plan table.
After the domain name is connected to the SCDN plan that supports WAF, cache, origin return and application protection rules can be set in the same website configuration. Access policies can be planned separately for static resources and dynamic interfaces.
Configure access rules for compatible HTTP(S) APIs. Test CC challenges and exceptions for system calls and payment callbacks, so browser challenges do not interrupt API traffic. Your application still needs authentication and access controls.
For website acceleration and application layer protection, you can choose the SCDN plan including WAF; multi-region network entrance, own business access and return-to-origin path planning can further evaluate Anycast-Boundless.
Have other questions?Contact a technical advisor
From personal projects to corporate operations, find the protection solution that's right for you.