The site detection feature helps you periodically check your website's home page and all site content. It detects potential risks such as home page tampering, trojans, hidden links, illicit content, and terrorist content. The feature provides the specific addresses of non-compliant content to help you view and fix the issues. This topic describes how to configure a site detection task.
Background information
Site detection scans the web pages and images on your website. It is metered by the number of URLs. For a single website, site detection supports a maximum of 100,000 URLs per detection epoch. The feature includes home page detection and full site detection.
- Home page detection: Periodically detects content on your website's home page and displays the latest scan results. The results include threat alerts for home page tampering, trojans, hidden links, illicit content, and terrorist content. The results are rendered in three formats: source code, text, and image. You can use these results for reference and correction.
- Full site detection: Periodically and automatically detects content on all web pages under your website's domain name and displays the latest scan results. The results include threat alerts for trojans, hidden links, illicit content, and terrorist content. The results are rendered in three formats: source code, text, and image. You can use these results for reference and correction.
The site detection feature only supports the subscription billing method. For more information about pricing, see the Site Detection Purchase page.
Step 1: Create a site detection task
When you use the site detection service, keywords must be in UTF-8 format. Added keywords or images take effect within 15 minutes. For example, after you add custom text, the text is applied to your detection task within 15 minutes.
- Purchase a site detection instance.Each instance can be attached to only one site. Enter the root domain of the site. To attach multiple sites, purchase the corresponding number of instances.
- Log on to the Content Moderation console. In the navigation pane on the left, choose .
- On the Instance Management tab, click Purchase Instance.
- On the Site Detection (Subscription) page, configure the parameters as needed, and then click Buy Now to complete the order.
- Attach the site that you want to detect to the instance.
- On the Instance Management tab, find an instance that is in the Not Attached state and click Attach Site in the Actions column.
- In the Attach Site dialog box, configure Protocol, Domain Name, Default Index Page Address, Home Page Detection Interval, and Full Site Detection Frequency based on the descriptions in the following table. Then, click Next.
Configuration Item Description Protocol Select the protocol type. Valid values: - HTTP: Hypertext Transfer Protocol.
- HTTPS: A network protocol that uses Transport Layer Security (TLS) or SSL over HTTP for encrypted transmission and identity authentication.
Note If your website serves significantly different content over HTTP and HTTPS, use two separate instances to attach to the HTTP and HTTPS protocols of your site.Domain Name The domain name of your site. Do not include http://orhttps://in the domain name. If your website has multiple subdomains, enter the root domain.Default Index Page Address The full URL of the site's home page. The URL must be under the domain name that you want to attach. Home Page Detection Interval The interval in hours at which to detect your website's home page. Full Site Detection Frequency The frequency at which to perform a full site detection. Valid values: - Low: once every 7 days
- High: once every day
Note A higher detection frequency consumes more bandwidth and incurs higher bandwidth fees. If your website has a large amount of content and insufficient bandwidth, a high detection frequency may affect the access speed of your website. To avoid affecting website performance, select a lower detection frequency.
- Select a site verification method.In the Verify Site dialog box, select a verification method based on the descriptions in the following table, and then click Verify Now.
Verification Method Description Alibaba Cloud account verification Verifies whether the site (domain name) to be detected is an asset under your current Alibaba Cloud account. Host file verification Follow the on-screen instructions to generate a file in the root directory of the domain's host for verification. CNAME verification Follow the on-screen instructions to add the specified CNAME record to the DNS records of the domain to be detected for verification. HTML tag verification on the website home page Follow the on-screen instructions to modify the HTML source file of the website's home page for verification. Site verification is used to prevent unauthorized detection. If you cannot verify the site immediately, you can click Verify Later to save the entered data. After the verification is passed, the site attachment and detection settings are complete, and the target instance automatically starts the detection task.
- Optional: On the Instance Management page, find an instance that is in the Detecting state. In the Actions column, you can perform the following operations as needed.
Configuration Item Description Pause/Start Detection If you do not want to run a detection at the current time, you can pause it. To resume a paused detection task, start the detection. Set Home Page Tamper-proofing Baseline Confirm the current home page baseline. If you want to change the baseline, you can click Re-scrape Current Home Page to scrape the current home page again and set it as the new baseline. Note When you attach a site and enable detection, the site detection task scrapes the current home page as the baseline to determine whether the home page has been tampered with. If you update the home page content, set the home page tamper-proofing baseline again. This allows the site detection task to re-scrape the current home page.Add Key Monitoring URLs Enter the URLs that you want to detect, with one URL per line. You can add up to 5,000 URLs. If your website has a large amount of content and you are concerned that important URLs might be missed during detection, you can add them as key monitoring URLs. The site detection task prioritizes the detection of these URLs. Edit Site Modify the site attached to the instance and the detection frequency information. Re-verify If your verification expires or you select Verify Later in Step 3 Renew Renew the instance to extend its usage duration. Detach If you no longer want to provide detection services for an attached site, you can detach it. Note After you detach a site, the purchased instance is not released. You can attach it to another site to provide detection services.
Step 2: Configure message notifications
Content Moderation supports message notifications. When a threat is detected on your site, you are notified based on your settings. By default, one message is pushed per day. You can set the message receiving method, account, and receiving time. You can also enable or disable real-time notifications for home page threats. This step is optional. You can configure the settings as needed.
- Log on to the Content Moderation console.
- In the navigation pane on the left, choose .
- On the Site Detection page, click Message Notification.
- On the Message Notification tab, enter the Notification Account information for threat alerts, select a Notification Method, and set the Time Zone, Push Time, and Real-time Message Notification.Note After you enable Real-time Message Notification, the system sends you a message in real time as soon as a threat is detected on the home page. To avoid disturbances, a maximum of one notification is sent per day for a single domain name if multiple threats are detected.
- Click Save to complete the message notification configuration.
Step 3: Configure threat libraries
During site detection, you can add a custom keyword blacklist to detect and block specific words. When you use site detection to check images, you can define specific images as whitelist or blacklist images to filter or block them. This step is optional. You can configure the settings as needed.
- Configure a custom text library
- On the Custom Text Library tab, click Create Text Library.
You can create up to 10 text libraries.
- In the Create Custom Text Library dialog box, set a Name, select the instances to which you want to apply the text library, and then click OK.
- On the Custom Text Library tab, find the new text library and click Manage in the Actions column.
- On the Text Library Management page, click Add Keyword.
- In the Add Keyword panel, enter or import keywords as prompted on the page, and then click OK to add the keywords.
The site detection feature supports importing and exporting text libraries.
- On the Custom Text Library tab, click Create Text Library.
- Configure a custom image library
- On the Custom Image Library tab, click Create Image Library.
You can create up to 10 image libraries.
- In the Create Image Library dialog box, set the Name, Scenario, Detection Result, and Instance for the image library based on the descriptions in the following table. Then, click OK.
Table 1. Create Image Library page parameters Configuration Item Description Name The name used to identify this image library. Scenario Supports the pornography detection and terrorist content scenarios. Detection Result Supports blacklist and whitelist detection results. A blacklist image library is used to block specific unwanted images. A whitelist image library ignores and filters the images you add during detection. Instance The instances to which the image library is applied. Note During site detection, only the instances you select here will use this image library for detection. - On the Custom Image Library tab, find the new image library and click Manage in the Actions column.
- Click Select File and upload local images to the image library.Note Each image library can contain up to 10,000 images.
- On the Custom Image Library tab, click Create Image Library.
Step 4: Review detection results
The Content Moderation site detection feature periodically detects the home page and all site content, including web page source code, text, and images, at the frequency that you set. You can view the home page and full site detection results in the Content Moderation console.
- Log on to the Content Moderation console. In the navigation pane on the left, choose or .View the latest detection results.
- Locate the URL that has a threat and click View Details to confirm the threat content.
- After you resolve the threat, click Handled to complete the process.
- If you disagree with a result, you can click Feedback to report the issue to us. After we confirm the issue, we will optimize and improve the algorithm.