Enable edge security

更新时间:
复制 MD 格式

Traditional Content Delivery Network (CDN) services are often ill-equipped to defend against large-scale network attacks. This is challenging for industries like gaming, finance, government, enterprises, e-commerce, and healthcare, which need services that combine robust security with high-performance content acceleration. Alibaba Cloud DCDN provides an integrated security and acceleration solution. With built-in features like DDoS mitigation, web application firewall (WAF), blacklists and whitelists, and hotlink protection, DCDN protects your applications at the edge in real time.

Security features

Category

Description

References

Network attack protection

DDoS mitigation: DCDN provides DDoS mitigation to minimize the risk of DDoS attacks, reduce business losses, and ensure service availability.

When the system detects a DDoS attack, it automatically reroutes traffic from DCDN to a scrubbing center for mitigation. After the attack subsides, traffic is automatically routed back to DCDN for normal content delivery.

DDoS mitigation at the edge

WAF: DCDN integrates a web application firewall (WAF) at its points of presence (POPs) to protect your applications. WAF identifies malicious patterns in your traffic and forwards only safe, legitimate requests to your origin server. This helps prevent intrusions, protects core business data, and prevents performance degradation from malicious attacks.

Overview of WAF at the edge (New)

Bot management: This feature protects your applications against automated tools and web scraping while allowing trusted crawlers. It offers threat intelligence and AI-powered protection to detect advanced bots and minimize their impact on your business.

Configure the bot management module

Sandbox: If your domain is under attack, such as a DDoS or HTTP flood attack, or experiences a significant, unreported spike in bandwidth or QPS, DCDN reserves the right to add your domain to a sandbox. This action prevents attacks on your domain from affecting the acceleration services for other users.

Sandbox overview

Access control

Referer-based hotlink protection: Controls access by inspecting the Referer header in HTTP requests. You can configure a referer blacklist/whitelist to identify and filter visitors, preventing unauthorized use of your resources.

Configure referer-based hotlink protection

User-Agent whitelist and blacklist: The User-Agent header contains information about the operating system, OS version, browser, and browser version. You can configure a User-Agent blacklist and whitelist to filter requests, restrict access to your DCDN resources, and improve security.

Configure a User-Agent blacklist or whitelist

IP whitelist and blacklist: Filters requests based on the client IP address. You can block or grant access to specific IP addresses to mitigate issues such as malicious IP-based abuse and attacks.

Configure an IP address blacklist or whitelist

URL signing: Provides advanced hotlink protection. This feature verifies encrypted strings and timestamps in signed URLs to protect resources on the origin server more securely and efficiently.

Configure URL signing

End-to-end encryption

End-to-end security: Provides an end-to-end HTTPS acceleration solution that supports SSL certificate upload and management.

Configure an SSL certificate

HTTP/2: Allows clients to use HTTP/2 to access DCDN points of presence (POPs).

Enable HTTP/2

HTTP/3 (QUIC): Clients can connect to DCDN points of presence (POPs) using QUIC for more secure data transmission and efficient resource access.

QUIC