CTDR predefined detection rules optimized
Dear Alibaba Cloud users,
To enhance the configuration experience for threat detection predefined rules, we will optimize certain predefined detection rules of Cloud Threat Detection and Response (CTDR) on March 14, 2025, UTC+8.
Change details
The following predefined detection rules will be adjusted:
Rule name
The following rules will be renamed:
|
Current name |
Adjusted name |
|
Affected Host of Outbound Connection Alert in Cloud Firewall |
Firewall Alert Malicious Outbound Connection IP Associated with Host Outbound IP |
|
Host Connect The Malicious IP (WAF Attack Intelligence) |
WAF Alert Malicious Payload IP Associated with Host Outbound IP |
|
Host Connect The Malicious Domain (WAF Attack Intelligence) |
WAF Alert Malicious Payload DNS Associated with Host DNS Request |
|
Java Expression Vulnerability Attack Success |
Web Vulnerability Exploitation Attack Payload Associated With Host Process Startup Behavior |
Rule merge
The following rules will be merged:
|
Current rule |
Merged rule |
|
JNDI Attack Success (IP Association) |
Web Vulnerability Exploitation Attack Payload IP Associated with Host Outbound IP |
|
Log4j2 Attack Success (IP Association) |
|
|
JNDI Attack Success (Domain Association) |
Web Vulnerability Exploitation Attack Payload DNS Associated with Host DNS Request |
|
Log4j2 Attack Success (Domain Association) |
Change impacts
-
Rule quantity: The total number of predefined detection rules will decrease from 10 to 8.
-
Unaffected rules:
-
Brute Force Cookie Behavior (Shiro Vulnerability Attack)
-
Extremely Long Cookie Request (Shiro Vulnerability Attack)
-
This optimization does not affect event generation or the enabling status of predefined rules.
Reference
For more information about CTDR predefined detection rules, see Configure threat detection rules.