What should I do if the Tencent Cloud Alibaba Cloud server is driven into a black hole?

What should we do when the Tencent Cloud Tencent Cloud server is driven into a black hole? First of all, we need to know the following.

What is a "black hole"?

Black hole refers to that when the server's attack traffic exceeds the black hole threshold of the local computer room, the cloud computing service provider blocks the server's external network access. When the server enters the black hole for a period of time, if the system monitors that the attack traffic stops, the black hole will be automatically unblocked.

I have entered a "black hole", what should I do?

Since the black hole is a service purchased by major cloud computing service providers from operators (China Unicom, China Telecom, China Mobile), and the operator has strict restrictions on the time and frequency of black hole release, the black hole status cannot be manually released, and it is necessary to wait patiently for the system to automatically release the black hole. unblock.

Why is the "black hole" strategy needed?

A DDoS attack not only affects the victim, but can also have a severe impact on the entire cloud network. Moreover, DDoS defense requires costs, the biggest of which is the cost of bandwidth. Bandwidth is purchased by cloud computing service providers from operators such as China Telecom, China Unicom, and China Mobile. Operators will not clean up DDoS attack traffic when calculating bandwidth fees, but directly charge cloud computing service providers for bandwidth.

Cloud computing service providers will try their best to defend against DDoS attacks for their users free of charge while controlling costs, but when the attack traffic exceeds the threshold, cloud computing service providers will block the traffic of the attacked IP to reduce the bandwidth cost of cloud computing service providers.

How long does it take for a black hole to unwind on its own?

The service provider generally defaults to a black hole duration of 2.5 hours, and unblocking is not supported during the black hole period. The actual black hole duration depends on the attack, ranging from 30 minutes to 24 hours. The duration of the black hole is mainly affected by the following factors: whether the attack continues. If the attack continues, the black hole time will be extended, and the black hole time will be recalculated from the extended moment. Whether the attacks are frequent, if a user is attacked for the first time, the black hole time will be automatically shortened; on the contrary, the user who is frequently attacked has a higher probability of being continuously attacked, and the black hole time will be automatically extended.

What should I do if the cloud server is hit into a black hole by ddos?

You can contact me to solve the black hole for you in seconds, but if you don't do defense, it's just a meaningless cycle to be hit and enter the black hole after solving it. So how to do protection? Let me introduce to you:

1. High-defense IP High-defense IP can protect any business.

2. Anti-Defense CDN Anti-Defense CDN is for website business, and the price is cheaper than Anti-Defense IP.

3. Game Shield Our Game Shield is billed by daily activity, regardless of DDOS and CC attack strength, but the premise is that you are putting in the game business.

If the Alibaba Cloud ECS cloud server encounters a DDoS attack, by default, Alibaba Cloud Cloud Shield provides free protection with a 5G quota by default. Once the quota is exceeded, the ECS cloud server will trigger a black hole. After the ECS enters the black hole, it will disconnect all external network links. So if our server is attacked and locked into the black hole of Alibaba Cloud, what should we do? what to do?

Generally speaking, after our server enters the black hole, we cannot apply for the release of the black hole and can only be automatically released. The default black hole time is 2.5 hours. The actual black hole duration depends on the attack situation, ranging from 30 minutes to 24 hours. If the attack continues, the black hole duration will be extended. If you urgently need to solve the black hole, you can contact us, and YI Network can help you solve the black hole in seconds.

At this point, someone may ask me what should I do if I solved the black hole and he continues to attack me. Here I can recommend to you the high-defense IP of our Ant Network. The distributed nodes hide your source IP and lead the attack to our nodes. This will not have any impact on your server, and all business can be carried out urgently.

Guess you like

Origin blog.csdn.net/XiaoYiLiangZai/article/details/124491642