Abnormal Log-in

Last Updated At: 2025-10-15 16:09:52

This document describes the functions and operations related to abnormal log-in.

Overview

When a server log-in behavior that does not meet the allowlist condition (common source IP, common username, common log-in location, common log-in time) is detected, an abnormal log-in alarm will be generated. If the source IP of the abnormal log-in is from an overseas IP (including Hong Kong, Macao, and Taiwan) or a malicious IP in threat intelligence, it will be marked as High Risk. Otherwise, it will be marked as Suspicious.

Restriction Description

  • Hosts with the CWP client installed (client online) will monitor abnormal log-in behaviors in real time.
  • The CWP console only retains abnormal log-in events in the last 6 months, and expired event data will no longer be displayed.

Operation Guide

  1. Log in to the tenant-side console of CWPP.
  2. In the left sidebar, select Intrusion Detection > Abnormal Login. Each function is described as follows.

Alarm List

On the alert list page, you can view and process abnormal login risks detected by CWPP.

Field Description:

  • Host name/instance ID: the server that has been abnormally logged in.
  • IP address: the server IP address that has been abnormally logged in.
  • Source IP address: login source IP, generally company network egress IP or network proxy IP.
  • Origin: the region of the login source IP.
  • Login username: the login username used when successfully logging in to the server.
  • Log-in time: the time of successful log-in to the server (time zone time on the server).
  • Danger level: suspicious/high risk.
  • status
    • Abnormal login: This log-in involves an abnormal region, abnormal username, abnormal login time, or source IP address login.
    • Allowlisted: The login source IP has been added to the allowlist (a combination of login source IP, login username, login time, common login location, and effective scope constitutes the allowlist determination rules).
    • Processed: The user has manually processed and marked the event as processed.
    • Ignored: User has ignored this alarm event.
  • Perform operations
    • Handle
      • Mark as processed: If you have manually processed this risk event, you can mark the event as processed.
      • Add to allowlist: After the add to allowlist operation, no Alarm will be triggered when the same event occurs again. Proceed with caution.
      • Ignore: Only ignore this alarm event. Alarm will still be triggered for the same event.
      • Delete a record: Delete the event record. The console will no longer display it. Deleted records cannot be restored. Proceed with caution.

Allowlist Management

On the allowlist management page, you can add/delete/modify/search for the allowlist of abnormal log-ins.
Field Description:

  • Server IP/name: The server where the allowlist is effective.
  • Source IP: allowlisted log-in source IP.
  • Common login location: The login location added to the allowlist.
  • Login username: allowlisted username.
  • Log-in time: allowlisted log-in time period.
  • Creation time: The creation time of this allowlist.
  • Modification time: The last time the allowlist was modified.
  • Perform operations
    • Edit: You can re-edit the login source IP, login username, login time, common log-in location, effective scope, etc.
    • Delete: You can perform deletion operations on the allowlist.

FAQs

How to Handle after Receiving an Abnormal Login Alert?

Determine whether the log-in behavior is your operation.

  • If it is your own login behavior and you don't want to see the Alarm anymore, click Handle and select Add to Allowlist. Configure the common log-in source IP, login username, login location, login time, and effective scope.

Log-in source IP is empty: It means that no alarm will be generated when IPs from all sources log in to the server.
Log-in username is empty: It means that no alarm will be generated when any username logs in to the server.
Log-in location is empty: It means no alarm will be generated regardless of the log-in location.
Log-in time is empty: It means no alarm will be generated regardless of the log-in time.

Note:

Login source IP, login username, login location and login time cannot be empty at the same time.

  • If the login is not one's action, please change server log-in password immediately (suggested modification: a strong password of more than 10 characters, including uppercase and lowercase letters and special characters).
    If the server has been logged in abnormally, the logging-in user may have intruded on your server and left malicious files. It is recommended that you immediately perform file detection and elimination, vulnerability detection, and baseline detection to strengthen your server security.

How to Set Up the Allowlist to Meet the Needs of Most Users?

  • Scenario 1: Log-in sources from a static IP range can use any username to log in to the server without generating abnormal log-in alarms.
    You can input the IP range in the login source IP and select the effective server range.
  • Scenario 2: The log-in source IP is dynamically changing. To support IPs from Hong Kong (China) as the log-in location to log in to the server using any username at any time without generating abnormal log-in alarms.
    You can select Hong Kong Special Administrative Region in the common log-in location and select the effective server range.

    Note:

    Login conditions support combination.

How to Turn Off Abnormal Log-In Alarms?

Please go to Settings Center > Alarm Settings to turn off the abnormal log-in alarm switch. If you keep the alarm switch on, it is recommended to tick the high-risk option to only trigger alarms for high-risk abnormal log-in behaviors.