Network Attack

Last Updated At: 2025-10-15 16:09:57

Network attacks, supported by the security attack and defense team's technical support, automatically monitor malicious traffic for you. Combined with malicious behaviors generated during the intrusion process, real-time automated correlation analysis is performed on attacks and alarms, outputting attack traffic data and notifying attack events. This document guides you on how to view and handle network attack alerts.

Restriction Description

  • Detection object: Only supported on Linux hosts of the pro edition/flagship edition.
  • Detection range: Only detects hotspot vulnerability attack behaviors that partially occur with EXP and have successful attack cases in the cloud.
  • Vulnerability defense: Only supported on Linux hosts of the flagship edition.

Defense Status Description

  • Supported vulnerability defense (not enabled): Host security supports defending against this vulnerability, but this host has not enabled defense for it.
  • Supported vulnerability defense (enabled): Host security supports defending against this vulnerability, and this host has enabled defense for it.
  • Vulnerability defense not supported yet: Host security does not support defending against this vulnerability.

    Note:

    • Possible reasons for not enabling vulnerability defense: The defense switch is not enabled, the host is a non-flagship edition, or the host is not in the protection host range.
    • Attack events indicate that there are currently hackers exploiting this vulnerability's attack techniques, but it does not mean that this vulnerability exists on the current machine.

Alert Statistics

  1. Log in to the CWPP tenant-side console. In the left sidebar, select Intrusion defense > Network attack.
  2. On the Network Attack Page, support viewing the vulnerability defense status in network attacks, statistics of pending alert-related data, and the Top 5 situations. Field Description:
  • Vulnerability defense status: Reflect the status of the vulnerability defense switch.
  • Pending network alerts: The current alarm count to be processed.
  • Number of attacked assets: The number of attacked assets involved in the current pending alarms.
  • Number of attacked ports: The number of attacked ports involved in the current pending alarms.
  • Number of attack source IPs: The number of attack source IPs in the current pending alarms.

View Alarms

On the Network Attack Page, support viewing network attack details, including hostname, instance ID, IP, destination port, etc.

Field Description:

  • Hostname/Instance ID: The hostname and instance ID of the affected host.
  • IP: The public network/private network IP of the attack host.
  • Destination port: Attacked port.
  • Source IP/address of the attack: The source IP and location of the attacker.
  • Vulnerability name: Refers to the attack technique used by the attacker to exploit a certain vulnerability, as well as the current status of the vulnerability defense.
  • Attack status: Refers to the result of an attacker's attack, attempted attack (attacked but not successfully attacked), successful attack (confirmed attack).
  • Last attack time: The time when the latest attack behavior was detected.
  • Number of attacks: Cumulative number of identical attacks detected.
  • Processing status: Pending, Processed, Whitelisted, Ignored.
  • Details: Support viewing alarm details, severity description, solution.

Handling Alerts

  1. In the list of network attack alerts, click Handle in the Action column.

    Note:

    Select one or more Alarms, and you can click Mark as processed, Ignore, or Delete records in the upper left corner to perform batch operations.

  1. Support marking pending alerts as processed, enabling vulnerability defense, adding to allowlist, ignoring, and deleting records.
    • Mark as processed: Manually handle the alarm and mark it as "processed" after processing.
    • Add to allowlist: Add the attack source IP to the allowlist. Subsequently, CWPP will no longer trigger an alarm for the cyber attack behavior of this source IP. Proceed with caution.
    • Ignore: Only ignore this alarm. If the same situation occurs again, an alarm will still be triggered.
    • Delete a record: Delete this alarm record. The console will no longer display it. Deleted records cannot be restored. Proceed with caution.