You can flexibly manage and control access traffic based on IP addresses, domain names, domain groups, and geographical locations.
The policy assistant allows you to quickly view the protection rule hits and adjust the rules in a timely manner.
Attack Defense
IPS: It provides you with basic protection functions, and, with many years of attack defense experience, it detects and defends against a wide range of common network attacks and effectively protects your assets.
Basic protection rule database: It provides threat detection and vulnerability scan based on the built-in IPS rule database. It can scan traffic for phishing, Trojans, worms, hacker tools, spyware, brute-force attacks, vulnerability exploits, SQL injection attacks, XSS attacks, and web attacks. It can also detect protocol anomalies, buffer overflow, access control, suspicious DNS activities, and other suspicious behaviors.
NOTE:
In the basic protection rule database, you can manually modify protection actions.
You can query rule information by rule ID, signature name, risk level, update time, CVE ID, attack type, rule group, and current action in the basic protection rule database.
Virtual patch database: Hot patches are provided for IPS at the network layer to intercept high-risk remote attacks in real time and prevent service interruption during vulnerability fixing.
New IPS rules are displayed in the virtual patch rule library. A new IPS rule will be added to the virtual patch rule library first and then to the IPS rule library.
Custom IPS signature: You can customize IPS signature rules. CFW will detect threats in data traffic based on signatures.
NOTE:
HTTP, TCP, UDP, POP3, SMTP and FTP protocols can be configured in user-defined IPS signatures.
Sensitive directory scan defense: It defends against scan attacks on sensitive directories on your servers.
Reverse shell defense: It defends against reverse shells.
Anti-virus: This function identifies and processes virus files through virus feature detection to prevent data damage, permission change, and system breakdown.
The antivirus function can check access via HTTP, SMTP, POP3, FTP, IMAP4, and SMB.
Security dashboard: You can easily check attack defense information on the security dashboard and adjust defense policies in a timely manner.
Traffic Analysis
It displays the top traffic data of cloud assets based on sessions.
Inbound traffic: statistics on the total inbound traffic from the Internet to ECSs
Outbound traffic: statistics on the traffic generated when cloud servers proactively access the Internet
Inter-VPC access: inbound and outbound traffic statistics between VPCs
Log Audit
You can check the following types of logs:
Attack event logs, which contain details about intrusions
Access control logs, which contain details about what access is allowed and what is blocked
Traffic logs, which contain the access traffic of specific services
You can use Log Tank Service (LTS) to record all CFW logs, including attack event, access control, and traffic logs.
System Management
You can use the following functions:
Alarm notification: You can use CFW to set notifications for attack logs and traffic threshold-crossing warnings. After the alarm notification function is enabled, IPS attack logs and traffic threshold-crossing warnings will be sent through emails or SMS messages.
Network packet capture: Helps you locate network faults and attacks.
DNS configuration: The DNS server resolves and delivers IP addresses.
Security report: Generates log reports to help you learn about the security status of assets in a timely manner.