Distribution of Anomaly/Attack Types

Function

In the anomaly/attack type distribution chart, you can view the proportions of various anomaly/attack types.

Parameter

Table 1 Query parameters of Anomaly/Attack Type Distribution
Parameter Description
Device Select a device from the drop-down list. Total Cleaning and Total Detecting are described as follows:
  • Total (Cleaning):

    Indicates that attack traffic on all cleaning devices is queried.

  • Total (Detecting):

    • If two or more detecting devices in a defense group work in Load Redundancy mode, the maximum anomaly traffic volume in the defense group is queried and the sum of anomaly traffic volumes among defense groups is queried.
    • If two or more detecting devices in each defense group work in Load Balancing mode, the sum of anomaly traffic volumes within each defense group and among defense groups is queried.
Zone Click , select a Zone on the Zone page that is displayed, and then click OK.
Service Select a service or service group from the drop-down list.

For details about service configuration, see (Optional) Creating a Service and a Defense Policy.

IP Address Enter the destination IP address. Both IPv4 and IPv6 addresses are applicable. The anomaly/attack traffic destined for the IP address is queried.
Time Click to select the start time and end time of statistics. Or you can change the time values in corresponding text boxes.

The end time should be later than the start time and the interval cannot be longer than one year.

Example

If the device is set to Total (Cleaning) and the Zone to test, Figure 1 shows anomaly/attack type distribution within a period of time.

Figure 1 Anomaly/attack type distribution (for cleaning devices)

Procedure

  1. Choose Report > Report > Anomaly/Attack Analysis.
  2. Click the Distribution of Anomaly/Attack Types tab.
  3. Set query parameters.
  4. Click Search.

    The distribution of anomalies/attacks that meet the query conditions is displayed.

  5. Optional: Open or save the query results as files, or send queried reports to the specified email address.

    • Click to open or save the query results as PDF files. A maximum of 10,000 entries can be displayed.
    • Click to open or save the query results as EXCEL files. A maximum of 10,000 entries can be displayed.
    • Click to open or save the query results as CSV files. All data except figures can be displayed.
    • Click to enter a recipient mail address and select an attachment format. Then click OK.


Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.