You can configure baseline learning to obtain the baseline values of the services of the Zone by learning cycle and generate learning results based on the learning task.
The basic policies of the Zone have been configured and deployed on the associated devices. For details, see Configuring a Defense Mode.
Devices associated with the Zone have been bound to collectors. For details, see Associating the Collector with Devices.
When the defense threshold is configured: recommended threshold = current threshold x current threshold weight + (baseline value x tolerance value) x (1 - current threshold weight). When the defense threshold is not configured: recommended threshold = baseline value x tolerance value. For details about the tolerance values, see Table 1.
Condition |
Tolerance Value |
|---|---|
Baseline packet rate < 5000 pps or baseline bandwidth < 5 Mbit/s |
200% |
5000 pps ≤ baseline packet rate < 30,000 pps, 5 Mbit/s ≤ baseline bandwidth < 20 Mbit/s, 0 ≤ baseline value of concurrent connections for the destination IP address < 5000, 0 ≤ baseline value of new connections for the destination IP address < 1000, 0 ≤ baseline value of concurrent connections for the source IP address < 200, or 0 ≤ baseline value of new connections for the source IP address < 200 |
160% |
5000 ≤ baseline value of concurrent connections for the destination IP address < 30,000, 200 ≤ baseline value of new connections for the source IP address < 300, or 200 ≤ baseline value of new connections for the source IP address < 300 |
140% |
30,000 pps ≤ baseline packet rate < 12,000,000 pps, 20 Mbit/s ≤ baseline bandwidth < 10240 Mbit/s, 30,000 ≤ baseline value of concurrent connections for the destination IP address < 12,000,000, 1000 ≤ baseline value of new connections for the destination IP address < 12,000,000, 300 ≤ baseline value of concurrent connections for the source IP address < 12,000,000, 300 ≤ baseline value of new connections for the source IP address < 12,000,000, or baseline threshold for the number of SYN packets > 10 |
120% |
False positive occurs if the threshold is too small. Table 2 lists some conditions and the corresponding recommended values.
Condition |
Recommended Value |
|---|---|
Baseline packet rate < 5000 pps |
5000 pps |
Baseline bandwidth < 5 Mbit/s |
5 Mbit/s |
Baseline value of concurrent connections for the destination IP address < 5000 |
5000 |
Baseline value of new connections for the destination IP address < 1000 |
1000 |
Baseline value of concurrent connections for the source IP address < 200 |
200 |
Baseline value of new connections for the source IP address < 200 |
200 |
Baseline threshold for the number of SYN packets < 10 |
10 |
If the current baseline learning type is set to SYN-Ratio Proportion Threshold, the recommended values are listed in Table 3.
The baseline statistics on the number of new connections and concurrent connections based on source IP addresses do not distinguish the destination IP addresses. Therefore, the learned baseline value is greater than the statistics based on a single destination IP address.
After baseline learning is enabled, click Stop to stop baseline learning.
When the baseline learning periods of multiple Zones are set to be the same, select all Zones that need to have baseline learning enabled and click
to set baseline learning in batches. For the parameter description, see Table 5.
Before the first learning cycle ends, baseline learning result from the start time to the current time is displayed. After the first learning period elapses, baseline traffic learning result of the last learning cycle is displayed.
in the Detail column to view the historical traffic curve for baseline learning in the last year and change Current Threshold.After Take effect automatically and Always Effective are selected in a baseline learning task, the system automatically applies the recommended values to defense policies after the baseline learning period ends.
The baseline learning result takes effect only after the corresponding defense item is enabled in defense policies.
When the confirmation mode of baseline learning is automatic, service traffic learning result is automatically applied to the defense policy of the Zone and deployed on the AntiDDoS or AntiDDoS1820-N.
When the automatic confirmation mode is not selected for baseline learning, service traffic learning result needs to be confirmed manually. For details, see Applying Baseline Learning Results.