Help Center> Web Application Firewall> Best Practices> Configuring Protection Policies> Configuring CC Attack Protection> Restricting Malicious Requests in Promotions by Using Cookies and HWWAFSESID
Updated on 2024-02-29 GMT+08:00

Restricting Malicious Requests in Promotions by Using Cookies and HWWAFSESID

This topic describes how to configure cookies and HWWAFSESID fields in CC attack protection rules to restrict malicious requests in promotions.

Application Scenarios

Using Cookies (or User IDs) to Configure a Path-based CC Attack Protection Rule

  1. Log in to the management console and connect your website to WAF. For details, see Adding a Domain Name to WAF.

  2. In the Policy column of the row containing the domain name, click the number to go to the Policies page.
  3. In the CC Attack Protection configuration area, toggle CC Attack Protection on if needed. Then, click Customize Rule.

    Figure 1 CC Attack Protection configuration area

  4. In the upper left corner of the CC Attack Protection page, click Add Rule.
  5. Configure a CC attack protection rule using a cookie or user ID to limit traffic to the path. Figure 2 shows an example.

    Set the following parameters based on site requirements:
    Figure 2 Configuring service cookies

  6. Click Confirm.

Using HWWAFSESID to Configure a CC Attack Protection Rule

  1. Log in to the management console and connect your website to WAF. For details, see Adding a Domain Name to WAF.

  2. In the Policy column of the row containing the domain name, click the number to go to the Policies page.
  3. In the CC Attack Protection configuration area, toggle CC Attack Protection on () if needed. Then, click Customize Rule.

    Figure 3 CC Attack Protection configuration area

  4. In the upper left corner of the CC Attack Protection page, click Add Rule.
  5. Configure a CC attack protection rule using HWWAFSESID to limit traffic to the path. For details, see Figure 4.

    • User Identifier: Select Cookie and set it to HWWAFSESID.
    • Other parameters: Set them to meet your service requirements.
    Figure 4 HWWAFSESID-based rate limiting

  6. Click Confirm.