Help Center/ Anti-DDoS Service/ User Guide/ Advanced Anti-DDoS User Guide/ Configuring a Protection Policy/ Using Intelligent CC Policies to Defend Against CC Attacks
Updated on 2026-07-06 GMT+08:00

Using Intelligent CC Policies to Defend Against CC Attacks

DDoS attacks are becoming increasingly sophisticated and intelligent. Traditional basic protection cannot distinguish between malicious and legitimate access, which can lead to service interruptions. To effectively defend against CC attacks, you must enable the intelligent CC protection capability of Advanced Anti-DDoS. Once enabled, AAD uses built-in, AI-powered models to analyze traffic to your website, identify CC attacks and abnormal features in HTTP requests targeting your origin server, and generate precise protection and access control rules for your website. This allows AAD to automatically protect your website from CC attacks.

If malicious IP addresses exhibit obvious attack characteristics, intelligent CC automatically adds them to the AAD instance blocklist and discards all requests from these IP addresses within a specified period. You can view or delete blocked IP addresses at any time, manually add other malicious IP addresses to the blacklist, or add specific trusted IP addresses to the whitelist. The system will directly allow all inbound traffic from allowlisted IP addresses.

Limitations and Constraints

This function is in the internal test phase and is available only to some users. If you want to use it, submit a service ticket.

Enabling Intelligent CC

  1. Log in to the AAD console.
  2. In the navigation pane on the left, choose Advanced Anti-DDoS > Protection Policies. The Protection Policies page is displayed.

    Figure 1 Advanced Anti-DDoS protection policies

  3. Click the Web CC Protection tab.

    Figure 2 Web CC protection

  4. After selecting the region and object to be protected, click Set under Intelligent CC.

    Figure 3 Intelligent CC

  5. Set the protection policy as required, as shown in Table 1.

    Figure 4 Setting Intelligent CC
    Table 1 Parameter description

    Parameter

    Description

    Schema

    • Warning: Records log but does not block malicious requests.
    • Protection: Blocks malicious requests and records logs.

    Severity

    • Lenient: Only known malicious attacks are blocked. This mode is suitable for large-scale websites and ensures that normal requests are not mistakenly blocked.
    • Normal: Ideal for scenarios with stable request volumes and redundant server processing performance. When detecting malicious attacks, with intelligent protection enabled, the impact on normal services is little. In this case, you are advised to use this level.
    • Strict: Suitable for scenarios where website performance is poor and protection needs to be stringent. However, some legitimate requests may be mistakenly blocked.

  6. On the Web CC Protection page, set Intelligent CC to to enable protection.