Help Center/ Cloud Firewall/ User Guide/ Attack Defense/ Configuring Intrusion Prevention/ Configuring Sensitive Directory Scan Defense
Updated on 2026-08-21 GMT+08:00

Configuring Sensitive Directory Scan Defense

Scenario

Enterprise networks often face external malicious scan attacks, especially those targeting sensitive directories on servers. This can lead to the leakage of sensitive information. CFW defends against sensitive directory scan attacks. After this function is enabled, the service can block scan attacks.

This section describes how to configure sensitive directory scan defense.

Notes and Constraints

  • Intrusion prevention does not support decryption detection and defense for TLS- and SSL-encrypted traffic.

Impacts on Services

If IPS basic protection is enabled, a range of possible threats and suspicious traffic will be blocked. To change the protection mode, you are advised to enable the Observe mode and check false alarms for a period of time and then switch to the Intercept mode.

Actions

  • Observe: If the firewall detects a sensitive directory scan attack, it only records the attack in Viewing Attack Event Logs.
  • Block session: If the firewall detects a sensitive directory scan attack, it blocks the current session.
  • Block IP: If CFW detects a sensitive directory scan attack, it blocks the attack IP address for a period of time.

    After Block IP is configured, CFW continuously blocks IP addresses. If address translation or proxy is involved, evaluate the impact of blocking IP addresses with caution.

Enabling Sensitive Directory Scan Defense

  1. Enable at least one type of traffic protection.

  2. Log in to the CFW console.
  3. Click in the upper left corner of the management console and select a region or project.
  4. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  5. In the navigation pane on the left, choose Protection Policies > Attack Defense > Intrusion Prevention.
  6. Ensure Basic Protection is enabled.
  7. In the Sensitive Directory Scan Defense area, click the toggle button. The configuration page will be displayed.
  8. On the Sensitive Directory Scan Defense page, configure the action and threshold.

    Table 1 Sensitive directory scan

    Parameter

    Description

    Action

    • Observe: If the firewall detects a sensitive directory scan attack, it only records the attack in Viewing Attack Event Logs.
    • Block session: If the firewall detects a sensitive directory scan attack, it blocks the current session.
    • Block IP: If CFW detects a sensitive directory scan attack, it blocks the attack IP address for a period of time.
      NOTE:

      After Block IP is configured, CFW continuously blocks IP addresses. If address translation or proxy is involved, evaluate the impact of blocking IP addresses with caution.

    Duration

    If Action is set to Block IP, you can set the blocking duration. The value range is 60s to 3,600s.

    Threshold

    CFW performs the specified action if the scan frequency of a sensitive directory reaches this threshold.

  9. Click OK.

Follow-up Operations

For details about the protection overview, see Event Center. For details about logs, see Viewing Attack Event Logs.

Related Operations

  • Changing the defense action: Click Configure in the Sensitive Directory Scan Defense area. In the displayed dialog box, select an action and click OK.
  • Modifying the threshold: Click Configure in the Sensitive Directory Scan Defense area. In the displayed dialog box, set the threshold and click OK.
  • Disabling sensitive directory scan defense: Click next to Sensitive Directory Scan Defense. In the displayed dialog box, click OK.