Help Center/ Edge Security/ Best Practices/ CC Attack Protection/ Preventing Bonus Hunting by Configuring Service Cookies and System IDs
Updated on 2024-10-31 GMT+08:00

Preventing Bonus Hunting by Configuring Service Cookies and System IDs

This topic introduces how to configure service cookies and system IDs to restrict malicious bonus hunting and downloads.

Application Scenarios

Using Cookies (or User IDs) to Configure a Path-based CC Attack Protection Rule

  1. Log in to the management console.
  2. Click in the upper left corner of the page and choose Content Delivery & Edge Computing > CDN and Security.
  3. In the navigation pane on the left, choose Website Setting under Edge Security.
  4. In the Policy column of the row containing the target domain name, click the number of enabled protection rules. On the page displayed, confirm that the status of CC attack protection is enabled () and click Customize Rule.

    Figure 1 CC Attack Protection configuration area

  5. In the upper left corner of the CC Attack Protection page, click Add Rule. In the displayed dialog box, specify the path to be protected, configure Rate Limit Mode with service cookies (or user ID), and complete other settings based on your service needs. Figure 2 shows an example rule.

    Figure 2 Configuring service cookies
    • User Identifier: Enter the service cookie or user ID.

  6. Click Confirm.

Using a System ID to Configure a Path-based CC Attack Protection Rule

  1. Log in to the management console.
  2. In the navigation pane on the left, choose Website Setting under Edge Security.
  3. In the Policy column of the row containing the target domain name, click the number of enabled protection rules. On the page displayed, confirm that the status of CC attack protection is enabled () and click Customize Rule.

    Figure 3 CC Attack Protection configuration area

  4. In the upper left corner of the CC Attack Protection page, click Add Rule. Configure a CC attack protection rule using system ID like HWSESID to limit traffic to the path. Figure 4 shows an example rule.

    Figure 4 System ID
    • User Identifier: Enter the system ID as the cookie.

  5. Click Confirm.