About Security Analysis

최신 업데이트:2026-08-20 16:25:51

Reading time: About 2 minutes

Security Analysis provides in-depth visual analysis tools for website security operations scenarios. It helps you gain insight into traffic trends, identify threats, and continuously optimize your security protection strategy based on real traffic data.

Note: Security Analysis is currently available to select users only. If you need access, contact technical support to request activation.

Two Core Modules

Module Coverage Primary Use
Request Traffic All HTTP requests (including legitimate traffic that was not blocked) Analyze traffic baselines and trace attacks that bypassed existing protection
Attack Events Requests that matched a security policy (DDoS, WAF, etc.) Evaluate protection effectiveness, investigate false positives, and fine-tune policies

Applicable Scenarios

When to use Security Analysis (Request Traffic):

  • You suspect an attack bypassed your existing protection policies (no matching entry in Attack Logs, but your business was affected)
  • You need to understand your normal traffic baseline to inform the configuration of custom rules or rate limiting
  • You want to analyze the composition of traffic sources during a specific time period

When to use Security Analysis (Attack Events):

  • You want to evaluate how effectively each security policy performed during a specific attack
  • You want to investigate whether a specific policy is generating a large number of false positives
  • You want to understand attack characteristics (attack paths, attack tools, and source distribution)

Differences from Attack Logs

Comparison Attack Logs Security Analysis
Data Scope Only requests that matched a security policy All requests & requests that matched a security policy
Data Precision Full attack log data Sampled log data
Analysis Granularity Details of individual requests Aggregated trends and Top rankings
Applicable Scenario View attack log details across all hostnames In-depth analysis of abnormal traffic for a single hostname, and false-positive review

About Data Sampling: Security Analysis uses log sampling to ensure fast page response times. The sampling rate is dynamically adjusted based on the hostname’s request volume (100%, 10%, or 1%). Top statistics are calculated from sampled data, so results are representative but not fully precise.

이 문서의 내용이 도움이 되었습니까?
아니오
정상적으로 제출되었습니다.피드백을 주셔서 감사합니다.앞으로도 개선을 위해 노력하겠습니다.