tencent cloud

Web Application Firewall

AI Policies

ダウンロード
フォーカスモード
フォントサイズ
最終更新日: 2026-09-16 10:35:11
AI翻訳
This document introduces the AI policy module of BOT traffic management. This feature leverages Tencent's nearly two decades of network security and BOT combat experience, and builds on AI technologies and Tencent's risk control practices to transform risk control features and anti-fraud experience into an AI policy model for rapid identification of malicious visitors. It rapidly identifies and handles BOTs, Advanced Persistent Threat BOTs, and distributed BOTs detected based on accumulated combat experience.

Prerequisites

Purchase WAF and BOT traffic management, and enable the BOT rule management switch for the domain that has been connected to WAF.

Protection configuration

1. Log in to the WAF console, and choose BOT and Business Security in the left sidebar.
2. On the BOT and Business Security page, select the domain to protect in the upper-left corner, and enable BOT Management.
3. In Global Settings, click Go to Configuration in the Intelligent Analysis module.
4. Click AI Policy. On the AI Policy page, if false positives are found in AI detection, click the policy and add the URL to the allowlist. This operation allows targeted allowlisting for specific URLs, effectively reducing abnormal interception caused by high access frequency of core business or callback business, thereby lowering the false positive rate.
Note:
The AI policy allowlist here only affects the AI policy module and does not affect the normal detection of other modules.
Parameter description:
Policy Name: The name of the policy.
Rule Description: The description of the policy.
Allowlisted URL: The allowlist path for the AI policy, which affects the scoring results of the AI policy.
Rule Switch: The switch for the AI policy allowlist. When the switch is enabled, the current AI policy allowlist takes effect. When a URL matches the AI policy allowlist, the AI policy does not increase its score, and its BOT evaluation score is provided by threat intelligence and intelligent statistics.
5. After completing the AI policy configuration, go to Scenario Management, select the target scenario, and click View Configuration on the right.
6. On the scenario details page, click the switch of the AI policy module to enable the AI policy module for this scenario.

AI Policy Practice Tutorial

The AI policy leverages historical BOT combat experience and operational insights from the BOT attack and defense lab to quickly identify common BOTs and Advanced Persistent Threat (APT) BOTs. Therefore, it is recommended to enable the AI policy under all circumstances. Additionally, requests from business callback APIs should be added to the AI policy allowlist.


ヘルプとサポート

この記事はお役に立ちましたか?

フィードバック