近期,我们监测到有部分用户反映其使用的 IP 地址在第三方数据库中被标注为“高风险”。针对此情况,我司技术团队已完成深度排查,现向各位说明如下:
产生原因: 经查,由于前几日我司基础设施遭受大规模 DDoS 攻击,攻击者采用了伪造源 IP 的手段。在攻击期间,网络边界设备在进行防御拦截时产生了大量反向包(Backscatter),导致被部分安全监测节点误判为主动扫描行为。
当前进展: 我们已正式向主要地理位置服务商提交了误报申诉(False Positive Report),要求其清理历史错误数据。
影响说明: 此标注仅为第三方数据库的历史记录误报,不影响您的正常业务使用及服务器本身安全性。
感谢您的理解与信任,我们将持续为您提供稳定、安全的网络环境。
Recently, we have detected that some users have reported their IP addresses being marked as "high-risk" in third-party databases. Our technical team has conducted an in-depth investigation into this matter and would like to provide the following explanation:
Cause: Investigation revealed that our company's infrastructure suffered a large-scale DDoS attack a few days prior, with attackers using spoofed source IP addresses. During the attack, network boundary devices generated a large number of backscatter packets during defense and interception, which were mistakenly identified as active scanning behavior by some security monitoring nodes.
Current progress: We have formally submitted a False Positive Report to the major geolocation service provider, requesting them to clean up the historical erroneous data.
Impact Explanation: This label is merely a false alarm based on historical data from a third-party database and does not affect your normal business operations or the security of the server itself.
Thank you for your understanding and trust. We will continue to provide you with a stable and secure network environment.
Post #174
6.66K
- 👍 12
- ❤ 7
- 👏 4