Currently, common hijacking phenomena are divided into two types: DNS hijacking and content hijacking. Tingyun Network can monitor and provide early warning for both hijacking phenomena.
By adding an IP whitelist, set the IP range of the target host, and compare the monitoring results with the whitelist to determine whether DNS hijacking has occurred. At the same time, the system will send alert emails and text messages to relevant personnel. The alert content includes: hijacking city, time period, quantity type, etc.IP whitelist customers can batch import the IP libraries of their own websites through the Tingyun Network system. If the IP that appears during the monitoring process is not in these libraries, we will judge it to be DNS hijacking.
By setting the correct content signature database, it is determined whether the current monitoring data contains non-signature database content, and the monitoring results are compared with the content signature database to determine whether it has been hijacked. When terminal netizens visit a website, content that is not the website appears is usually caused by content hijacking. The main phenomena seen include pop-up advertising windows or changes to the entire page content.
The hijacking alert system can record Ping, Traceroute, and Nslookup information when a hijacking occurs, providing website maintenance personnel with specific hijacking evidence to facilitate problem location and later investigation.