> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/product-guides/network-ddos/interface/attacks.md).

# Attacks

<figure><img src="/files/FWCGfIj0YeWkoDs2Tmtn" alt=""><figcaption></figcaption></figure>

Attacks are displayed in two ways: in the initial overview, and with details.

{% hint style="info" %}
Entries are added to this list only when Network DDoS is in [Attack mode](/product-guides/network-ddos-v3/introduction.md#three-modes-of-security-posture).
{% endhint %}

## Overview Display

### **Date**

Date and time of DDoS attack.

### **Type**

Type of DDoS attack.

### **Ticket ID**

Displays Attack Ticket ID. Should be added to any tickets referring to attacks.

### **Prefix**

The IP address that was under attack.

### **Duration**

Displays attack durations.

### **Impact Mbit**

Displays the peak bit rate of traffic observed during the attack.

### **Impact Packets**

Displays the peak packets per second observed during the attack.

### **Details (**![](/files/Vipmju7OJxJPFYXFtgJq))

Redirects to [Attack Details](#id-infrastructureddos-attacks-attackdetails).

### **Notification History (**![](/files/YZXT2i4Tc1VZMkq7MfaY)**)**

Redirects to [Alarming](/administration/account/interface/alarming.md).

***

## Attack Details Display <a href="#id-infrastructureddos-attacks-attackdetails" id="id-infrastructureddos-attacks-attackdetails"></a>

### **DDoS Attack with ID**

<div align="left"><figure><img src="/files/L0YvRvYQa6qlANjEYe2y" alt=""><figcaption></figcaption></figure></div>

Displays DDoS Attack ID. Please add this number to support tickets concerning the attack.

### **Download Report (**<img src="/files/8o14ZCOgUcyr3YNxKlk9" alt="" data-size="line">**)**

Downloads DDoS Attack Report as PDF file.

### **Summary**

<figure><img src="/files/OfP8l5ayZydtadPXh4h9" alt=""><figcaption></figcaption></figure>

Summarizes attack details.

### **Alert Traffic in Mbit**

<figure><img src="/files/rHcwfQ5ifx44GhdL73C1" alt=""><figcaption></figcaption></figure>

Displays the attack traffic in Mbit for each attack vector in the measured period.

***

### **Scrubbing Centers**

<figure><img src="/files/Rn7HEF4joAUeedJiLqpf" alt=""><figcaption></figcaption></figure>

Displays all scrubbing centers over which affected traffic was routed. Inbound traffic to Link11 will be directed across the Link11 backbone from the Point of Presence closest to the client, to the Scrubbing Center a customer is connected to. Final processing and clean traffic forwarding will be done by the connected Scrubbing Center. The Scrubbing Centers widget provides insight into the distribution of traffic globally.

### **Attack Characterization**

<figure><img src="/files/KrH2PS5DUxCmfCujJvcf" alt=""><figcaption></figcaption></figure>

Summarizes attack characteristics by adding up all unique IPs, showing a distribution of used protocols and source ports attacked.

### **Source Countries**

<figure><img src="/files/6bNWTrcEnV3j5nwc4non" alt=""><figcaption></figcaption></figure>

Displays all countries from which the attack originated in percentage by location of their source network.

### **Packet Size Distribution**

<figure><img src="/files/0XwwmfeVrOBH02eAKEwR" alt=""><figcaption></figcaption></figure>

Displays the packet size distribution in bytes across all protocols used.

### **Source Networks**

<figure><img src="/files/oHgwL5IVhJCId1Rnw5ST" alt=""><figcaption></figcaption></figure>

Displays the distribution of the attack source networks in percentage.

### **Blocked IPs**

<figure><img src="/files/OK956TrGs20YkejKncLB" alt=""><figcaption></figcaption></figure>

Displays all blocked IPs with their timestamps and the blocking reason.
