Attack Insights add-on

Attack Insights help you investigate security threats patterns and evolving threats by providing automated analysis of observed traffic activity.

It uses advanced detection models developed by Akamai’s Threat Research Team to identify unusual traffic patterns, potential attacks and suspicious anomalies, helping you understand emerging threats and prioritize further investigation.

It helps you optimize your security posture with:

  • Anomaly detection. Identifies significant deviations in traffic behavior that may indicate an attack.
  • Cross-platform intelligence. Leverages anonymized data across Akamai’s enormous platform to identify broader attack patterns through a uniquely wide lens.
  • Contextualized insights. Provides detailed explanations on why requests may be suspicious, including triggered rules and relevant security events.
  • Response actions. Notifies your security team about detected threats with possible next steps.
  • Event exploration. Lets you drill down into attack details in a single click that automatically sets and displays the relevant filters and views.

You can access Attack Insights from Web Security Analytics by selecting Attack Insights from the view selector or by clicking the lightning icon.

Attack Insight types

Attack Insights includes different insight types that identify specific patterns of suspicious or potentially malicious activity. Each insight provides a detailed analysis of the detected activity, including affected endpoints, traffic patterns, top sources, applicable detection rules, and other relevant context to help you investigate and assess its potential impact. Insight types include:

  • Spikes in Web Application Firewall detections. Detects unusual surges in requests that trigger Web Application Firewall detections for specific endpoints.
  • AI bot traffic spikes. Highlights unusual increases in AI bot traffic targeting your applications.
  • Suspected DDoS attempts. Identifies unusual increases in traffic that may indicate a distributed denial-of-service (DDoS) attack.
  • Account Protector. Surfaces unusual authentication activity detected by Account Protector, such as excessive login requests without a username or unexpected changes in login response patterns.
  • WAF latest threats. Highlights the latest Web Application Firewall threat activity observed across your industry during the past week. Use this insight to stay informed about emerging attack trends that may affect your applications.
  • DDoS latest threats. Identifies the latest distributed DDoS threat activity observed across your industry during the past week.

Did this page help you?