☰

Detection

Detection

Overview

Origin Protection Detection API

Version information

Version : 1.0.0.BETA

License information

Terms of service : https://www.nexusguard.com/

URI scheme

BasePath : /api
Schemes : HTTPS

Paths

Sets the detection mode.

POST /specp/op/site/{site_id}/network/{network_id}/host/{host_id}/detection/mode

Description

Sets the detection mode.

Parameters

Type Name Description Schema
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query detection_level
optional
Object detection level. Valid values: network, host. Default is host. This parameter can be ignored when the current object is of type Host. enum (host, network)
FormData mode
required
Detection mode: 0=normal, 1=rapid, 2=smart. enum (0, 1, 2)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Sets the detection overview switch.

POST /specp/op/site/{site_id}/network/{network_id}/host/{host_id}/detection/overview_switch

Description

Sets the detection overview switch.

Parameters

Type Name Description Schema
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query detection_level
optional
Object detection level. Valid values: network, host. Default is host. This parameter can be ignored when the current object is of type Host. enum (host, network)
FormData item
required
Overview policy switch name.
- ntif_switch: Takes effect when the mode is either normal or rapid, IPv6 is not supported
- signature_ddos_update: Takes effect when mode is either normal or rapid
- smart_policy_mode: Takes effect when smart_filter_app_is_installed=1, IPv6 is not supported
- signature_ntif_update: Takes effect when mode is either normal or rapid, IPv6 is not supported
- ddos_switch: Takes effect when detection_level is network and mode is either normal or rapid, or when detection_level is host
- blackhole_switch: Takes effect when detection_level is host
enum (ntif_switch, signature_ddos_update, smart_policy_mode, signature_ntif_update, ddos_switch, blackhole_switch)
FormData item_status
required
Policy switch status: 0=off/manual, 1=on/auto. Only when detection_level is host, mode is normal, ip type is IPv4, and item is signature_ddos_update, the corresponding switch status is: 0 = off, 1 = manual, 2 = auto. enum (0, 1, 2)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Sets the detection policy.

POST /specp/op/site/{site_id}/network/{network_id}/host/{host_id}/detection/policy

Description

Sets the detection policy.

Parameters

Type Name Description Schema
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query detection_level
optional
Object detection level. Valid values: network, host. Default is host. This parameter can be ignored when the current object is of type Host. enum (host, network)
FormData policy_content
required
JSON string for policy configuration, the threshold value, e.g., 1K 1M, etc.
Object fields:
- detection_mode_threshold_policy: rapid_end_time is effective only when mode=rapid.
Example:
{“start_time”:60,“end_time”:600,“confidence_setting”:“customized”,“confidence_threshold”:80,“rapid_end_time”:600}
Constraints:
start_time must be one of [60, 120, 180]
end_time must be one of [600,900,1200,1800,3600]
confidence_setting must be one of [“off”, “auto”, “customized”]
confidence_threshold must be between 0 and 100.
rapid_end_time must be one of [600,900,1200,1800,3600]
- blackhole_policy:
Example:
{“blackhole_bps”:“2K”,“blackhole_pps”:“20K”,“blackhole_time”:60}
Constraints:
blackhole_time cannot be less than 60
- smart_policy:
Example:
{“low_bps”:“2K”,“low_pps”:“2K”,“high_bps”:“20K”,“high_pps”:“20K”}
- ntif_policy:
Example:
{“signature_type”:“botnet”,“signature_key”:“g_0”,“low_pps”:“2K”,“high_pps”:“20K”,“is_enabled”:1}
Constraints:
is_enabled must be one of [0,1]
- ddos_policy:
Example:
{“signature_type”:“tcp”,“signature_key”:“tcp_rst”,“low_pps”:“2K”,“high_pps”:“20K”,“is_enabled”:1}
Constraints:
is_enabled must be one of [0, 1, 2]. The value 2 is available only when detection_level is host and mode is normal. When the current mode is normal and is_enabled is 2, only is_enabled takes effect in the modified policy; other threshold configurations do not take effect.
string
FormData policy_type
required
Protection policy type, supports the following types:
- detection_mode_threshold_policy: Takes effect when the mode is either normal or rapid
- blackhole_policy: Takes effect when detection_level is host and blackhole_switch=1
- smart_policy: Takes effect when smart_policy_mode=0, IPv6 is not supported
- ntif_policy: Takes effect when ntif_switch=1, IPv6 is not supported
- ddos_policy: Takes effect when ddos_switch=1
enum (detection_mode_threshold_policy, blackhole_policy, smart_policy, ntif_policy, ddos_policy)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets the info of detection policies.

GET /specp/op/site/{site_id}/network/{network_id}/host/{host_id}/detection/policy

Description

Gets the info of detection policies.

Parameters

Type Name Description Schema
Path host_id
required
Unique identifier of a host. string
Path network_id
required
Unique identifier of a network. string
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query detection_level
optional
Object detection level. Valid values: network, host. Default is host. This parameter can be ignored when the current object is of type Host. enum (host, network)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
Detection template policy information. result

result

Name Description Schema
blackhole_policy
optional
The Blackhole detection policy. Takes effect when the blackhole_switch is 1. blackhole_policy
ddos_policy
optional
The DDoS attack detection policy. When ddos_switch is 1, all policies take effect if mode is normal or rapid, regardless of whether detection_level is network or host. When mode is smart, only the total_traffic policy takes effect. < ddos_policy > array
detection_mode_threshold_policy
optional
Detection mode threshold. detection_mode_threshold_policy
mode
optional
For the detection mode, 0 represents normal mode, 1 represents rapid mode, and 2 represents smart mode. integer
ntif_policy
optional
The NTIF attack detection policy. Takes effect when the ntif_switch is 1 and the mode is either normal or rapid. < ntif_policy > array
overview_switch
optional
Overview switch status. overview_switch
smart_filter_app_is_installed
optional
SMART Filter app installation status: 1 for installed, 0 for not installed. integer
smart_policy
optional
S.M.A.RT policy threshold. Takes effect when smart_policy_mode=0. smart_policy

blackhole_policy

Name Description Schema
blackhole_bps
optional
The bps threshold value, e.g., 1K 1M, etc. string
blackhole_pps
optional
The pps threshold value, e.g., 1K 1M, etc. string
blackhole_time
optional
Duration, in seconds. integer

ddos_policy

Name Description Schema
high_bps
optional
The high end of the bps threshold value, e.g., 1K, 1M, etc. This value is supported when signature_key is set to total_traffic. string
high_pps
optional
The high end of the pps threshold value, e.g., 1K 1M, etc. string
is_enabled
optional
Policy detection switch. 0 represents off, 1 represents manual, 2 represents auto. integer
low_bps
optional
The low end of the bps threshold value, e.g., 1K, 1M, etc. This value is supported when signature_key is set to total_traffic. string
low_pps
optional
The low end of the pps threshold value, e.g., 1K 1M, etc. string
signature_key
optional
Protocol submodule signature key. string
signature_name
optional
Protocol submodule signature name. string
signature_type
optional
Detection module protocol, e.g., tcp, udp, icmp, etc. string

detection_mode_threshold_policy

Name Description Schema
confidence_setting
optional
The Normal Plus mode type. Valid values: [“off”, “auto”, “customized”]. string
confidence_threshold
optional
Normal Plus threshold. Takes effect when confidence_setting is customized. integer
end_time
optional
Attack dies off time. The unit is seconds. Takes effect when the mode is normal. integer
rapid_end_time
optional
Attack dies off time. The unit is seconds. Takes effect when the mode is rapid. integer
start_time
optional
Attack observation time. The unit is seconds. Takes effect when the mode is normal. integer

ntif_policy

Name Description Schema
high_pps
optional
The high end of threshold value, e.g., 1K 1M, etc. string
is_enabled
optional
Policy detection switch. 0 represents off, 1 represents on. integer
low_pps
optional
The low end of threshold value, e.g., 1K 1M, etc. string
signature_key
optional
Protocol submodule signature key. string
signature_name
optional
Protocol submodule signature name. string
signature_type
optional
Detection module name, e.g., botnet, anonymizer, etc. string

overview_switch

Name Description Schema
blackhole_switch
optional
Blackhole detection switch. 0 represents off, 1 represents on. Takes effect when detection_level is host. integer
ddos_switch
optional
DDoS detection switch. 0 represents off, 1 represents on. Takes effect when detection_level is network and mode is either normal or rapid, or when detection_level is host. integer
ntif_switch
optional
NTIF detection switch. 0 represents off, 1 represents on. Takes effect when the mode is either normal or rapid. integer
signature_ddos_update
optional
DDoS signature update mode. 0 represents off, 1 represents manual, 2 represents auto. Takes effect when mode is either normal or rapid. integer
signature_ntif_update
optional
NTIF signature update mode. 0 represents off, 1 represents on. Takes effect when mode is either normal or rapid. integer
smart_policy_mode
optional
S.M.A.RT policy mode. 0 represents manual, 1 represents auto. Takes effect when smart_filter_app_is_installed=1. integer

smart_policy

Name Description Schema
high_bps
optional
The high end of bps threshold value, e.g., 1K 1M, etc. string
high_pps
optional
The high end of pps threshold value, e.g., 1K 1M, etc. string
low_bps
optional
The low end of bps threshold value, e.g., 1K 1M, etc. string
low_pps
optional
The low end of pps threshold value, e.g., 1K 1M, etc. string

Produces

Security

Type Name
apiKey ApiKeyAuth

Definitions

Result

The returned result.

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Security

ApiKeyAuth

Type : apiKey
Name : access_token
In : QUERY