☰

Detection Template

Detection Template

Overview

Clean Pipe Detection Template API

Version information

Version : 1.0.0.BETA

License information

Terms of service : https://www.nexusguard.com/

URI scheme

Host : api.nexusguard.com
BasePath : /api
Schemes : HTTPS

Paths

Creates a detection template.

POST /spe/customer/{customer_id}/cp/detection/template

Description

This API creates a detection template with the information provided by the user. See notes on individual parameters below.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query description
optional
Description of the template you want to create. The description must be 0-100 characters. string
Query detection_base_template_id
optional
Unique identifier of a detection base template. When this value is provided, the policy of the base detection template will be inherited. Can be obtained by invoking this API integer
Query detection_level
optional
Object detection level. Valid values: network, host. Default is host. This value takes effect when no base detection template is inherited. enum (host, network)
Query ip_type
optional
IP address family for the template, ipv4 or ipv6. Default is ipv4. This value takes effect when no base detection template is inherited. enum (ipv4, ipv6)
Query name
required
Name of the template you want to create. The template name must be 2-40 characters long and may include letters, numbers, spaces, Chinese characters, hyphens, underscores, and dots. string
FormData mode
optional
Detection mode: 0=normal, 1=rapid, 2=smart. The default value is 0. This value takes effect when no base detection template is inherited. enum (0, 1, 2)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Update detection template information.

PUT /spe/customer/{customer_id}/cp/detection/template/{template_id}

Description

Update detection template information.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path template_id
required
Unique identifier of a detection template. integer
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query description
optional
New description for the template. The description must be 0-100 characters. string
Query name
required
New name for the template. The template name must be 2-40 characters long and may include letters, numbers, spaces, Chinese characters, hyphens, underscores, and dots. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Delete detection template.

DELETE /spe/customer/{customer_id}/cp/detection/template/{template_id}

Description

Delete detection template.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path template_id
required
Unique identifier of a detection template. integer
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Produces

Security

Type Name
apiKey ApiKeyAuth

Sets the detection template overview switch.

POST /spe/customer/{customer_id}/cp/detection/template/{template_id}/overview_switch

Description

Sets the detection template overview switch.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path template_id
required
Unique identifier of a detection template. integer
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
FormData item
required
Overview policy switch name.
- ntif_switch: Takes effect when the mode is either normal or rapid, IPv6 is not supported
- signature_ddos_update: Takes effect when mode is either normal or rapid
- smart_policy_mode: Takes effect when smart_filter_app_is_installed=1, IPv6 is not supported
- signature_ntif_update: Takes effect when mode is either normal or rapid, IPv6 is not supported
- ddos_switch: Takes effect when detection_level is network and mode is either normal or rapid, or when detection_level is host
- blackhole_switch: Takes effect when detection_level is host
enum (ntif_switch, signature_ddos_update, smart_policy_mode, signature_ntif_update, ddos_switch, blackhole_switch)
FormData item_status
required
Policy switch status: 0=off, 1=on. When item is set to smart_policy_mode, 0 represents manual, and 1 represents auto. enum (0, 1)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Sets the detection template policy.

POST /spe/customer/{customer_id}/cp/detection/template/{template_id}/policy

Description

Sets the detection template policy.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path template_id
required
Unique identifier of a detection template. integer
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
FormData policy_content
required
JSON string for policy configuration, the threshold value, e.g., 1K 1M, etc.
Object fields:
- detection_mode_threshold_policy: rapid_end_time is effective only when mode=rapid.
Example:
{“start_time”:60,“end_time”:600,“confidence_setting”:“customized”,“confidence_threshold”:80,“rapid_end_time”:600}
Constraints:
start_time must be one of [60, 120, 180]
end_time must be one of [600,900,1200,1800,3600]
confidence_setting must be one of [“off”, “auto”, “customized”]
confidence_threshold must be between 0 and 100.
rapid_end_time must be one of [600,900,1200,1800,3600]
- blackhole_policy:
Example:
{“blackhole_bps”:“2K”,“blackhole_pps”:“20K”,“blackhole_time”:60}
Constraints:
blackhole_time cannot be less than 60
- smart_policy:
Example:
{“low_bps”:“2K”,“low_pps”:“2K”,“high_bps”:“20K”,“high_pps”:“20K”}
- ntif_policy:
Example:
{“signature_type”:“botnet”,“signature_key”:“g_0”,“low_pps”:“2K”,“high_pps”:“20K”,“is_enabled”:1}
Constraints:
is_enabled must be one of [0,1]
- ddos_policy:
Example:
{“signature_type”:“tcp”,“signature_key”:“tcp_rst”,“low_pps”:“2K”,“high_pps”:“20K”,“is_enabled”:1}
Constraints:
is_enabled must be one of [0, 1, 2]. The value 2 is available only when detection_level is host and mode is normal. When the current mode is normal and is_enabled is 2, only is_enabled takes effect in the modified policy; other threshold configurations do not take effect.
string
FormData policy_type
required
Protection policy type, supports the following types:
- detection_mode_threshold_policy: Takes effect when the mode is either normal or rapid
- blackhole_policy: Takes effect when detection_level is host and blackhole_switch=1
- smart_policy: Takes effect when smart_policy_mode=0, IPv6 is not supported
- ntif_policy: Takes effect when ntif_switch=1, IPv6 is not supported
- ddos_policy: Takes effect when ddos_switch=1
enum (detection_mode_threshold_policy, blackhole_policy, smart_policy, ntif_policy, ddos_policy)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets the information of detection template policy.

GET /spe/customer/{customer_id}/cp/detection/template/{template_id}/policy

Description

Gets the information of detection template policy.

Parameters

Type Name Description Schema
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Path template_id
required
Unique identifier of a detection template. integer
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
Detection template policy information. result

result

Name Description Schema
blackhole_policy
optional
The Blackhole detection policy. Takes effect when the blackhole_switch is 1. blackhole_policy
ddos_policy
optional
The DDoS attack detection policy. When ddos_switch is 1, all policies take effect if mode is normal or rapid, regardless of whether detection_level is network or host. When mode is smart, only the total_traffic policy takes effect. < ddos_policy > array
detection_mode_threshold_policy
optional
Detection mode threshold. detection_mode_threshold_policy
mode
optional
For the detection mode, 0 represents normal mode, 1 represents rapid mode, and 2 represents smart mode. integer
ntif_policy
optional
The NTIF attack detection policy. Takes effect when the ntif_switch is 1 and the mode is either normal or rapid. < ntif_policy > array
overview_switch
optional
Overview switch status. overview_switch
smart_filter_app_is_installed
optional
SMART Filter app installation status: 1 for installed, 0 for not installed. integer
smart_policy
optional
S.M.A.RT policy threshold. Takes effect when smart_policy_mode=0. smart_policy

blackhole_policy

Name Description Schema
blackhole_bps
optional
The bps threshold value, e.g., 1K 1M, etc. string
blackhole_pps
optional
The pps threshold value, e.g., 1K 1M, etc. string
blackhole_time
optional
Duration, in seconds. integer

ddos_policy

Name Description Schema
high_bps
optional
The high end of the bps threshold value, e.g., 1K, 1M, etc. This value is supported when signature_key is set to total_traffic. string
high_pps
optional
The high end of the pps threshold value, e.g., 1K 1M, etc. string
is_enabled
optional
Policy detection switch. 0 represents off, 1 represents manual, 2 represents auto. integer
low_bps
optional
The low end of the bps threshold value, e.g., 1K, 1M, etc. This value is supported when signature_key is set to total_traffic. string
low_pps
optional
The low end of the pps threshold value, e.g., 1K 1M, etc. string
signature_key
optional
Protocol submodule signature key. string
signature_name
optional
Protocol submodule signature name. string
signature_type
optional
Detection module protocol, e.g., tcp, udp, icmp, etc. string

detection_mode_threshold_policy

Name Description Schema
confidence_setting
optional
The Normal Plus mode type. Valid values: [“off”, “auto”, “customized”]. string
confidence_threshold
optional
Normal Plus threshold. Takes effect when confidence_setting is customized. integer
end_time
optional
Attack dies off time. The unit is seconds. Takes effect when the mode is normal. integer
rapid_end_time
optional
Attack dies off time. The unit is seconds. Takes effect when the mode is rapid. integer
start_time
optional
Attack observation time. The unit is seconds. Takes effect when the mode is normal. integer

ntif_policy

Name Description Schema
high_pps
optional
The high end of threshold value, e.g., 1K 1M, etc. string
is_enabled
optional
Policy detection switch. 0 represents off, 1 represents on. integer
low_pps
optional
The low end of threshold value, e.g., 1K 1M, etc. string
signature_key
optional
Protocol submodule signature key. string
signature_name
optional
Protocol submodule signature name. string
signature_type
optional
Detection module name, e.g., botnet, anonymizer, etc. string

overview_switch

Name Description Schema
blackhole_switch
optional
Blackhole detection switch. 0 represents off, 1 represents on. Takes effect when detection_level is host. integer
ddos_switch
optional
DDoS detection switch. 0 represents off, 1 represents on. Takes effect when detection_level is network and mode is either normal or rapid, or when detection_level is host. integer
ntif_switch
optional
NTIF detection switch. 0 represents off, 1 represents on. Takes effect when the mode is either normal or rapid. integer
signature_ddos_update
optional
DDoS signature update mode. 0 represents off, 1 represents on. Takes effect when mode is either normal or rapid. integer
signature_ntif_update
optional
NTIF signature update mode. 0 represents off, 1 represents on. Takes effect when mode is either normal or rapid. integer
smart_policy_mode
optional
S.M.A.RT policy mode. 0 represents manual, 1 represents auto. Takes effect when smart_filter_app_is_installed=1. integer

smart_policy

Name Description Schema
high_bps
optional
The high end of bps threshold value, e.g., 1K 1M, etc. string
high_pps
optional
The high end of pps threshold value, e.g., 1K 1M, etc. string
low_bps
optional
The low end of bps threshold value, e.g., 1K 1M, etc. string
low_pps
optional
The low end of pps threshold value, e.g., 1K 1M, etc. string

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets detection template list.

GET /spe/customer/{customer_id}/cp/detection/templates

Description

Gets detection template list.

Parameters

Type Name Description Schema Default
Path customer_id
required
Unique identifier of a customer. Can be obtained by invoking this API. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query detection_level
optional
Object detection level. Valid values: network, host. Default is host. enum (network, host) "host"
Query ip_type
optional
IP address family. Can be one of the following values: ipv4, ipv6. Default is ipv4. enum (ipv4, ipv6) "ipv4"
Query page
optional
Page number. Default is 1. Range is 1-65535. integer 1
Query page_size
optional
Page size. Default is 10. Range is 1-50. integer 10

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
Detection template list. result

result

Name Description Schema
current_page
optional
Current page. Returns 1 when templates is empty. integer
templates
optional
Detection template list. < templates > array
total_page
optional
Total pages. Returns 0 when templates is empty. integer

templates

Name Description Schema
detection_level
optional
Object detection level. Can be one of the following values: network, host. enum (network, host)
ip_type
optional
IP address family. Can be one of the following values: ipv4, ipv6. enum (ipv4, ipv6)
mode
optional
Detection mode. 0 represents normal mode, 1 represents rapid mode, and 2 represents smart mode. integer
template_description
optional
Template description. Same as the description parameter in add/edit APIs. string
template_id
optional
Unique identifier of a detection template. integer
template_name
optional
Template name. Same as the name parameter in add/edit APIs. string

Produces

Security

Type Name
apiKey ApiKeyAuth

Definitions

Result

The returned result.

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Security

ApiKeyAuth

Type : apiKey
Name : access_token
In : QUERY