Detection Template
Detection Template
Overview
Clean Pipe Detection Template API
Version information
Version : 1.0.0.BETA
License information
Terms of service : https://www.nexusguard.com/
URI scheme
Host : api.nexusguard.com
BasePath : /api
Schemes : HTTPS
Paths
Creates a detection template.
POST /spe/customer/{customer_id}/cp/detection/template
Description
This API creates a detection template with the information provided by the user. See notes on individual parameters below.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Query | description optional |
Description of the template you want to create. The description must be 0-100 characters. | string |
| Query | detection_base_template_id optional |
Unique identifier of a detection base template. When this value is provided, the policy of the base detection template will be inherited. Can be obtained by invoking this API | integer |
| Query | detection_level optional |
Object detection level. Valid values: network, host. Default is host. This value takes effect when no base detection template is inherited. | enum (host, network) |
| Query | ip_type optional |
IP address family for the template, ipv4 or ipv6. Default is ipv4. This value takes effect when no base detection template is inherited. | enum (ipv4, ipv6) |
| Query | name required |
Name of the template you want to create. The template name must be 2-40 characters long and may include letters, numbers, spaces, Chinese characters, hyphens, underscores, and dots. | string |
| FormData | mode optional |
Detection mode: 0=normal, 1=rapid, 2=smart. The default value is 0. This value takes effect when no base detection template is inherited. | enum (0, 1, 2) |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Update detection template information.
PUT /spe/customer/{customer_id}/cp/detection/template/{template_id}
Description
Update detection template information.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | template_id required |
Unique identifier of a detection template. | integer |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Query | description optional |
New description for the template. The description must be 0-100 characters. | string |
| Query | name required |
New name for the template. The template name must be 2-40 characters long and may include letters, numbers, spaces, Chinese characters, hyphens, underscores, and dots. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Delete detection template.
DELETE /spe/customer/{customer_id}/cp/detection/template/{template_id}
Description
Delete detection template.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | template_id required |
Unique identifier of a detection template. | integer |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Sets the detection template overview switch.
POST /spe/customer/{customer_id}/cp/detection/template/{template_id}/overview_switch
Description
Sets the detection template overview switch.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | template_id required |
Unique identifier of a detection template. | integer |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| FormData | item required |
Overview policy switch name. - ntif_switch: Takes effect when the mode is either normal or rapid, IPv6 is not supported - signature_ddos_update: Takes effect when mode is either normal or rapid - smart_policy_mode: Takes effect when smart_filter_app_is_installed=1, IPv6 is not supported - signature_ntif_update: Takes effect when mode is either normal or rapid, IPv6 is not supported - ddos_switch: Takes effect when detection_level is network and mode is either normal or rapid, or when detection_level is host - blackhole_switch: Takes effect when detection_level is host |
enum (ntif_switch, signature_ddos_update, smart_policy_mode, signature_ntif_update, ddos_switch, blackhole_switch) |
| FormData | item_status required |
Policy switch status: 0=off, 1=on. When item is set to smart_policy_mode, 0 represents manual, and 1 represents auto. | enum (0, 1) |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Sets the detection template policy.
POST /spe/customer/{customer_id}/cp/detection/template/{template_id}/policy
Description
Sets the detection template policy.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | template_id required |
Unique identifier of a detection template. | integer |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| FormData | policy_content required |
JSON string for policy configuration, the threshold value, e.g., 1K 1M, etc. Object fields: - detection_mode_threshold_policy: rapid_end_time is effective only when mode=rapid. Example: {“start_time”:60,“end_time”:600,“confidence_setting”:“customized”,“confidence_threshold”:80,“rapid_end_time”:600} Constraints: start_time must be one of [60, 120, 180] end_time must be one of [600,900,1200,1800,3600] confidence_setting must be one of [“off”, “auto”, “customized”] confidence_threshold must be between 0 and 100. rapid_end_time must be one of [600,900,1200,1800,3600] - blackhole_policy: Example: {“blackhole_bps”:“2K”,“blackhole_pps”:“20K”,“blackhole_time”:60} Constraints: blackhole_time cannot be less than 60 - smart_policy: Example: {“low_bps”:“2K”,“low_pps”:“2K”,“high_bps”:“20K”,“high_pps”:“20K”} - ntif_policy: Example: {“signature_type”:“botnet”,“signature_key”:“g_0”,“low_pps”:“2K”,“high_pps”:“20K”,“is_enabled”:1} Constraints: is_enabled must be one of [0,1] - ddos_policy: Example: {“signature_type”:“tcp”,“signature_key”:“tcp_rst”,“low_pps”:“2K”,“high_pps”:“20K”,“is_enabled”:1} Constraints: is_enabled must be one of [0, 1, 2]. The value 2 is available only when detection_level is host and mode is normal. When the current mode is normal and is_enabled is 2, only is_enabled takes effect in the modified policy; other threshold configurations do not take effect. |
string |
| FormData | policy_type required |
Protection policy type, supports the following types: - detection_mode_threshold_policy: Takes effect when the mode is either normal or rapid - blackhole_policy: Takes effect when detection_level is host and blackhole_switch=1 - smart_policy: Takes effect when smart_policy_mode=0, IPv6 is not supported - ntif_policy: Takes effect when ntif_switch=1, IPv6 is not supported - ddos_policy: Takes effect when ddos_switch=1 |
enum (detection_mode_threshold_policy, blackhole_policy, smart_policy, ntif_policy, ddos_policy) |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Gets the information of detection template policy.
GET /spe/customer/{customer_id}/cp/detection/template/{template_id}/policy
Description
Gets the information of detection template policy.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | template_id required |
Unique identifier of a detection template. | integer |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
Detection template policy information. | result |
| Name | Description | Schema |
|---|---|---|
| blackhole_policy optional |
The Blackhole detection policy. Takes effect when the blackhole_switch is 1. | blackhole_policy |
| ddos_policy optional |
The DDoS attack detection policy. When ddos_switch is 1, all policies take effect if mode is normal or rapid, regardless of whether detection_level is network or host. When mode is smart, only the total_traffic policy takes effect. | < ddos_policy > array |
| detection_mode_threshold_policy optional |
Detection mode threshold. | detection_mode_threshold_policy |
| mode optional |
For the detection mode, 0 represents normal mode, 1 represents rapid mode, and 2 represents smart mode. | integer |
| ntif_policy optional |
The NTIF attack detection policy. Takes effect when the ntif_switch is 1 and the mode is either normal or rapid. | < ntif_policy > array |
| overview_switch optional |
Overview switch status. | overview_switch |
| smart_filter_app_is_installed optional |
SMART Filter app installation status: 1 for installed, 0 for not installed. | integer |
| smart_policy optional |
S.M.A.RT policy threshold. Takes effect when smart_policy_mode=0. | smart_policy |
| Name | Description | Schema |
|---|---|---|
| blackhole_bps optional |
The bps threshold value, e.g., 1K 1M, etc. | string |
| blackhole_pps optional |
The pps threshold value, e.g., 1K 1M, etc. | string |
| blackhole_time optional |
Duration, in seconds. | integer |
| Name | Description | Schema |
|---|---|---|
| high_bps optional |
The high end of the bps threshold value, e.g., 1K, 1M, etc. This value is supported when signature_key is set to total_traffic. | string |
| high_pps optional |
The high end of the pps threshold value, e.g., 1K 1M, etc. | string |
| is_enabled optional |
Policy detection switch. 0 represents off, 1 represents manual, 2 represents auto. | integer |
| low_bps optional |
The low end of the bps threshold value, e.g., 1K, 1M, etc. This value is supported when signature_key is set to total_traffic. | string |
| low_pps optional |
The low end of the pps threshold value, e.g., 1K 1M, etc. | string |
| signature_key optional |
Protocol submodule signature key. | string |
| signature_name optional |
Protocol submodule signature name. | string |
| signature_type optional |
Detection module protocol, e.g., tcp, udp, icmp, etc. | string |
detection_mode_threshold_policy
| Name | Description | Schema |
|---|---|---|
| confidence_setting optional |
The Normal Plus mode type. Valid values: [“off”, “auto”, “customized”]. | string |
| confidence_threshold optional |
Normal Plus threshold. Takes effect when confidence_setting is customized. | integer |
| end_time optional |
Attack dies off time. The unit is seconds. Takes effect when the mode is normal. | integer |
| rapid_end_time optional |
Attack dies off time. The unit is seconds. Takes effect when the mode is rapid. | integer |
| start_time optional |
Attack observation time. The unit is seconds. Takes effect when the mode is normal. | integer |
| Name | Description | Schema |
|---|---|---|
| high_pps optional |
The high end of threshold value, e.g., 1K 1M, etc. | string |
| is_enabled optional |
Policy detection switch. 0 represents off, 1 represents on. | integer |
| low_pps optional |
The low end of threshold value, e.g., 1K 1M, etc. | string |
| signature_key optional |
Protocol submodule signature key. | string |
| signature_name optional |
Protocol submodule signature name. | string |
| signature_type optional |
Detection module name, e.g., botnet, anonymizer, etc. | string |
| Name | Description | Schema |
|---|---|---|
| blackhole_switch optional |
Blackhole detection switch. 0 represents off, 1 represents on. Takes effect when detection_level is host. | integer |
| ddos_switch optional |
DDoS detection switch. 0 represents off, 1 represents on. Takes effect when detection_level is network and mode is either normal or rapid, or when detection_level is host. | integer |
| ntif_switch optional |
NTIF detection switch. 0 represents off, 1 represents on. Takes effect when the mode is either normal or rapid. | integer |
| signature_ddos_update optional |
DDoS signature update mode. 0 represents off, 1 represents on. Takes effect when mode is either normal or rapid. | integer |
| signature_ntif_update optional |
NTIF signature update mode. 0 represents off, 1 represents on. Takes effect when mode is either normal or rapid. | integer |
| smart_policy_mode optional |
S.M.A.RT policy mode. 0 represents manual, 1 represents auto. Takes effect when smart_filter_app_is_installed=1. | integer |
| Name | Description | Schema |
|---|---|---|
| high_bps optional |
The high end of bps threshold value, e.g., 1K 1M, etc. | string |
| high_pps optional |
The high end of pps threshold value, e.g., 1K 1M, etc. | string |
| low_bps optional |
The low end of bps threshold value, e.g., 1K 1M, etc. | string |
| low_pps optional |
The low end of pps threshold value, e.g., 1K 1M, etc. | string |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Gets detection template list.
GET /spe/customer/{customer_id}/cp/detection/templates
Description
Gets detection template list.
Parameters
| Type | Name | Description | Schema | Default |
|---|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string | |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string | |
| Query | detection_level optional |
Object detection level. Valid values: network, host. Default is host. | enum (network, host) | "host" |
| Query | ip_type optional |
IP address family. Can be one of the following values: ipv4, ipv6. Default is ipv4. | enum (ipv4, ipv6) | "ipv4" |
| Query | page optional |
Page number. Default is 1. Range is 1-65535. | integer | 1 |
| Query | page_size optional |
Page size. Default is 10. Range is 1-50. | integer | 10 |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
Detection template list. | result |
| Name | Description | Schema |
|---|---|---|
| current_page optional |
Current page. Returns 1 when templates is empty. | integer |
| templates optional |
Detection template list. | < templates > array |
| total_page optional |
Total pages. Returns 0 when templates is empty. | integer |
| Name | Description | Schema |
|---|---|---|
| detection_level optional |
Object detection level. Can be one of the following values: network, host. | enum (network, host) |
| ip_type optional |
IP address family. Can be one of the following values: ipv4, ipv6. | enum (ipv4, ipv6) |
| mode optional |
Detection mode. 0 represents normal mode, 1 represents rapid mode, and 2 represents smart mode. | integer |
| template_description optional |
Template description. Same as the description parameter in add/edit APIs. | string |
| template_id optional |
Unique identifier of a detection template. | integer |
| template_name optional |
Template name. Same as the name parameter in add/edit APIs. | string |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Definitions
Result
The returned result.
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Security
ApiKeyAuth
Type : apiKey
Name : access_token
In : QUERY