Detection
Detection
Overview
Origin Protection Detection API
Version information
Version : 1.0.0.BETA
License information
Terms of service : https://www.nexusguard.com/
URI scheme
BasePath : /api
Schemes : HTTPS
Paths
Sets the detection mode.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/detection/mode
Description
Sets the detection mode.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Query | detection_level optional |
Object detection level. Valid values: network, host. Default is host. This parameter can be ignored when the current object is of type Host. | enum (host, network) |
| FormData | mode required |
Detection mode: 0=normal, 1=rapid, 2=smart. | enum (0, 1, 2) |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Sets the detection overview switch.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/detection/overview_switch
Description
Sets the detection overview switch.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Query | detection_level optional |
Object detection level. Valid values: network, host. Default is host. This parameter can be ignored when the current object is of type Host. | enum (host, network) |
| FormData | item required |
Overview policy switch name. - ntif_switch: Takes effect when the mode is either normal or rapid, IPv6 is not supported - signature_ddos_update: Takes effect when mode is either normal or rapid - smart_policy_mode: Takes effect when smart_filter_app_is_installed=1, IPv6 is not supported - signature_ntif_update: Takes effect when mode is either normal or rapid, IPv6 is not supported - ddos_switch: Takes effect when detection_level is network and mode is either normal or rapid, or when detection_level is host - blackhole_switch: Takes effect when detection_level is host |
enum (ntif_switch, signature_ddos_update, smart_policy_mode, signature_ntif_update, ddos_switch, blackhole_switch) |
| FormData | item_status required |
Policy switch status: 0=off/manual, 1=on/auto. Only when detection_level is host, mode is normal, ip type is IPv4, and item is signature_ddos_update, the corresponding switch status is: 0 = off, 1 = manual, 2 = auto. | enum (0, 1, 2) |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Sets the detection policy.
POST /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/detection/policy
Description
Sets the detection policy.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Query | detection_level optional |
Object detection level. Valid values: network, host. Default is host. This parameter can be ignored when the current object is of type Host. | enum (host, network) |
| FormData | policy_content required |
JSON string for policy configuration, the threshold value, e.g., 1K 1M, etc. Object fields: - detection_mode_threshold_policy: rapid_end_time is effective only when mode=rapid. Example: {“start_time”:60,“end_time”:600,“confidence_setting”:“customized”,“confidence_threshold”:80,“rapid_end_time”:600} Constraints: start_time must be one of [60, 120, 180] end_time must be one of [600,900,1200,1800,3600] confidence_setting must be one of [“off”, “auto”, “customized”] confidence_threshold must be between 0 and 100. rapid_end_time must be one of [600,900,1200,1800,3600] - blackhole_policy: Example: {“blackhole_bps”:“2K”,“blackhole_pps”:“20K”,“blackhole_time”:60} Constraints: blackhole_time cannot be less than 60 - smart_policy: Example: {“low_bps”:“2K”,“low_pps”:“2K”,“high_bps”:“20K”,“high_pps”:“20K”} - ntif_policy: Example: {“signature_type”:“botnet”,“signature_key”:“g_0”,“low_pps”:“2K”,“high_pps”:“20K”,“is_enabled”:1} Constraints: is_enabled must be one of [0,1] - ddos_policy: Example: {“signature_type”:“tcp”,“signature_key”:“tcp_rst”,“low_pps”:“2K”,“high_pps”:“20K”,“is_enabled”:1} Constraints: is_enabled must be one of [0, 1, 2]. The value 2 is available only when detection_level is host and mode is normal. When the current mode is normal and is_enabled is 2, only is_enabled takes effect in the modified policy; other threshold configurations do not take effect. |
string |
| FormData | policy_type required |
Protection policy type, supports the following types: - detection_mode_threshold_policy: Takes effect when the mode is either normal or rapid - blackhole_policy: Takes effect when detection_level is host and blackhole_switch=1 - smart_policy: Takes effect when smart_policy_mode=0, IPv6 is not supported - ntif_policy: Takes effect when ntif_switch=1, IPv6 is not supported - ddos_policy: Takes effect when ddos_switch=1 |
enum (detection_mode_threshold_policy, blackhole_policy, smart_policy, ntif_policy, ddos_policy) |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Result |
Consumes
multipart/form-data
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Gets the info of detection policies.
GET /spe/customer/{customer_id}/op/site/{site_id}/network/{network_id}/host/{host_id}/detection/policy
Description
Gets the info of detection policies.
Parameters
| Type | Name | Description | Schema |
|---|---|---|---|
| Path | customer_id required |
Unique identifier of a customer. Can be obtained by invoking this API. | string |
| Path | host_id required |
Unique identifier of a host. | string |
| Path | network_id required |
Unique identifier of a network. | string |
| Path | site_id required |
Unique identifier of a site. Can be obtained by invoking this API for Origin Protection sites. | string |
| Query | access_token required |
Access token used to authenticate your access to the API. Can be obtained by invoking this API. | string |
| Query | detection_level optional |
Object detection level. Valid values: network, host. Default is host. This parameter can be ignored when the current object is of type Host. | enum (host, network) |
Responses
| HTTP Code | Description | Schema |
|---|---|---|
| 200 | Response sent when the API is successfully invoked. | Response 200 |
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
| result optional |
Detection template policy information. | result |
| Name | Description | Schema |
|---|---|---|
| blackhole_policy optional |
The Blackhole detection policy. Takes effect when the blackhole_switch is 1. | blackhole_policy |
| ddos_policy optional |
The DDoS attack detection policy. When ddos_switch is 1, all policies take effect if mode is normal or rapid, regardless of whether detection_level is network or host. When mode is smart, only the total_traffic policy takes effect. | < ddos_policy > array |
| detection_mode_threshold_policy optional |
Detection mode threshold. | detection_mode_threshold_policy |
| mode optional |
For the detection mode, 0 represents normal mode, 1 represents rapid mode, and 2 represents smart mode. | integer |
| ntif_policy optional |
The NTIF attack detection policy. Takes effect when the ntif_switch is 1 and the mode is either normal or rapid. | < ntif_policy > array |
| overview_switch optional |
Overview switch status. | overview_switch |
| smart_filter_app_is_installed optional |
SMART Filter app installation status: 1 for installed, 0 for not installed. | integer |
| smart_policy optional |
S.M.A.RT policy threshold. Takes effect when smart_policy_mode=0. | smart_policy |
| Name | Description | Schema |
|---|---|---|
| blackhole_bps optional |
The bps threshold value, e.g., 1K 1M, etc. | string |
| blackhole_pps optional |
The pps threshold value, e.g., 1K 1M, etc. | string |
| blackhole_time optional |
Duration, in seconds. | integer |
| Name | Description | Schema |
|---|---|---|
| high_bps optional |
The high end of the bps threshold value, e.g., 1K, 1M, etc. This value is supported when signature_key is set to total_traffic. | string |
| high_pps optional |
The high end of the pps threshold value, e.g., 1K 1M, etc. | string |
| is_enabled optional |
Policy detection switch. 0 represents off, 1 represents manual, 2 represents auto. | integer |
| low_bps optional |
The low end of the bps threshold value, e.g., 1K, 1M, etc. This value is supported when signature_key is set to total_traffic. | string |
| low_pps optional |
The low end of the pps threshold value, e.g., 1K 1M, etc. | string |
| signature_key optional |
Protocol submodule signature key. | string |
| signature_name optional |
Protocol submodule signature name. | string |
| signature_type optional |
Detection module protocol, e.g., tcp, udp, icmp, etc. | string |
detection_mode_threshold_policy
| Name | Description | Schema |
|---|---|---|
| confidence_setting optional |
The Normal Plus mode type. Valid values: [“off”, “auto”, “customized”]. | string |
| confidence_threshold optional |
Normal Plus threshold. Takes effect when confidence_setting is customized. | integer |
| end_time optional |
Attack dies off time. The unit is seconds. Takes effect when the mode is normal. | integer |
| rapid_end_time optional |
Attack dies off time. The unit is seconds. Takes effect when the mode is rapid. | integer |
| start_time optional |
Attack observation time. The unit is seconds. Takes effect when the mode is normal. | integer |
| Name | Description | Schema |
|---|---|---|
| high_pps optional |
The high end of threshold value, e.g., 1K 1M, etc. | string |
| is_enabled optional |
Policy detection switch. 0 represents off, 1 represents on. | integer |
| low_pps optional |
The low end of threshold value, e.g., 1K 1M, etc. | string |
| signature_key optional |
Protocol submodule signature key. | string |
| signature_name optional |
Protocol submodule signature name. | string |
| signature_type optional |
Detection module name, e.g., botnet, anonymizer, etc. | string |
| Name | Description | Schema |
|---|---|---|
| blackhole_switch optional |
Blackhole detection switch. 0 represents off, 1 represents on. Takes effect when detection_level is host. | integer |
| ddos_switch optional |
DDoS detection switch. 0 represents off, 1 represents on. Takes effect when detection_level is network and mode is either normal or rapid, or when detection_level is host. | integer |
| ntif_switch optional |
NTIF detection switch. 0 represents off, 1 represents on. Takes effect when the mode is either normal or rapid. | integer |
| signature_ddos_update optional |
DDoS signature update mode. 0 represents off, 1 represents manual, 2 represents auto. Takes effect when mode is either normal or rapid. | integer |
| signature_ntif_update optional |
NTIF signature update mode. 0 represents off, 1 represents on. Takes effect when mode is either normal or rapid. | integer |
| smart_policy_mode optional |
S.M.A.RT policy mode. 0 represents manual, 1 represents auto. Takes effect when smart_filter_app_is_installed=1. | integer |
| Name | Description | Schema |
|---|---|---|
| high_bps optional |
The high end of bps threshold value, e.g., 1K 1M, etc. | string |
| high_pps optional |
The high end of pps threshold value, e.g., 1K 1M, etc. | string |
| low_bps optional |
The low end of bps threshold value, e.g., 1K 1M, etc. | string |
| low_pps optional |
The low end of pps threshold value, e.g., 1K 1M, etc. | string |
Produces
application/json
Security
| Type | Name |
|---|---|
| apiKey | ApiKeyAuth |
Definitions
Result
The returned result.
| Name | Description | Schema |
|---|---|---|
| code optional |
Error code | integer |
| msg optional |
Error message | string |
Security
ApiKeyAuth
Type : apiKey
Name : access_token
In : QUERY