☰

Detection

Detection

Overview

Network Protection Detection API

Version information

Version : 1.0.0.BETA

License information

Terms of service : https://www.nexusguard.com/

URI scheme

Host : api.nexusguard.com
BasePath : /api
Schemes : HTTPS

Paths

Sets the detection mode.

POST /spe/np/site/{site_id}/detection/mode

Description

Sets the detection mode.

Parameters

Type Name Description Schema Default
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Network Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query detection_level
optional
Detection level scope: network or host. Default is host. When the site operates at host level only, network-level branches may be ignored. enum (host, network) "host"
FormData mode
required
Detection mode: 0=normal, 1=rapid, 2=smart. enum (0, 1, 2)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Sets the detection overview switch.

POST /spe/np/site/{site_id}/detection/overview_switch

Description

Sets the detection overview switch.

Parameters

Type Name Description Schema Default
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Network Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query detection_level
optional
Detection level scope: network or host. Default is host. When the site operates at host level only, network-level branches may be ignored. enum (host, network) "host"
FormData item
required
Overview policy switch name.
- ntif_switch: Takes effect when the mode is either normal or rapid, IPv6 is not supported
- signature_ddos_update: Takes effect when mode is either normal or rapid
- signature_ntif_update: Takes effect when mode is either normal or rapid, IPv6 is not supported
- ddos_switch: Takes effect when detection_level is network and mode is either normal or rapid, or when detection_level is host
- blackhole_switch: Takes effect when detection_level is host
enum (ntif_switch, signature_ddos_update, signature_ntif_update, ddos_switch, blackhole_switch)
FormData item_status
required
Policy switch status: 0=off, 1=on. enum (0, 1)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Sets the detection policy.

POST /spe/np/site/{site_id}/detection/policy

Description

Sets the detection policy.

Parameters

Type Name Description Schema Default
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Network Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query detection_level
optional
Detection level scope: network or host. Default is host. When the site operates at host level only, network-level branches may be ignored. enum (host, network) "host"
FormData policy_content
required
JSON string for policy configuration, the threshold value, e.g., 1K 1M, etc.
Object fields:
- detection_mode_threshold_policy: rapid_end_time is effective only when mode=rapid.
Example:
{“start_time”:60,“end_time”:600,“confidence_setting”:“customized”,“confidence_threshold”:80,“rapid_end_time”:600}
Constraints:
start_time must be one of [60, 120, 180]
end_time must be one of [600,900,1200,1800,3600]
confidence_setting must be one of [“off”, “auto”, “customized”]
confidence_threshold must be between 0 and 100.
rapid_end_time must be one of [600,900,1200,1800,3600]
- blackhole_policy:
Example:
{“blackhole_bps”:“2K”,“blackhole_pps”:“20K”,“blackhole_time”:60}
Constraints:
blackhole_time cannot be less than 60
- ntif_policy:
Example:
{“signature_type”:“botnet”,“signature_key”:“g_0”,“low_pps”:“2K”,“high_pps”:“20K”,“is_enabled”:1}
Constraints:
is_enabled must be one of [0,1]
- ddos_policy:
Example:
{“signature_type”:“tcp”,“signature_key”:“tcp_rst”,“low_pps”:“2K”,“high_pps”:“20K”,“is_enabled”:1}
Constraints:
is_enabled must be one of [0, 1, 2]. The value 2 is available only when detection_level is host and mode is normal. When the current mode is normal and is_enabled is 2, only is_enabled takes effect in the modified policy; other threshold configurations do not take effect.
string
FormData policy_type
required
Protection policy type, supports the following types:
- detection_mode_threshold_policy: Takes effect when the mode is either normal or rapid
- blackhole_policy: Takes effect when detection_level is host and blackhole_switch=1
- ntif_policy: Takes effect when ntif_switch=1, IPv6 is not supported
- ddos_policy: Takes effect when ddos_switch=1
enum (detection_mode_threshold_policy, blackhole_policy, ntif_policy, ddos_policy)

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Result

Consumes

Produces

Security

Type Name
apiKey ApiKeyAuth

Gets the detection policy for a Network Protection site.

GET /spe/np/site/{site_id}/detection/policy

Description

Gets the detection policy for a Network Protection site.

Parameters

Type Name Description Schema Default
Path site_id
required
Unique identifier of a site. Can be obtained by invoking this API for Network Protection sites. string
Query access_token
required
Access token used to authenticate your access to the API. Can be obtained by invoking this API. string
Query detection_level
optional
Detection level scope: network or host. Default is host. When the site operates at host level only, network-level branches may be ignored. enum (host, network) "host"

Responses

HTTP Code Description Schema
200 Response sent when the API is successfully invoked. Response 200

Response 200

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string
result
optional
Site Detection policy information. result

result

Name Description Schema
blackhole_policy
optional
The Blackhole detection policy. Takes effect when the blackhole_switch is 1. blackhole_policy
ddos_policy
optional
The DDoS attack detection policy. When ddos_switch is 1, all policies take effect if mode is normal or rapid, regardless of whether detection_level is network or host. When mode is smart, only the total_traffic policy takes effect. < ddos_policy > array
detection_mode_threshold_policy
optional
Detection mode threshold. detection_mode_threshold_policy
mode
optional
For the detection mode, 0 represents normal mode, 1 represents rapid mode, and 2 represents smart mode. integer
ntif_policy
optional
The NTIF attack detection policy. Takes effect when the ntif_switch is 1 and the mode is either normal or rapid. < ntif_policy > array
overview_switch
optional
Overview switch status. overview_switch

blackhole_policy

Name Description Schema
blackhole_bps
optional
The bps threshold value, e.g., 1K 1M, etc. string
blackhole_pps
optional
The pps threshold value, e.g., 1K 1M, etc. string
blackhole_time
optional
Duration, in seconds. integer

ddos_policy

Name Description Schema
high_bps
optional
The high end of the bps threshold value, e.g., 1K, 1M, etc. This value is supported when signature_key is set to total_traffic. string
high_pps
optional
The high end of the pps threshold value, e.g., 1K 1M, etc. string
is_enabled
optional
Policy detection switch. 0 represents off, 1 represents manual, 2 represents auto. integer
low_bps
optional
The low end of the bps threshold value, e.g., 1K, 1M, etc. This value is supported when signature_key is set to total_traffic. string
low_pps
optional
The low end of the pps threshold value, e.g., 1K 1M, etc. string
signature_key
optional
Protocol submodule signature key. string
signature_name
optional
Protocol submodule signature name. string
signature_type
optional
Detection module protocol, e.g., tcp, udp, icmp, etc. string

detection_mode_threshold_policy

Name Description Schema
confidence_setting
optional
The Normal Plus mode type. Valid values: [“off”, “auto”, “customized”]. string
confidence_threshold
optional
Normal Plus threshold. Takes effect when confidence_setting is customized. integer
end_time
optional
Attack dies off time. The unit is seconds. Takes effect when the mode is normal. integer
rapid_end_time
optional
Attack dies off time. The unit is seconds. Takes effect when the mode is rapid. integer
start_time
optional
Attack observation time. The unit is seconds. Takes effect when the mode is normal. integer

ntif_policy

Name Description Schema
high_pps
optional
The high end of threshold value, e.g., 1K 1M, etc. string
is_enabled
optional
Policy detection switch. 0 represents off, 1 represents on. integer
low_pps
optional
The low end of threshold value, e.g., 1K 1M, etc. string
signature_key
optional
Protocol submodule signature key. string
signature_name
optional
Protocol submodule signature name. string
signature_type
optional
Detection module name, e.g., botnet, anonymizer, etc. string

overview_switch

Name Description Schema
blackhole_switch
optional
Blackhole detection switch. 0 represents off, 1 represents on. Takes effect when detection_level is host. integer
ddos_switch
optional
DDoS detection switch. 0 represents off, 1 represents on. Takes effect when detection_level is network and mode is either normal or rapid, or when detection_level is host. integer
ntif_switch
optional
NTIF detection switch. 0 represents off, 1 represents on. Takes effect when the mode is either normal or rapid. integer
signature_ddos_update
optional
DDoS signature update mode. 0 represents off, 1 represents on. Takes effect when mode is either normal or rapid. integer
signature_ntif_update
optional
NTIF signature update mode. 0 represents off, 1 represents on. Takes effect when mode is either normal or rapid. integer

Produces

Security

Type Name
apiKey ApiKeyAuth

Definitions

Result

The returned result.

Name Description Schema
code
optional
Error code integer
msg
optional
Error message string

Security

ApiKeyAuth

Type : apiKey
Name : access_token
In : QUERY