All Products
Search
Document Center

Security Center:DescribeSecureSuggestion

Last Updated:Jan 20, 2026
This topic is generated by a machine translation engine without any human intervention. ALIBABA CLOUD DOES NOT GUARANTEE THE ACCURACY OF MACHINE TRANSLATED CONTENT. To request a human-translated version of this topic or provide feedback on this translation, please include it in the feedback form.

Query Security Risk Handling Suggestions Details

Debugging

You can run this interface directly in OpenAPI Explorer, saving you the trouble of calculating signatures. After running successfully, OpenAPI Explorer can automatically generate SDK code samples.

Authorization information

The following table shows the authorization information corresponding to the API. The authorization information can be used in the Action policy element to grant a RAM user or RAM role the permissions to call this API operation. Description:

  • Operation: the value that you can use in the Action element to specify the operation on a resource.
  • Access level: the access level of each operation. The levels are read, write, and list.
  • Resource type: the type of the resource on which you can authorize the RAM user or the RAM role to perform the operation. Take note of the following items:
    • For mandatory resource types, indicate with a prefix of * .
    • If the permissions cannot be granted at the resource level, All Resources is used in the Resource type column of the operation.
  • Condition Key: the condition key that is defined by the cloud service.
  • Associated operation: other operations that the RAM user or the RAM role must have permissions to perform to complete the operation. To complete the operation, the RAM user or the RAM role must have the permissions to perform the associated operations.
OperationAccess levelResource typeCondition keyAssociated operation
yundun-sas:DescribeSecureSuggestionget
*All Resources
*
    none
none

Request parameters

ParameterTypeRequiredDescriptionExample
SourceIpstringNo

The IP address of the access source.

192.168.XX.XX
LangstringNo

The language type for request and response messages, default is zh. Values:

  • zh: Chinese
  • en: English
zh
CalTypestringNo

Choose to query the new or old version of the security score rules. When the value is home_security_score, it queries the new version of the security score rules; otherwise, it defaults to querying the old version of the security score rules.

home_security_score
SourceintegerNo

Source of the security score. If left empty, it defaults to Cloud Security Center. Enumerated values:

  • 0: Cloud Security Center.

  • 1: Yaochi Console.

0
ResourceDirectoryAccountIdlongNo

Resource directory member account ID (Alibaba Cloud account).

Note You can obtain this parameter by calling the DescribeMonitorAccounts API.
1232428423234****

Response parameters

ParameterTypeDescriptionExample
object
RequestIdstring

The ID of this call request, which is a unique identifier generated by Alibaba Cloud for this request, and can be used to troubleshoot and locate issues.

676F80E3-4B3F-43DA-9CBB-5FF79F202AA2
TotalCountinteger

The total number of security risks that need to be reinforced.

15
Scorestring

Security score.

95
CalTimelong

Timestamp of the security score calculation.

1755744253000
Suggestionsarray<object>

List of security risk handling suggestions.

Suggestionobject

List of security risk handling suggestions.

Pointsinteger

Deduction value for a single deduction item.

40
SuggestTypestring

Type of the pending security risk. Values:

  • SS_REINFORCE: Key features not configured (e.g., malicious host behavior defense)
  • SS_ALARM: Pending alerts
  • SS_VUL: Vulnerabilities to be fixed
  • SS_HC: Baseline issues
  • SS_AK: AK leakage issues
  • SS_CLOUD_HC: Cloud platform configuration risks
  • OTHER: Other
SS_ALARM
Detailarray<object>

Details of the security risk handling suggestions.

Detailobject

Details of the security risk handling suggestions.

Titlestring

Name of the pending security risk item.

Website tamper-proofing capability not configured
Descriptionstring

Description of the security risk handling suggestion.

Malicious tampering of Web pages will affect your normal access to web page content, and may also lead to serious economic losses, brand losses, and even political risks. The webpage tamper-proof service can monitor the website directory in real time and restore the tampered files or directories through backup, so as to ensure that the website information of important systems is not tampered with maliciously and prevent the occurrence of horse hanging, black chain, illegal implantation of terrorist threats, pornography and other content.
SubTypestring

Types of pending security risks. The values include:

  • ALARM_HIGH: Unhandled high-risk alert events
  • ALARM_MEDIUM: Unhandled medium-risk alert events
  • ALARM_LOW: Unhandled low-risk alert events
  • VUL_EMR_UNCHECK: Unchecked urgent vulnerabilities
  • VUL_EMR_UNFIX: Unfixed urgent vulnerabilities
  • VUL_WIN: Unfixed Windows server vulnerabilities
  • VUL_LINUX: Unfixed Linux server vulnerabilities
  • VUL_CMS: Unfixed CMS vulnerabilities
  • ACCESSKEY_LEAK: AccessKey leakage risks
  • HC_WARN: Baseline risks
  • HC_WEAK_EXPLOIT_WARN: Risks of weak passwords exposed by the public network
  • HC_WEAK_PASSWORD_WARN: Risk of weak password
  • HC_HIGH_EXPLOIT_WARN: High risk of being invaded
  • HC_OTHER_WARN: Security configuration risks
  • HC_DATABASE_WARN: Database has security risks
  • CLOUD_HC_SAS_OPEN: Security protection not installed on the server
  • CLOUD_HC_AEGIS_OFFLINE: Server protection status is offline
  • CLOUD_HC_ACCOUNT_DOUBLE_CHECK: Two-Factor Authentication not enabled for primary account
  • CLOUD_HC_RDS: RDS database security policy check failed, posing security risks
  • CLOUD_HC_DDOS: Risks in Anti-DDoS Pro back-to-origin settings
  • CLOUD_HC_HIGH_LEVEL: Cloud product configuration with high risk
  • CLOUD_HC_OTHER_LEVEL: Cloud product configuration with medium and low risks
  • OTHER_ATTACH: Attack incidents
  • OTHER_DATABASE_ATTACH: Database has security risks
  • REINFORCE_BASELINE: Config assessment
  • REINFORCE_SUSPICIOUS: Antivirus
  • REINFORCE_ANALYSIS: Log analysis
  • REINFORCE_AK_LEAK: AccessKey leaked intelligence detection
  • REINFORCE_WEB_LOCK: Website tamper-proofing capability not configured
  • REINFORCE_BRUTE_FORCE: Anti-brute force cracking
  • REINFORCE_XPRESS_INSTALL: One-click client installation
  • REINFORCE_RANSOMWARE: Enable anti-ransomware strategy
  • REINFORCE_UNI_RANSOMWARE: Anti-ransomware for databases
  • REINFORCE_VIRUS_SCHEDULE_SCAN: Periodic virus scan policies not configured
  • REINFORCE_IMAGE_REPO_SCAN: No container image scan range configured
  • REINFORCE_IMAGE_SCAN_TASK: Image security scan
  • REINFORCE_K8S_LOG_ANALYSIS: Container K8s threat detection is disabled
  • REINFORCE_CONTAINER_NETWORK: Container visualization
REINFORCE_WEB_LOCK

Examples

Sample success responses

JSONformat

{
  "RequestId": "676F80E3-4B3F-43DA-9CBB-5FF79F202AA2",
  "TotalCount": 15,
  "Score": 95,
  "CalTime": 1755744253000,
  "Suggestions": [
    {
      "Points": 40,
      "SuggestType": "SS_ALARM",
      "Detail": [
        {
          "Title": "Website tamper-proofing capability not configured",
          "Description": "Malicious tampering of Web pages will affect your normal access to web page content, and may also lead to serious economic losses, brand losses, and even political risks. The webpage tamper-proof service can monitor the website directory in real time and restore the tampered files or directories through backup, so as to ensure that the website information of important systems is not tampered with maliciously and prevent the occurrence of horse hanging, black chain, illegal implantation of terrorist threats, pornography and other content.",
          "SubType": "REINFORCE_WEB_LOCK"
        }
      ]
    }
  ]
}

Error codes

HTTP status codeError codeError messageDescription
400NoPermissionno permission-
400RdCheckNoPermissionResource directory account verification has no permission.-
403NoPermissioncaller has no permissionYou are not authorized to do this operation.
500ServerErrorServerError-
500RdCheckInnerErrorResource directory account service internal error.-

For a list of error codes, visit the Service error codes.

Change history

Change timeSummary of changesOperation
2025-12-02The Error code has changed. The request parameters of the API has changedView Change Details
2024-05-15The Error code has changedView Change Details