Queries the details of malicious files detected in container images.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:DescribeAffectedMaliciousFileImages |
get |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| MaliciousMd5 |
string |
No |
The MD5 hash of the malicious file. Note
Call the DescribeGroupedMaliciousFiles operation to obtain the MD5 hash of the malicious file. |
d836968041f7683b5459**** |
| CurrentPage |
integer |
Yes |
The page number of the current page when using paging. Minimum value: 1. Default value: 1. |
1 |
| PageSize |
string |
Yes |
The maximum number of entries per page when using paging. Default value: 20. |
20 |
| Lang |
string |
No |
The language type of the request and response. Valid values:
|
zh |
| RepoRegionId |
string |
No |
The region ID of the image repository. Valid values:
|
cn-hangzhou |
| RepoInstanceId |
string |
No |
The ID of the container image instance. Note
Call the ListRepository operation of Container Registry. You can obtain the container image instance ID from the InstanceId response parameter. |
cri-datvailb**** |
| RepoId |
string |
No |
The ID of the image repository. Note
Call the ListRepository operation of Container Registry. You can obtain the image repository ID from the RepoId response parameter. |
crr-vridcl4**** |
| RepoName |
string |
No |
The name of the image repository. Note
Fuzzy match is supported. |
centos |
| RepoNamespace |
string |
No |
The namespace of the image repository. Note
Fuzzy match is supported. |
hanghai-namespace |
| ImageTag |
string |
No |
The tag of the image. |
0.2 |
| ImageDigest |
string |
No |
The digest of the image. |
6a5e103187b31a94592a47a5858617f7a179ead61df7606**** |
| ImageLayer |
string |
No |
The layer of the image. |
27213ad375b53628dd152a5ca**** |
| ClusterId |
string |
No |
The ID of the container cluster to query. Note
Call the DescribeGroupedContainerInstances operation to obtain this parameter. |
c60b77fe62093480db6164a3c2fa5**** |
| ScanRange |
array |
No |
The collection of scan ranges. |
|
|
string |
No |
The scan range. Valid values:
|
image |
|
| ClusterName |
string |
No |
The name of the cluster. |
minikube |
| ContainerId |
string |
No |
The ID of the container. |
cc20a1024011c44b6a8710d6f8b**** |
| Pod |
string |
No |
The pod. |
22222-7xsqq |
| Namespace |
string |
No |
The namespace. |
test-002 |
| Image |
string |
No |
The name of the container image. |
registry.cn-wulanchabu.aliyuncs.com/sas_test/huxin-test-001:nuxeo6-**** |
| Levels |
string |
No |
The severity levels. Separate multiple values with commas (,). Valid values:
|
serious,suspicious |
| Status |
string |
No |
The processing status of the malicious image sample. Valid values:
|
0 |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| RequestId |
string |
The ID of the request. Alibaba Cloud generates a unique identifier for each request. You can use this ID to troubleshoot issues. |
ACF97412-FD09-4D1F-994F-34DF12BREF20 |
| PageInfo |
object |
The pagination information. |
|
| CurrentPage |
integer |
The page number of the current page when using paging. Minimum value: 1. Default value: 1. |
1 |
| PageSize |
integer |
The maximum number of entries per page when using paging. Default value: 20. |
20 |
| TotalCount |
integer |
The total number of images in which malicious samples are detected. |
2 |
| Count |
integer |
The number of images with malicious samples returned on the current page. |
2 |
| AffectedMaliciousFileImagesResponse |
array<object> |
The list of images in which malicious samples are detected. |
|
|
object |
The information about an image in which malicious samples are detected. |
||
| Status |
integer |
The processing status of the malicious image sample. Valid values:
|
1 |
| Digest |
string |
The digest of the image. |
6a5e1031a5858617f7d8a179ead6**** |
| LatestVerifyTimestamp |
integer |
The timestamp of the latest verification. |
1596522711000 |
| RepoInstanceId |
string |
The instance ID of the container image. |
cri-datvail3m**** |
| Namespace |
string |
The namespace of the image repository. |
hanghai-namespace |
| Tag |
string |
The tag of the image. |
0.2 |
| RepoRegionId |
string |
The region ID of the image repository. |
cn-shanghai |
| ImageUuid |
string |
The UUID of the image. |
e05c0de798217637868ef4**** |
| FirstScanTimestamp |
integer |
The timestamp of the first scan. |
1594907349000 |
| MaliciousMd5 |
string |
The MD5 hash of the malicious file. |
d836968041f768300d9605a**** |
| FilePath |
string |
The file path of the image. |
/d836968041f7683b5605a**** |
| RepoId |
string |
The ID of the image repository. |
crr-vridcl4**** |
| Layer |
string |
The layer of the image. |
27213ad3447f0209dd152a5cadea**** |
| LatestScanTimestamp |
integer |
The timestamp of the latest scan. |
1596522785000 |
| RepoName |
string |
The name of the image repository. |
centos |
| Level |
string |
The severity level of the malicious image sample. Valid values:
|
serious |
| DownloadUrl |
string |
The download URL of the malicious sample. |
https://aegis-metadata-file.oss-cn-shanghai.aliyuncs.com/ |
| HighLight |
string |
The highlighted text. |
{"ruleVersion":"highlight_20210908","ruleId":600106,"events":[[2,54]]} |
| ContainerId |
string |
The ID of the container. |
04d20e98c8e2c93b7b864372084320a15a58c8671e53c972ce3a71d9c163**** |
| Image |
string |
The name of the image. |
registry.cn-wulanchabu.aliyuncs.com/sas_test/huxin-test-001:nuxeo6-conta**** |
| Pod |
string |
The pod. |
22222-7xsqq |
| ClusterId |
string |
The ID of the cluster. |
c08d5fc1a329a4b88950a253d082f1**** |
| ClusterName |
string |
The name of the cluster. |
docker-law |
| InstanceName |
string |
The name of the server instance. |
sql-test-001 |
| InternetIp |
string |
The public IP address of the server. |
47.101.XX.XX |
| IntranetIp |
string |
The private IP address of the server. |
172.22.XX.XX |
| TargetId |
string |
The ID of the scan target. |
m-bp17m0pc0xprzbwo**** |
| TargetName |
string |
The name of the scan target. |
source-test-obj-9LaLJ |
| TargetType |
string |
The object type of the scan target. Valid values:
|
ECS_IMAGE |
| Uuid |
string |
The UUID of the server. |
48a473c4-1650-4931-a822-7e6c2c28**** |
| Id |
integer |
The ID of the alert event. |
1000040 |
Examples
Success response
JSON format
{
"RequestId": "ACF97412-FD09-4D1F-994F-34DF12BREF20",
"PageInfo": {
"CurrentPage": 1,
"PageSize": 20,
"TotalCount": 2,
"Count": 2
},
"AffectedMaliciousFileImagesResponse": [
{
"Status": 1,
"Digest": "6a5e1031a5858617f7d8a179ead6****",
"LatestVerifyTimestamp": 1596522711000,
"RepoInstanceId": "cri-datvail3m****",
"Namespace": "hanghai-namespace",
"Tag": "0.2",
"RepoRegionId": "cn-shanghai",
"ImageUuid": "e05c0de798217637868ef4****",
"FirstScanTimestamp": 1594907349000,
"MaliciousMd5": "d836968041f768300d9605a****",
"FilePath": "/d836968041f7683b5605a****",
"RepoId": "crr-vridcl4****",
"Layer": "27213ad3447f0209dd152a5cadea****",
"LatestScanTimestamp": 1596522785000,
"RepoName": "centos",
"Level": "serious",
"DownloadUrl": "https://aegis-metadata-file.oss-cn-shanghai.aliyuncs.com/",
"HighLight": "{\"ruleVersion\":\"highlight_20210908\",\"ruleId\":600106,\"events\":[[2,54]]}",
"ContainerId": "04d20e98c8e2c93b7b864372084320a15a58c8671e53c972ce3a71d9c163****",
"Image": "registry.cn-wulanchabu.aliyuncs.com/sas_test/huxin-test-001:nuxeo6-conta****",
"Pod": "22222-7xsqq",
"ClusterId": "c08d5fc1a329a4b88950a253d082f1****",
"ClusterName": "docker-law",
"InstanceName": "sql-test-001",
"InternetIp": "47.101.XX.XX",
"IntranetIp": "172.22.XX.XX",
"TargetId": "m-bp17m0pc0xprzbwo****",
"TargetName": "source-test-obj-9LaLJ",
"TargetType": "ECS_IMAGE",
"Uuid": "48a473c4-1650-4931-a822-7e6c2c28****",
"Id": 1000040
}
]
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 500 | ServerError | ServerError | |
| 403 | NoPermission | caller has no permission |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.