All Products
Search
Document Center

Security Center:DescribeAntiBruteForceRules

Last Updated:Jun 15, 2026

Queries the brute-force attacks prevention rules that you have created.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:DescribeAntiBruteForceRules

get

*AntiBruteForceRule

acs:yundun-sas:{#regionId}:{#accountId}:antibruteforcerule/{#AntiBruteForceRuleId}

None None

Request parameters

Parameter

Type

Required

Description

Example

SourceIp

string

No

The IP address of the access source.

121.69.XX.XX

Id

integer

No

The ID of the brute-force attacks prevention rule.

Note

You can invoke the DescribeAntiBruteForceRules operation to obtain this parameter.

1141****

CurrentPage

integer

No

The page number of the page to return. Default value: 1, which indicates the first page.

1

PageSize

string

No

The maximum number of entries to return on each page in a paged query. This parameter is used for paging.

10

Name

string

No

The name of the brute-force attacks prevention rule.

testName

Response elements

Element

Type

Description

Example

object

The response parameters.

RequestId

string

The request ID, which is a unique identifier generated by Alibaba Cloud for the request. You can use this ID to troubleshoot issues.

4E5BFDCF-B9DD-430D-9DA4-151BCB581C9D

PageInfo

object

The pagination information of the query result.

CurrentPage

integer

The page number of the current page in a paged query. This parameter is used for paging.

1

PageSize

integer

The maximum number of entries returned per page in a paged query. This parameter is used for paging.

20

TotalCount

integer

The total number of brute-force attacks prevention rules that have been created.

2

Count

integer

The number of entries returned on the current page in a paged query. This parameter is used for paging.

2

Rules

array<object>

The details of brute-force attacks prevention rules.

array<object>

The details of a brute-force attacks prevention rule.

MachineCount

integer

The number of servers to which the brute-force attacks prevention rule is applied.

3

EnableSmartRule

boolean

This parameter is deprecated and does not need to be specified.

false

FailCount

integer

The threshold for the number of failed logon attempts that triggers the brute-force attacks prevention rule.

15

ForbiddenTime

integer

The duration for which the attacker IP address is disabled after the brute-force attacks prevention rule is triggered. Unit: minutes.

360

Span

integer

The time threshold within which the brute-force attacks prevention rule takes effect. Unit: minutes. For example, if Span is set to 10, the brute-force attacks prevention rule is triggered and blocks logon attempts for the specified duration when the number of failed logon attempts within 10 minutes exceeds the settings threshold.

10

DefaultRule

boolean

Indicates whether the current rule is the default rule. Valid values:

  • true: The rule is the default rule.

  • false: The rule is not the default rule.

Note

A brute-force attacks prevention rule that is configured as the default rule takes effect on all servers that do not have a prevention rule configured. See Settings for more information.

true

Name

string

The name of the brute-force attacks prevention rule.

AntiBruteForceRule01

Id

integer

The ID of the brute-force attacks prevention rule.

1629

UuidList

array

The list of UUIDs of the servers to which the brute-force attacks prevention rule is applied.

string

The UUID of a server to which the brute-force attacks prevention rule is applied.

uuid-018c-4ef7-89fd-988b9b0e****

CreateTimestamp

integer

The UNIX timestamp when the brute-force attacks prevention rule was created. Unit: milliseconds.

1669800181000

ProtocolType

object

The protocol types that the brute-force attacks prevention rule supports for interception.

Rdp

string

RDP interception method, with values:

  • on: Enabled

  • off: Disabled

on

Ssh

string

SSH interception method, with values:

  • on: Enabled

  • off: Disabled

on

SqlServer

string

SQL Server interception method, with values:

  • on: Enabled

  • off: Disabled

off

Examples

Success response

JSON format

{
  "RequestId": "4E5BFDCF-B9DD-430D-9DA4-151BCB581C9D",
  "PageInfo": {
    "CurrentPage": 1,
    "PageSize": 20,
    "TotalCount": 2,
    "Count": 2
  },
  "Rules": [
    {
      "MachineCount": 3,
      "EnableSmartRule": false,
      "FailCount": 15,
      "ForbiddenTime": 360,
      "Span": 10,
      "DefaultRule": true,
      "Name": "AntiBruteForceRule01",
      "Id": 1629,
      "UuidList": [
        "uuid-018c-4ef7-89fd-988b9b0e****"
      ],
      "CreateTimestamp": 1669800181000,
      "ProtocolType": {
        "Rdp": "on",
        "Ssh": "on",
        "SqlServer": "off"
      }
    }
  ]
}

Error codes

HTTP status code

Error code

Error message

Description

500 ServerError ServerError
403 NoPermission caller has no permission

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.