Queries security alert data from a website security report.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:DescribeDomainSecureAlarmList |
list |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| SourceIp |
string |
No |
The IP address of the access source. |
139.227.*.* |
| Lang |
string |
No |
The language type of the request and response messages. Valid values:
|
zh |
| From |
string |
No |
The identifier of the request source. Set this parameter to sas. |
sas |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response parameters. |
||
| TotalCount |
integer |
The total number of entries returned. |
42 |
| RequestId |
string |
The ID of the request. The ID is a unique identifier that Alibaba Cloud generates for the request and can be used to troubleshoot issues. |
D03DD0FD-6041-5107-AC00-383E28F1**** |
| AlarmList |
array<object> |
The list of security alerts for website assets. |
|
|
object |
The list of security alerts for website assets. |
||
| Dealed |
boolean |
Indicates whether the alert event has been handled. Valid values:
|
y |
| Stages |
string |
The stage of the attack or intrusion. |
[\"authority_maintenance\"] |
| InternetIp |
string |
The public IP address of the server. |
95.214.*.* |
| SuspiciousEventCount |
integer |
The total number of security alerts for your website assets. |
1 |
| GmtModified |
integer |
The time when the alert event was last modified. |
1656901794000 |
| AlarmEventNameOriginal |
string |
The original parent name of the alert event. |
login_common_location |
| AlarmUniqueInfo |
string |
The unique identifier of the alert event. |
8df914418f4211fbf756efe7a6f4**** |
| CanCancelFault |
boolean |
Indicates whether the alert event can be unmarked as a false positive. Valid values:
|
false |
| SecurityEventIds |
string |
The IDs of the alert events associated with the alert event. |
270789 |
| CanBeDealOnLine |
boolean |
Indicates whether the alert event can be handled online, such as blocking, adding to a whitelist, or ignoring. Valid values:
|
true |
| Description |
string |
The description of the alert event. |
The detection model finds that there is a Trojan horse program on your server. The Trojan horse program is a program specially used to invade the user's host. Generally, it will download and release another malicious program after being implanted into the system through disguise. |
| ContainHwMode |
boolean |
Indicates whether the alert event contains the critical event protection mode. |
true |
| InstanceName |
string |
The name of the asset instance affected by the alert event. |
TestInstance |
| SaleVersion |
string |
The edition of Security Center that supports the detection of the alert event. Valid values:
|
1 |
| OperateErrorCode |
string |
The result code of the alert event handling. |
kill_and_quara.Success |
| Solution |
string |
The solution for the alert event. |
A malicious program implanted by hacker after intrusion will occupy your bandwidth and attack other servers, and may affect you own service. The malicious process may also have self-deleting behavior or disguise as a system service to evade detection. |
| DataSource |
string |
The data source of the alert event. |
aegis_**** |
| HasTraceInfo |
boolean |
Indicates whether the alert event has tracing information. Valid values:
|
true |
| OperateTime |
integer |
The timestamp when the alert event was handled. Unit: milliseconds. |
1631699497000 |
| InstanceId |
string |
The ID of the asset instance affected by the alert event. |
i-e**** |
| IntranetIp |
string |
The private IP address of the asset instance affected by the alert event. |
192.168.XX.XX |
| EndTime |
integer |
The timestamp of the most recent occurrence of the alert event. Unit: milliseconds. |
1543740301000 |
| StartTime |
integer |
The start timestamp of the alert event. Unit: milliseconds. |
1543740301000 |
| Uuid |
string |
The unique identifier of the instance associated with the alert event. |
47900178-885d-4fa4-9d77-**** |
| AlarmEventType |
string |
The type of the alert event. |
Malicious Software |
| AutoBreaking |
boolean |
Indicates whether automatic defense is enabled. |
true |
| AlarmEventName |
string |
The name of the alert event. |
Trojan |
| Level |
string |
The risk level of the alert event. Valid values:
|
serious |
Examples
Success response
JSON format
{
"TotalCount": 42,
"RequestId": "D03DD0FD-6041-5107-AC00-383E28F1****",
"AlarmList": [
{
"Dealed": true,
"Stages": "[\\\"authority_maintenance\\\"]\n",
"InternetIp": "95.214.*.*",
"SuspiciousEventCount": 1,
"GmtModified": 1656901794000,
"AlarmEventNameOriginal": "login_common_location",
"AlarmUniqueInfo": "8df914418f4211fbf756efe7a6f4****",
"CanCancelFault": false,
"SecurityEventIds": "270789",
"CanBeDealOnLine": true,
"Description": "The detection model finds that there is a Trojan horse program on your server. The Trojan horse program is a program specially used to invade the user's host. Generally, it will download and release another malicious program after being implanted into the system through disguise.",
"ContainHwMode": true,
"InstanceName": "TestInstance",
"SaleVersion": "1",
"OperateErrorCode": "kill_and_quara.Success",
"Solution": "A malicious program implanted by hacker after intrusion will occupy your bandwidth and attack other servers, and may affect you own service. The malicious process may also have self-deleting behavior or disguise as a system service to evade detection. ",
"DataSource": "aegis_****",
"HasTraceInfo": true,
"OperateTime": 1631699497000,
"InstanceId": "i-e****",
"IntranetIp": "192.168.XX.XX",
"EndTime": 1543740301000,
"StartTime": 1543740301000,
"Uuid": "47900178-885d-4fa4-9d77-****",
"AlarmEventType": "Malicious Software",
"AutoBreaking": true,
"AlarmEventName": "Trojan",
"Level": "serious"
}
]
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 500 | ServerError | ServerError | |
| 403 | NoPermission | caller has no permission |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.