All Products
Search
Document Center

Security Center:DescribeSecureSuggestion

Last Updated:Aug 27, 2026

Queries the details of security risk handling suggestions, including risk types, scores, and recommended actions.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:DescribeSecureSuggestion

get

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

SourceIp

string

No

The source IP address of the request.

192.168.XX.XX

Lang

string

No

The language of the request and response. Default value: zh. Valid values:

  • zh: Chinese

  • en: English

zh

CalType

string

No

The version of security score rules to query. Set to home_security_score to query the new version. If not specified, the old version is queried by default.

home_security_score

Source

integer

No

The source of the security score. Default value: Cloud Security Center. Valid values:

  • 0: Cloud Security Center.

  • 1: Yaochi Console.

0

ResourceDirectoryAccountId

integer

No

The ID of the member account in the resource directory.

Note

You can call the DescribeMonitorAccounts operation to query this parameter.

1232428423234****

Response elements

Element

Type

Description

Example

object

RequestId

string

The request ID.

676F80E3-4B3F-43DA-9CBB-5FF79F202AA2

TotalCount

integer

The total number of security risks that require handling.

15

Score

string

The security score.

95

CalTime

integer

The timestamp when the security score was calculated.

1755744253000

Suggestions

array<object>

The list of security risk handling suggestions.

array<object>

The list of security risk handling suggestions.

Points

integer

The point deduction for a single risk item.

40

SuggestType

string

The type of the pending security risk. Valid values:

  • SS_REINFORCE: Key features not configured (e.g., malicious host behavior defense)

  • SS_ALARM: Pending alerts

  • SS_VUL: Vulnerabilities to be fixed

  • SS_HC: Baseline issues

  • SS_AK: AK leakage issues

  • SS_CLOUD_HC: Cloud platform configuration risks

  • OTHER: Other

SS_ALARM

Detail

array<object>

The details of security risk handling suggestions.

object

The details of security risk handling suggestions.

Title

string

The name of the pending security risk item.

Website tamper-proofing capability not configured

Description

string

The description of the security risk handling suggestion.

Malicious tampering of Web pages will affect your normal access to web page content, and may also lead to serious economic losses, brand losses, and even political risks. The webpage tamper-proof service can monitor the website directory in real time and restore the tampered files or directories through backup, so as to ensure that the website information of important systems is not tampered with maliciously and prevent the occurrence of horse hanging, black chain, illegal implantation of terrorist threats, pornography and other content.

SubType

string

The subtype of the pending security risk. Valid values:

  • ALARM_HIGH: Unhandled high-risk alerts

  • ALARM_MEDIUM: Unhandled medium-risk alerts

  • ALARM_LOW: Unhandled low-risk alerts

  • VUL_EMR_UNCHECK: Unchecked urgent vulnerabilities

  • VUL_EMR_UNFIX: Unfixed urgent vulnerabilities

  • VUL_WIN: Unfixed Windows server vulnerabilities

  • VUL_LINUX: Unfixed Linux server vulnerabilities

  • VUL_CMS: Unfixed CMS vulnerabilities

  • ACCESSKEY_LEAK: AccessKey leakage risks

  • HC_WARN: Baseline risks

  • HC_WEAK_EXPLOIT_WARN: Weak passwords exposed to the Internet

  • HC_WEAK_PASSWORD_WARN: Weak password risks

  • HC_HIGH_EXPLOIT_WARN: High intrusion risk

  • HC_OTHER_WARN: Security configuration risks

  • HC_DATABASE_WARN: Database security risks

  • CLOUD_HC_SAS_OPEN: Security protection not installed on the server

  • CLOUD_HC_AEGIS_OFFLINE: Server protection agent is offline

  • CLOUD_HC_ACCOUNT_DOUBLE_CHECK: Two-factor authentication not enabled for the primary account

  • CLOUD_HC_RDS: RDS security policy check failed

  • CLOUD_HC_DDoS: Risks in Anti-DDoS Pro back-to-origin settings

  • CLOUD_HC_HIGH_LEVEL: High-risk cloud product configuration

  • CLOUD_HC_OTHER_LEVEL: Medium or low-risk cloud product configuration

  • OTHER_ATTACH: Attack incidents

  • OTHER_DATABASE_ATTACH: Database security risks

  • REINFORCE_BASELINE: Config assessment

  • REINFORCE_SUSPICIOUS: Antivirus

  • REINFORCE_ANALYSIS: Log analysis

  • REINFORCE_AK_LEAK: AccessKey leak detection

  • REINFORCE_WEB_LOCK: Website tamper-proofing capability not configured

  • REINFORCE_BRUTE_FORCE: Anti-brute force cracking

  • REINFORCE_XPRESS_INSTALL: One-click client installation

  • REINFORCE_RANSOMWARE: Anti-ransomware policy not enabled

  • REINFORCE_UNI_RANSOMWARE: Anti-ransomware for databases

  • REINFORCE_VIRUS_SCHEDULE_SCAN: Periodic virus scan policy not configured

  • REINFORCE_IMAGE_REPO_SCAN: Container image scan scope not configured

  • REINFORCE_IMAGE_SCAN_TASK: Image security scan

  • REINFORCE_K8s_LOG_ANALYSIS: Container K8s threat detection is disabled

  • REINFORCE_CONTAINER_NETWORK: Container visualization

REINFORCE_WEB_LOCK

Examples

Success response

JSON format

{
  "RequestId": "676F80E3-4B3F-43DA-9CBB-5FF79F202AA2",
  "TotalCount": 15,
  "Score": "95",
  "CalTime": 1755744253000,
  "Suggestions": [
    {
      "Points": 40,
      "SuggestType": "SS_ALARM",
      "Detail": [
        {
          "Title": "Website tamper-proofing capability not configured",
          "Description": "Malicious tampering of Web pages will affect your normal access to web page content, and may also lead to serious economic losses, brand losses, and even political risks. The webpage tamper-proof service can monitor the website directory in real time and restore the tampered files or directories through backup, so as to ensure that the website information of important systems is not tampered with maliciously and prevent the occurrence of horse hanging, black chain, illegal implantation of terrorist threats, pornography and other content.",
          "SubType": "REINFORCE_WEB_LOCK"
        }
      ]
    }
  ]
}

Error codes

HTTP status code

Error code

Error message

Description

400 NoPermission no permission
400 RdCheckNoPermission Resource directory account verification has no permission.
500 ServerError ServerError
500 RdCheckInnerError Resource directory account service internal error.
403 NoPermission caller has no permission You are not authorized to do this operation.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.