Queries the details of custom security score rules.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:GetSecurityScoreRule |
get |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| Lang |
string |
No |
The language type for the request and response messages. Default value: zh. Valid values:
|
zh |
| CalType |
string |
No |
Specifies whether to query the new or legacy security score rules. If the value is home_security_score, the new security score rules are queried. Otherwise, the legacy security score rules are queried by default. |
home_security_score |
| ResourceDirectoryAccountId |
integer |
No |
The Alibaba Cloud account ID of the member accounts in the resource folder. Note
Invoke the DescribeMonitorAccounts operation to obtain this parameter. |
127608589417**** |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| RequestId |
string |
The request ID, which is a unique identifier generated by Alibaba Cloud for the request. You can use this ID to troubleshoot issues. |
F8B6F758-BCD4-597A-8A2C-DA5A552C**** |
| SecurityScoreRuleList |
array<object> |
The list of legacy security score rules. |
|
|
array<object> |
The security score rule data. |
||
| RuleType |
string |
The type of the security score rule. Valid values:
|
SS_ALARM |
| Score |
integer |
The deduction value of the security score rule. Note
The configurable range is 0 to 100. The total deduction thresholds of all security score rules must equal 100. |
20 |
| Title |
string |
The description of the security score rule. |
Unhandled Alerts |
| SecurityScoreItemList |
array<object> |
The list of individual deduction items for the security score rule. |
|
|
object |
The individual deduction item data for the security score rule. |
||
| SubRuleType |
string |
The sub-rule type of the security score deduction item. The relationship between security score categorization types and sub-rule types is as follows:
|
ALARM_SERIOUS |
| Score |
integer |
The deduction value of the individual item. |
3 |
| ScoreThreshold |
integer |
The deduction threshold of the individual item. Note
The configurable range is 0 to the deduction threshold of the security score rule. |
5 |
| Title |
string |
The description of the sub-rule type for the security score deduction item. |
Unhandled Urgent Alert Event Exists |
| EnableStatus |
boolean |
The enabling status of the custom security score rule. Valid values:
|
true |
| SecurityScoreCategoryList |
array<object> |
The list of new security score rules. |
|
|
array<object> |
The security score rule data. |
||
| SecurityRuleList |
array<object> |
The deduction list of security score rule types. |
|
|
array<object> |
The security score rule type data. |
||
| RuleType |
string |
The type of the security score rule. |
SS_AI_RISK |
| Score |
integer |
The deduction threshold of the security score rule type. |
10 |
| Title |
string |
The name of the security score rule type. |
AI Application Risks |
| SecurityScoreItemList |
array<object> |
The deduction list of security score rule sub-items. |
|
|
object |
The security score rule sub-item data. |
||
| SubRuleType |
string |
The type of the security score rule sub-item.
|
SSI_AI_VUL_RISK |
| Score |
integer |
The deduction value of the individual item. |
5 |
| ScoreThreshold |
integer |
The deduction threshold of the individual item. |
10 |
| Title |
string |
The name of the security score rule sub-item. |
Unhandled application vulnerabilities exist. |
| Category |
string |
The category of the security score rule. Valid values:
|
SS_SAS_HANDLE |
| Score |
integer |
The deduction threshold of the security score rule category. |
30 |
| Title |
string |
The name of the security score rule category. |
Security Response |
Examples
Success response
JSON format
{
"RequestId": "F8B6F758-BCD4-597A-8A2C-DA5A552C****",
"SecurityScoreRuleList": [
{
"RuleType": "SS_ALARM",
"Score": 20,
"Title": "Unhandled Alerts",
"SecurityScoreItemList": [
{
"SubRuleType": "ALARM_SERIOUS",
"Score": 3,
"ScoreThreshold": 5,
"Title": "Unhandled Urgent Alert Event Exists"
}
]
}
],
"EnableStatus": true,
"SecurityScoreCategoryList": [
{
"SecurityRuleList": [
{
"RuleType": "SS_AI_RISK",
"Score": 10,
"Title": "AI Application Risks\n",
"SecurityScoreItemList": [
{
"SubRuleType": "SSI_AI_VUL_RISK",
"Score": 5,
"ScoreThreshold": 10,
"Title": "Unhandled application vulnerabilities exist.\n\n"
}
]
}
],
"Category": "SS_SAS_HANDLE",
"Score": 30,
"Title": "Security Response"
}
]
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | RdCheckNoPermission | Resource directory account verification has no permission. | |
| 500 | ServerError | ServerError | |
| 500 | RdCheckInnerError | Resource directory account service internal error. | |
| 403 | NoPermission | caller has no permission | You are not authorized to do this operation. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.