API security in Alibaba Cloud Web Application Firewall (WAF) reports two kinds of findings for your APIs: risks and security events. Review the statistics of both, search the detection lists to locate a specific record, change handling statuses, open individual records for analysis, and export the data for further analysis.
How risks differ from security events
A risk is a security risk or a security exposure on an API that is caused by development defects, or by management or configuration defects. A risk does not necessarily indicate that an attack has occurred. For more information about risk types, see API risk types supported by API security.
A security event is an abnormal call or an attack behavior against an API, such as brute-force attacks on a logon API or abuse of an SMS sending API to send spam messages. A security event is an alert that is generated because an attack has occurred. For more information about the security events that API security can detect, see Abnormal event types supported by API security.
API security reports security events in two dimensions: IP Security Events provides statistics by IP dimension, and Account Security Events provides statistics by account dimension.
Prerequisites
Account Extraction is configured for the protected object. This configuration is required before you can view Account Security Events. For instructions, see Configure account extraction.
View risk detection data
The Risk Detection tab of the API Security page shows the statistics and the conditional search of API risk detection and analysis. To open the tab, click Risk Detection, or click More in the upper-right corner of the Risky Site Statistics table.
The tab contains three feature modules: risk statistics, the left-side risk type pane, and API risk details.
Risk statistics
The risk statistics module contains the following two parts:
Risk Impact Statistics: the number of domains at risk, the number of API entries at risk, and the number of high risks, medium risks, and low risks, each with its daily new count.
Risk Status Statistics: the number of risks in the To Be Confirmed, To Be Fixed, Confirmed, Fixed, and Ignored statuses.
Click any number in the module to view the matching risk records in API Risk Details.
Left-side risk type pane
The left-side risk type pane shows the risk types of the API assets that you own and the corresponding counts. Click a risk type to view the API entries that have this risk type in API Risk Details.
API risk details
The API Risk Details module lists the detected API risks. From this list, you can search for a specific risk, change the status of a risk, open the details page of a risk, and export the risk data.
Manage API risks
After you locate the target API risk, you can change its status, view the API assets that the risk involves, and view the risk details.
Change the status of an API risk
The initial status of an API risk is To Be Confirmed. Change the status in either of the following locations:
In the API Risk Details list, click the
icon in the Status column, select the risk status that you want to change to, and then click OK.On the risk details page, set the status to Confirmed, To Be Fixed, Pending System Verification, Fixed (Manual Verification), or Ignore, and enter remark information.
To stop tracking an alert that you no longer need, change the risk status to Ignored or Fixed. The risk is then no longer counted in the To Be Confirmed or To Be Fixed statistics.
When you set the risk status to Pending System Verification, the system automatically identifies whether the risk is fixed. If any of the following conditions is met, the status is set to Fixed (System Verification). Otherwise, the status is set to Verification Failed.
For an Unauthenticated Access to Sensitive API risk, the API is detected as authenticated or as having no sensitive data transmission.
For an Unauthorized Access to Internal API risk, the API is detected as not being an internal API or as being authenticated.
For other risks, Last Detection Time is more than 7 days ago and the API has been accessed in the last 7 days.
For other risks, Last Detection Time is more than 1 day ago and the access volume today is greater than 100.
View the API assets involved in a risk
Click the source API of the target risk to view the API assets on the API details page. For more information about the API details page, see API details.
View API risk details
Click View Details in the Actions column of the target risk ID to open the risk details page. The page provides the following tabs:
Basic information — View the API, risk ID, time first detected, risk description, handling suggestion, domain name, business purpose, status, AI analysis, and other information.
Risk status description — View the available risk statuses and set the status of the risk.
Risk Verification — View the request samples. You can also perform the following operations:
Click Browser to open the GET request directly in a browser.
Click Command Line to convert the request sample into a command line. Click Copy and manually access the request.
Click Copy Code to copy the request sample.
Operation Records — View the handling records of the risk event.
View security event data
The Security Events tab of the API Security page shows the statistics and the conditional search of API attack event analysis. To open the tab, click Security Events, or click More in the upper-right corner of the Statistics on Attacked Sites table.
The tab provides an IP Security Events tab and an Account Security Events tab. Both contain the same three feature modules: attack impact statistics, the left-side event type pane, and API security event details. The statistics items and the available search fields differ by dimension.
Attack impact statistics
The items in the attack impact statistics module depend on the tab:
IP Security Events: Attacked Domain Names, Attacked APIs, and the number of High-Risk Events, Moderate-Risk Events, and Low-Risk Events, each with its New Events Today count.
Account Security Events: Risky Account, and the number of High-Risk Events, Moderate-Risk Events, and Low-Risk Events, each with its New Events Today count.
Click any number in the module to view the matching security event records in Details of API Security Events.
Left-side event type pane
The left-side event type pane shows the event types of the API assets that you own and the corresponding counts. Click an event type to view the events of that type in Details of API Security Events.
API security event details
The Details of API Security Events module lists the detected security events. From this list, you can search for a specific event and open its details page. You can also change the status of an event, add the source IP address or account to the whitelist, block the source IP address, and export the event data.
Manage API security events
After you locate the target API security event, you can change its status, add the source IP address or account to the whitelist, block the source IP address, and view the event details.
Change the status of an API security event
Locate the target security event ID, click the
icon in the Status column, select the event status that you want to change to, and then click OK.
Add an IP address or account to the whitelist
Click Add to Whitelist in the Actions column of the target event to add the IP address or account that generated the current event to the whitelist with one click. By default, this action has the following results:
The rule type of the current event is no longer detected.
The event status changes to Confirmed.
Block an IP address
Click Block IP Address in the Actions column of the target event to add the IP address of the current event to the denylist with one click. By default, the event status changes to Handled.
View API security event details
Click View Details in the Actions column of the target event to open the event details page. The page provides the following information:
Basic information — View the event ID, start and end time, status, and other information. You can also change the status of the security event. When you set the status to Confirmed, Handled, or Ignore, you can enter remark information.
Attack details — View the data samples, event trends, and other information.
For IP security events, click Log Query in the Actions column of Attack Source Analysis to query logs.
For account security events, click Log Query in the Actions column of API Distribution to query logs.
Handling suggestion — View the suggestions for handling the security event.
Operation records — View the handling records of the security event.
Search for API risks and security events
The API Risk Details list and the Details of API Security Events list support the same two search methods. Use simple search to look up a single record by one field, or use advanced search to filter records by multiple conditions.
Simple search
In the search box above the list, click the
icon, select a search field, enter the corresponding API name, ID, IP address, or account, and then click Search to run the query. Fuzzy search is supported.
The available search fields depend on the list.
| List | Search fields |
| API Risk Details | API Operation or Risk Item ID |
| Details of API Security Events, IP Security Events tab | IP, API Operation, or Event ID |
| Details of API Security Events, Account Security Events tab | Account, API Operation, or Event ID |
Advanced search
Click More, configure the search conditions, and then click Search to run the query.
The following figure shows the advanced search conditions.

The following table describes each search condition and the lists in which the condition is available.
| Condition | Description | Available in |
| Time | The time range of the query. Quick queries are supported: the last 15 minutes, the last 30 minutes, the last 1 hour, the last 24 hours, today, yesterday, and the last 7 days. The minimum granularity for a custom time query is 10 minutes. | All lists |
| Risk Level | Multi-select is supported. | API Risk Details |
| Event Level | Multi-select is supported. | Details of API Security Events |
| Status | Multi-select is supported. | All lists |
| Purpose | The business purpose of the API. Multi-select is supported. | API Risk Details and the IP Security Events tab |
| Domain Name | Single-select. | All lists |
| Type | Single-select. | All lists |
For more information about business purpose types, see How API security classifies API business purposes.
Change the displayed items of a list
Click the icon in the upper-right corner of the list, and then select the data fields to display in the list.
Export risk and security event data
Export runs as a task: API security first generates the file, and then you download it from the export records. Complete both of the following steps.
Click the
icon in the upper-right corner of API Risk Details or Details of API Security Events. API security creates an export task for you.Click Export Record in the upper-right corner of the API Security page. Locate the file that you want to download and click Download in the Actions column.
If you configure query conditions, the exported file contains only the queried data. Otherwise, the file contains all data.
After the exported file is generated, it is temporarily stored in the WAF console and expires after three days. Expired files cannot be downloaded. Download the file within its validity period.
The downloaded file is saved to the default download location of your browser. You can go to the default location to view the downloaded file.
Statistical periods, retention, and default query ranges
API security applies different time ranges to the statistics modules, to the stored records, and to the details lists. Account for these differences when a statistics number and a list result do not match.
Statistics modules — The risk statistics and the attack impact statistics use a default statistical period of the last one year.
Risk alert records — Risk alert records that risk detection generates are retained for one year and do not disappear automatically.
Details lists — API Risk Details and Details of API Security Events return data from the last 30 days by default: the 30 full 24-hour days that end yesterday, plus the records that exist for today up to the time of the query.