Mengkueri detail satu aktivitas anomali, termasuk pengatur waktu terjadinya aktivitas anomali, deskripsi anomali, dan status penanganan.
Coba sekarang
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sddp:DescribeEventDetail |
get |
*Semua Sumber daya.
|
|
None |
Parameter permintaan
|
Parameter |
Type |
Required |
Description |
Example |
| Lang |
string |
No |
Bahasa permintaan dan tanggapan. Nilai valid:
|
zh |
| Id |
integer |
Yes |
ID unik aktivitas anomali. Catatan
Untuk mengkueri detail satu aktivitas anomali, berikan ID unik aktivitas anomali. Anda dapat memanggil operasi DescribeEvents untuk memperoleh ID tersebut. |
13456723343 |
Elemen respons
|
Element |
Type |
Description |
Example |
|
object |
|||
| RequestId |
string |
ID permintaan. |
69FB3C1-F4C9-42DF-9B72-7077A8989C13 |
| Event |
object |
Detail aktivitas anomali. |
|
| DisplayName |
string |
Nama tampilan akun yang memicu aktivitas anomali. |
yundunsr |
| Status |
integer |
Status penanganan aktivitas anomali. Nilai valid:
|
0 |
| DealReason |
string |
Alasan penanganan aktivitas anomali. |
Anomaly confirmed |
| UserId |
integer |
ID akun yang memicu aktivitas anomali. |
229157443385014*** |
| StatusName |
string |
Nama status penanganan aktivitas anomali. |
Pending |
| DealTime |
integer |
Pengatur waktu penanganan aktivitas anomali. Format: Stempel waktu UNIX. Unit: milidetik. |
1611139155000 |
| DealLoginName |
string |
Nama login akun yang menangani aktivitas anomali. |
det1111 |
| SubTypeName |
string |
Nama subtipe aktivitas anomali. |
Anomalous volume of downloaded data |
| Backed |
boolean |
Apakah penguatan deteksi diaktifkan untuk aktivitas anomali. Nilai valid:
Catatan
Meningkatkan kemampuan deteksi untuk aktivitas anomali dapat meningkatkan akurasi deteksi dan meningkatkan laju peringatan event untuk aktivitas anomali. |
false |
| DataInstance |
string |
Nama instans aset produk tempat aktivitas anomali berada. |
in-222*** |
| EventTime |
integer |
Pengatur waktu terjadinya aktivitas anomali. Format: Stempel waktu UNIX. Unit: milidetik. |
1545829129000 |
| LoginName |
string |
Nama login akun yang memicu aktivitas anomali. |
det1111 |
| SubTypeCode |
string |
Kode subtipe aktivitas anomali. |
020008 |
| LogDetail |
string |
Informasi log peringatan. |
{"client_ip": ["106.11.XX.XX", "106.11.XX.XX", "106.11.XX.XX", "106.11.XX.XX", "106.11.XX.XX", "106.11.XX.XX", "106.11.XX.XX", "106.11.XX.XX", "106.11.XX.XX"], "start_time": "2020-05-10 00:00:01", "instance": ["omniscience-data", "punish-beaver-data"], "end_time": "2020-05-10 00:21:22", "client_ua": ["Java/1.8.0_152", "Java/1.8.0_92", "aliyun-sdk-java/2.0.0", "aliyun-sdk-java/2.8.0(Linux/4.9.151-015.ali3000.alios7.x86_64/amd64;1.8.0_152)"], "user_name": 1512222261295262} |
| TypeCode |
string |
Kode tipe induk aktivitas anomali. |
02 |
| AlertTime |
integer |
Pengatur waktu pemicuan peringatan untuk aktivitas anomali. Format: Stempel waktu UNIX. Unit: milidetik. |
1545829129000 |
| DealUserId |
integer |
ID akun yang menangani aktivitas anomali. |
229157443385014*** |
| TypeName |
string |
Nama tipe induk aktivitas anomali. Nilai valid:
|
Anomalous data flow |
| DealDisplayName |
string |
Nama tampilan akun yang menangani aktivitas anomali. |
yundunsr |
| Id |
integer |
ID unik aktivitas anomali yang dicatat oleh Pusat Keamanan Data. |
52234 |
| ProductCode |
string |
Nama produk tempat aktivitas anomali berada. Nilai valid: MaxCompute, OSS, ADS, OTS, RDS, dan lainnya. |
MaxCompute |
| HandleInfoList |
array<object> |
Riwayat penanganan. |
|
|
object |
Detail event yang ditangani secara manual. |
||
| Status |
integer |
The status of the handling action. Valid values:
|
1 |
| EnableTime |
integer |
The time when the handling action was enabled. This value is a UNIX timestamp. Unit: milliseconds. |
1611139155000 |
| HandlerValue |
integer |
The duration of the handling action. Unit: minutes. If this parameter is empty, the handling action is permanent. |
10 |
| DisableTime |
integer |
The time when the handling action was disabled. This value is a UNIX timestamp. Unit: milliseconds. |
1611139155000 |
| HandlerName |
string |
The handling method. |
Remove from the whitelist |
| HandlerType |
string |
The handling type. |
rds_security_ip |
| CurrentValue |
string |
Specifies the account that handled the event. |
sddp-test2 |
| Id |
integer |
The handling ID. |
11 |
| Detail |
object |
Konten spesifik dalam detail aktivitas anomali. |
|
| Content |
array<object> |
The content of the anomalous activity. |
|
|
object |
The content of the anomalous activity. |
||
| Label |
string |
The title of the anomalous activity content. |
Anomaly description |
| Value |
string |
The description of the anomalous activity content. |
The account was used to access OSS from an unusual terminal whose IP address is 1.2.3.4 from 00:06:45 on September 9, 2019 to 00:57:37 on September 9, 2019. |
| Name |
string |
The name of the anomalous activity. |
daliaoyuncom |
| Chart |
array<object> |
The baseline behavior profile for the anomalous activity. |
|
|
array<object> |
The baseline behavior profile for the anomalous activity. |
||
| Type |
string |
The type of the chart. Valid values:
|
1 |
| Label |
string |
The name of the baseline behavior profile for the anomalous activity. |
Baseline behavior chart |
| XLabel |
string |
The label of the x-axis. |
Number of days |
| YLabel |
string |
The label of the y-axis. |
Value |
| Data |
object |
The data items of the baseline behavior profile for the anomalous activity. |
|
| Y |
array |
The values of the data items on the y-axis. |
[1,2,3,...] |
|
string |
The value of the data item on the y-axis. |
[1,2,3,...] |
|
| X |
array |
The values of the data items on the x-axis. |
[test1,test2,...] |
|
string |
The value of the data item on the x-axis. |
[test1,test2,...] |
|
| Z |
array |
The values of the data items on the z-axis. |
|
|
string |
The value of the data item on the z-axis. |
[5,7,...] |
|
| ChatType |
integer |
The type of the chart. Valid values:
Catatan
This parameter is returned only when NewAlarm is set to true. |
1 |
| Name |
string |
The title of the chart. Catatan
This parameter is returned only when NewAlarm is set to true. |
misskingm |
| ZLabel |
string |
The label of the z-axis. Catatan
This parameter is returned only when NewAlarm is set to true. |
chart description |
| ResourceInfo |
array<object> |
The information about the source of the anomalous activity. |
|
|
object |
The information about the source of the anomalous activity. |
||
| Label |
string |
The title of the source of the anomalous activity. |
Risk |
| Value |
string |
The description of the source of the anomalous activity. |
Based on the record of authentication by using an unusual terminal, an attacker may have obtained the access permission of the account, or an employee accessed data from a personal terminal. |
| NewAlarm |
boolean |
Apakah peringatan merupakan versi baru. Nilai valid:
|
true |
Contoh
Respons sukses
JSONformat
{
"RequestId": "69FB3C1-F4C9-42DF-9B72-7077A8989C13",
"Event": {
"DisplayName": "yundunsr",
"Status": 0,
"DealReason": "Anomaly confirmed\n",
"UserId": 0,
"StatusName": "Pending",
"DealTime": 1611139155000,
"DealLoginName": "det1111",
"SubTypeName": "Anomalous volume of downloaded data\n",
"Backed": false,
"DataInstance": "in-222***",
"EventTime": 1545829129000,
"LoginName": "det1111",
"SubTypeCode": "020008",
"LogDetail": "{\"client_ip\": [\"106.11.XX.XX\", \"106.11.XX.XX\", \"106.11.XX.XX\", \"106.11.XX.XX\", \"106.11.XX.XX\", \"106.11.XX.XX\", \"106.11.XX.XX\", \"106.11.XX.XX\", \"106.11.XX.XX\"], \"start_time\": \"2020-05-10 00:00:01\", \"instance\": [\"omniscience-data\", \"punish-beaver-data\"], \"end_time\": \"2020-05-10 00:21:22\", \"client_ua\": [\"Java/1.8.0_152\", \"Java/1.8.0_92\", \"aliyun-sdk-java/2.0.0\", \"aliyun-sdk-java/2.8.0(Linux/4.9.151-015.ali3000.alios7.x86_64/amd64;1.8.0_152)\"], \"user_name\": 1512222261295262}",
"TypeCode": "02",
"AlertTime": 1545829129000,
"DealUserId": 0,
"TypeName": "Anomalous data flow\n",
"DealDisplayName": "yundunsr",
"Id": 52234,
"ProductCode": "MaxCompute",
"HandleInfoList": [
{
"Status": 1,
"EnableTime": 1611139155000,
"HandlerValue": 10,
"DisableTime": 1611139155000,
"HandlerName": "Remove from the whitelist\n",
"HandlerType": "rds_security_ip",
"CurrentValue": "sddp-test2",
"Id": 11
}
],
"Detail": {
"Content": [
{
"Label": "Anomaly description\n",
"Value": "The account was used to access OSS from an unusual terminal whose IP address is 1.2.3.4 from 00:06:45 on September 9, 2019 to 00:57:37 on September 9, 2019.",
"Name": "daliaoyuncom"
}
],
"Chart": [
{
"Type": "1",
"Label": "Baseline behavior chart\n",
"XLabel": "Number of days\n",
"YLabel": "Value",
"Data": {
"Y": [
"[1,2,3,...]"
],
"X": [
"[test1,test2,...]"
],
"Z": [
"[5,7,...]"
]
},
"ChatType": 1,
"Name": "misskingm",
"ZLabel": "chart description"
}
],
"ResourceInfo": [
{
"Label": "Risk",
"Value": "Based on the record of authentication by using an unusual terminal, an attacker may have obtained the access permission of the account, or an employee accessed data from a personal terminal."
}
]
},
"NewAlarm": true
}
}
Kode kesalahan
Lihat Error Codes untuk daftar lengkap.
Catatan rilis
Lihat Release Notes untuk daftar lengkap.