全部產品
Search
文件中心

Security Center:DescribeSecureSuggestion - 查詢安全風險處理建議詳情

更新時間:Mar 21, 2026

查詢安全分相關的安全風險的處理建議詳情。

調試

您可以在OpenAPI Explorer中直接運行該介面,免去您計算簽名的困擾。運行成功後,OpenAPI Explorer可以自動產生SDK程式碼範例。

調試

授權資訊

下表是API對應的授權資訊,可以在RAM權限原則語句的Action元素中使用,用來給RAM使用者或RAM角色授予調用此API的許可權。具體說明如下:

  • 操作:是指具體的許可權點。

  • 存取層級:是指每個操作的存取層級,取值為寫入(Write)、讀取(Read)或列出(List)。

  • 資源類型:是指操作中支援授權的資源類型。具體說明如下:

    • 對於必選的資源類型,用前面加 * 表示。

    • 對於不支援資源級授權的操作,用全部資源表示。

  • 條件關鍵字:是指雲產品自身定義的條件關鍵字。

  • 關聯操作:是指成功執行操作所需要的其他許可權。操作者必須同時具備關聯操作的許可權,操作才能成功。

操作

存取層級

資源類型

條件關鍵字

關聯操作

yundun-sas:DescribeSecureSuggestion

get

*全部資源

*

請求參數

名稱

類型

必填

描述

樣本值

SourceIp

string

訪問源的 IP 位址。

192.168.XX.XX

Lang

string

請求和接收訊息的語言類型,預設為 zh。取值:

  • zh:中文

  • en:英文

zh

CalType

string

選取查詢新版安全分或舊版安全分規則,當取值為home_security_score時,查詢新版安全分規則,否則預設查詢舊版安全分規則。

home_security_score

Source

integer

安全分來源,傳空預設為Security Center,枚舉值:

  • 0:Security Center。

  • 1:Business Foundation System控制台。

0

ResourceDirectoryAccountId

integer

資來源目錄成員帳號 ID(阿里雲帳號)。

說明

調用 DescribeMonitorAccounts 介面可以擷取該參數。

1232428423234****

返回參數

名稱

類型

描述

樣本值

object

RequestId

string

本次調用請求的 ID,是由阿里雲為該請求產生的唯一識別碼,可用於排查和定位問題。

676F80E3-4B3F-43DA-9CBB-5FF79F202AA2

TotalCount

integer

待加固的安全風險的總條數。

15

Score

string

安全分分數。

95

CalTime

integer

安全分計算時間戳記。

1755744253000

Suggestions

array<object>

安全風險處理列表。

array<object>

安全風險處理列表。

Points

integer

單個扣分項的扣分值。

40

SuggestType

string

待處理的安全風險的類型。取值:

  • SS_REINFORCE:關鍵功能未配置(例如:惡意主機行為防禦)

  • SS_ALARM:待處理警示

  • SS_VUL:待修複漏洞

  • SS_HC:基準問題

  • SS_AK:AK 泄露問題

  • SS_CLOUD_HC:雲平台配置風險

  • OTHER:其他

SS_ALARM

Detail

array<object>

安全風險處理建議的詳情。

object

安全風險處理建議的詳情。

Title

string

安全風險待處理項的名稱。

Website tamper-proofing capability not configured

Description

string

安全風險處理建議的描述。

Malicious tampering of Web pages will affect your normal access to web page content, and may also lead to serious economic losses, brand losses, and even political risks. The webpage tamper-proof service can monitor the website directory in real time and restore the tampered files or directories through backup, so as to ensure that the website information of important systems is not tampered with maliciously and prevent the occurrence of horse hanging, black chain, illegal implantation of terrorist threats, pornography and other content.

SubType

string

安全風險待處理項的類型。取值包含:

  • ALARM_HIGH:存在未處理的高危警示事件

  • ALARM_MEDIUM:存在未處理的中危警示事件

  • ALARM_LOW:存在未處理的低危警示事件

  • VUL_EMR_UNCHECK:存在未檢測的應急漏洞

  • VUL_EMR_UNFIX:存在未修複的應急漏洞

  • VUL_WIN:存在未修複的 Windows 主機漏洞

  • VUL_LINUX:存在未修複的 Linux 主機漏洞

  • VUL_CMS:存在未修複的 CMS 漏洞

  • ACCESSKEY_LEAK:存在 AK 泄漏風險

  • HC_WARN:存在基準檢查風險

  • HC_WEAK_EXPLOIT_WARN:存在公網暴露的弱口令風險

  • HC_WEAK_PASSWORD_WARN:存在弱口令風險

  • HC_HIGH_EXPLOIT_WARN:存在高危可被入侵的風險

  • HC_OTHER_WARN:存在安全配置風險

  • HC_DATABASE_WARN:資料庫存在安全風險

  • CLOUD_HC_SAS_OPEN:伺服器未安裝安全防護,存在安全風險

  • CLOUD_HC_AEGIS_OFFLINE:伺服器保護狀態為離線

  • CLOUD_HC_ACCOUNT_DOUBLE_CHECK:主帳號未開啟雙因素認證,帳號存在安全風險

  • CLOUD_HC_RDS:RDS-資料庫安全性原則檢查未通過,存在安全風險

  • CLOUD_HC_DDOS:DDoS 高防回源配置檢查未通過,存在安全風險

  • CLOUD_HC_HIGH_LEVEL:雲產品配置存在高危風險

  • CLOUD_HC_OTHER_LEVEL:雲產品配置存在中低危風險

  • OTHER_ATTACH:存在攻擊事件

  • OTHER_DATABASE_ATTACH:資料庫存在安全風險

  • REINFORCE_BASELINE:雲平台配置檢查

  • REINFORCE_SUSPICIOUS:防病毒功能

  • REINFORCE_ANALYSIS:日誌分析

  • REINFORCE_AK_LEAK:AccessKey 泄露情報檢測

  • REINFORCE_WEB_LOCK:未開啟網頁防篡改功能

  • REINFORCE_BRUTE_FORCE:防暴力破解

  • REINFORCE_XPRESS_INSTALL:一鍵安裝用戶端

  • REINFORCE_RANSOMWARE:開啟防勒索策略

  • REINFORCE_UNI_RANSOMWARE:資料庫防勒索

  • REINFORCE_VIRUS_SCHEDULE_SCAN:未開啟周期病毒掃描策略

  • REINFORCE_IMAGE_REPO_SCAN:未配置容器鏡像掃描範圍

  • REINFORCE_IMAGE_SCAN_TASK:一鍵掃描容器鏡像安全風險

  • REINFORCE_K8S_LOG_ANALYSIS:未開啟 K8s 威脅檢測

  • REINFORCE_CONTAINER_NETWORK:容器可視化

  • ALARM_HIGH:Unhandled Urgency Alerts

  • ALARM_MEDIUM:Unhandled Warning Alerts

  • ALARM_LOW:Unhandled Reminder Alerts

  • VUL_EMR_UNCHECK:Unchecked Urgent Vulnerabilities

  • VUL_EMR_UNFIX:Unfixed Urgent Vulnerabilities

  • VUL_WIN:Unfixed Windows Server Vulnerabilities

  • VUL_LINUX:Unfixed Linux Server Vulnerabilities

  • VUL_CMS:Unfixed CMS Vulnerabilities

  • ACCESSKEY_LEAK:AccessKey Leakage Risks

  • HC_WARN:Baseline Risks

  • HC_WEAK_EXPLOIT_WARN:There is a risk of weak passwords exposed by the public network.

  • HC_WEAK_PASSWORD_WARN:Risk of weak password

  • HC_HIGH_EXPLOIT_WARN:There is a high risk of invasion

  • HC_OTHER_WARN:Security Configuration risk

  • HC_DATABASE_WARN:Database has security risks

  • CLOUD_HC_SAS_OPEN:Security protection has not been installed on the server

  • CLOUD_HC_AEGIS_OFFLINE:Server protection status is offline

  • CLOUD_HC_ACCOUNT_DOUBLE_CHECK:Two-Factor Authentication not Enabled for Primary Account

  • CLOUD_HC_RDS:RDS-database security policy failed, security risks

  • CLOUD_HC_DDOS:Risks in Anti-DDoS Pro Back-to-Origin Settings

  • CLOUD_HC_HIGH_LEVEL:Cloud product configuration has high risk

  • CLOUD_HC_OTHER_LEVEL:Cloud product configuration has medium and low risk risks

  • OTHER_ATTACH:Attacks

  • OTHER_DATABASE_ATTACH:Database has security risks

  • REINFORCE_BASELINE:Config Assessment

  • REINFORCE_SUSPICIOUS:Antivirus

  • REINFORCE_ANALYSIS:Log Analysis

  • REINFORCE_AK_LEAK:AccessKey Leaked Intelligence Detection

  • REINFORCE_WEB_LOCK:Website tamper-proofing capability not configured

  • REINFORCE_BRUTE_FORCE:Anti brute force cracking

  • REINFORCE_XPRESS_INSTALL:One-click client installation

  • REINFORCE_RANSOMWARE:Enable anti-extortion strategy

  • REINFORCE_UNI_RANSOMWARE:Anti-ransomware for Databases

  • REINFORCE_VIRUS_SCHEDULE_SCAN:Periodic virus scan policies not configured

  • REINFORCE_IMAGE_REPO_SCAN:No container image scan range configured

  • REINFORCE_IMAGE_SCAN_TASK:Image security scan

  • REINFORCE_K8S_LOG_ANALYSIS:Container K8s threat detection is disabled

  • REINFORCE_CONTAINER_NETWORK:Container Visualization

REINFORCE_WEB_LOCK

樣本

正常返回樣本

JSON格式

{
  "RequestId": "676F80E3-4B3F-43DA-9CBB-5FF79F202AA2",
  "TotalCount": 15,
  "Score": "95",
  "CalTime": 1755744253000,
  "Suggestions": [
    {
      "Points": 40,
      "SuggestType": "SS_ALARM",
      "Detail": [
        {
          "Title": "Website tamper-proofing capability not configured",
          "Description": "Malicious tampering of Web pages will affect your normal access to web page content, and may also lead to serious economic losses, brand losses, and even political risks. The webpage tamper-proof service can monitor the website directory in real time and restore the tampered files or directories through backup, so as to ensure that the website information of important systems is not tampered with maliciously and prevent the occurrence of horse hanging, black chain, illegal implantation of terrorist threats, pornography and other content.",
          "SubType": "REINFORCE_WEB_LOCK"
        }
      ]
    }
  ]
}

錯誤碼

HTTP status code

錯誤碼

錯誤資訊

描述

400 NoPermission no permission 無此服務的存取權限。
400 RdCheckNoPermission Resource directory account verification has no permission. 資來源目錄帳號校正無許可權。
500 ServerError ServerError 服務故障,請稍後重試!
500 RdCheckInnerError Resource directory account service internal error. 資來源目錄帳號服務內部錯誤。
403 NoPermission caller has no permission 當前操作未被授權,請聯絡主帳號在RAM控制台進行授權後再執行操作。

訪問錯誤中心查看更多錯誤碼。

變更歷史

更多資訊,參考變更詳情