Skip to Content
WEB应用防火墙 UEWAF获取误报记录列表 - DescribeWafAttackFalseAlarmListInfo

获取误报记录列表 - DescribeWafAttackFalseAlarmListInfo

简介

获取误报记录列表

定义

公共参数

参数名类型描述信息必填
Actionstring对应的 API 指令名称,当前 API 为 DescribeWafAttackFalseAlarmListInfoYes
PublicKeystring用户公钥,可从 控制台 获取Yes
Signaturestring根据公钥及 API 指令生成的用户签名,参见 签名算法Yes

请求参数

参数名类型描述信息必填
ProjectIdstring项目ID。不填写为默认项目,子帐号必须填写。 请参考GetProjectList接口No
Offsetint记录 偏移,等效于PageNumYes
Limitint记录限制数目,等效于PageSizeYes
FullDomainstring要查询的域名,优先级比Domain高No

响应字段

字段名类型描述信息必填
RetCodeint返回状态码,为 0 则为成功返回,非 0 为失败Yes
Actionstring操作指令名称Yes
Messagestring返回错误消息,当 RetCode 非 0 时提供详细的描述信息No
TotalCountint误报记录总数Yes
DetailListarray[WafAttack]误报记录列表,参考WafAttackYes

数据模型

WafAttack

字段名类型描述信息必填
Regionstring区域No
Protocolstring协议No
ServerNamestring服务器名称No
DestIpstring目标IP地址No
Portstring端口No
Alertsarray[WafAlert]告警匹配信息,参考WafAlertNo
Attackstring攻击类型No
Methodstring请求方法No
FalsePositiveboolean是否误报No
RiskRankstring风险等级No
TimeStampint攻击时间戳No
Hoststring主机名No
Refererstring引用地址No
Countint攻击次数No
UristringURINo
Clientstring客户端No
Modestring工作模式No
Actionstring匹配动作No
UAstring用户代理No
Argsstring参数No

WafAlert

字段名类型描述信息必填
Descriptionstring规则描述No
Idint匹配规则IDNo

示例

请求示例

https://api.an-link.com/?Action=DescribeWafAttackFalseAlarmListInfo &ProjectId=org-xxx &Domain=www.test.com &Offset=0 &Limit=10 &FullDomain=izRcaHFo

响应示例

{ "Action": "DescribeWafAttackFalseAlarmListInfoResponse", "DetailList": [ { "AccessId": "183.238.16.138-a9736253", "Action": "DENY", "Alerts": [ { "Description": "XSS", "Id": 32003, "Match": { "0": "\u003cscript", "1": "\u003cscript", "2": "\u003c", "5": "script" } } ], "Args": "", "Attack": "xss", "Client": "183.238.16.138", "ClientIPInfo": { "city_name": "深圳", "country_name": "中国", "latitude": "22.547", "longitude": "114.085947", "owner_domain": "", "region_name": "广东", "timezone": "Asia/Shanghai" }, "Count": 1, "DestIp": "106.75.79.224", "FalsePositive": true, "Host": "www.test.com", "Id": "5e8c1dbb243527db1df82677", "Method": "GET", "Mode": "SIMULATE", "Port": "80", "Protocol": "http", "Referer": "NULL", "Region": "cn-bj", "RequestBody": null, "RequestHeaders": { "Accept": "text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8", "AcceptEncoding": "", "AcceptLanguage": "en-US", "CacheControl": "", "Connection": "", "Cookie": "", "Host": "www.test.com", "UpgradeInsecureRequests": "", "UserAgent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; Tablet PC 2.0)", "XForwardFor": "" }, "RiskRank": "high", "ServerName": "www.test.com", "TimeStamp": 1586240955, "TopId": 50146955, "UA": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; Tablet PC 2.0)", "Uri": "/home.html?user=\u0026password=\u0026action!login:cantLogin%3Cscript%3Ealert(1344)%3C/script%3E=AppScan" } ], "RetCode": 0, "TotalCount": 1 }