更新时间:2024-04-29 GMT+08:00
分享

查询攻击日志

功能介绍

查询攻击日志

调用方法

请参见如何调用API

URI

GET /v1/{project_id}/cfw/logs/attack

表1 路径参数

参数

是否必选

参数类型

描述

project_id

String

租户项目id

表2 Query参数

参数

是否必选

参数类型

描述

start_time

Long

开始时间

end_time

Long

结束时间

src_ip

String

源IP

src_port

Integer

源端口号

最小值:0

最大值:65535

dst_ip

String

目的IP

dst_port

Integer

目的端口号

最小值:0

最大值:65535

protocol

String

协议类型:TCP为6, UDP为17,ICMP为1,ICMPV6为58,ANY为-1,手动类型不为空,自动类型为空

枚举值:

  • 6
  • 17
  • 1
  • 58

app

String

应用协议

log_id

String

日志ID,当是第一页时为空,不是第一页时不为空

next_date

Long

下个日期,当是第一页时为空,不是第一页时不为空

offset

Integer

偏移量:指定返回记录的开始位置,必须为数字,取值范围为大于或等于0,默认0

limit

Integer

每页显示个数,范围为1-1024

fw_instance_id

String

防火墙实例id,创建云防火墙后用于标志防火墙由系统自动生成的标志id,可通过调用查询防火墙实例接口获得。具体可参考APIExlorer和帮助中心FAQ。

action

String

动作0:permit,1:deny

枚举值:

  • 0
  • 1

direction

String

方向0:外到内1:内到外

枚举值:

  • 0
  • 1

attack_type

String

入侵事件类型

attack_rule

String

入侵事件规则

level

String

威胁等级
  • CRITICAL:严重
  • HIGH:高
  • MEDIUM:中
  • LOW:低

source

String

判断来源

enterprise_project_id

String

企业项目id,用户支持企业项目后,由企业项目生成的id。

dst_host

String

目标主机

log_type

String

日志类型

枚举值:

  • internet
  • nat
  • vpc

attack_rule_id

String

入侵事件id

src_region_name

String

源region名称

dst_region_name

String

目的region名称

请求参数

表3 请求Header参数

参数

是否必选

参数类型

描述

X-Auth-Token

String

用户Token。 通过调用IAM服务获取用户Token接口获取(响应消息头中X-Subject-Token的值)

响应参数

状态码: 200

表4 响应Body参数

参数

参数类型

描述

data

data object

查询攻击日志返回值

表5 data

参数

参数类型

描述

total

Integer

返回数量

limit

Integer

每页显示个数,范围为1-1024

records

Array of records objects

记录

表6 records

参数

参数类型

描述

direction

String

方向,有内到外和外到内两种

枚举值:

  • out2in
  • in2out

action

String

动作

event_time

Long

事件时间

attack_type

String

攻击类型

attack_rule

String

攻击规则

level

String

威胁等级

source

String

来源

packet_length

Long

报文长度

attack_rule_id

String

攻击规则id

hit_time

Integer

命中时间

log_id

String

日志ID

src_ip

String

源IP

src_port

Integer

源端口

最小值:0

最大值:65535

dst_ip

String

目的IP

dst_port

Integer

目的端口

最小值:0

最大值:65535

protocol

String

协议

packet

String

攻击日志报文

app

String

应用协议

packetMessages

Array of PacketMessage objects

攻击报文信息

dst_host

String

目标主机

src_region_id

String

源区域id

src_region_name

String

源区域名称

dst_region_id

String

目的区域id

dst_region_name

String

目的区域名称

表7 PacketMessage

参数

参数类型

描述

hex_index

String

16进制index

hexs

Array of strings

16进制数列

utf8_String

String

utf_8字符串

状态码: 400

表8 响应Body参数

参数

参数类型

描述

error_code

String

错误码

最小长度:8

最大长度:36

error_msg

String

错误描述

最小长度:2

最大长度:512

请求示例

查询项目id为9d80d070b6d44942af73c9c3d38e0429防火墙id为2af58b7c-893c-4453-a984-bdd9b1bd6318初始时间为1663567058000,结束时间为1664171765000的第一页数据,查询条数为10条

https://{Endpoint}/v1/9d80d070b6d44942af73c9c3d38e0429/cfw/logs/attack?fw_instance_id=2af58b7c-893c-4453-a984-bdd9b1bd6318&start_time=1663567058000&end_time=1664171765000&limit=10

响应示例

状态码: 200

OK

{
  "data" : {
    "limit" : 10,
    "records" : [ {
      "action" : "deny",
      "app" : "HTTP",
      "attack_rule" : "Tool Nmap Web Server Probe Detected",
      "attack_rule_id" : "336154",
      "attack_type" : "Web Attack",
      "direction" : "out2in",
      "dst_ip" : "100.95.148.49",
      "dst_port" : 8080,
      "event_time" : 1664146216000,
      "level" : "MEDIUM",
      "log_id" : "15591",
      "packet" : "+hZUZMhV+hY/AaHMCABFKABpXPNAADAGof1kVe6QZF+UMcTQH5B0wdaz888+uoAYAOVyNQAAAQEICjrmikVb9JLCR0VUIC9uaWNlJTIwcG9ydHMlMkMvVHJpJTZFaXR5LnR4dCUyZWJhayBIVFRQLzEuMA0KDQo=",
      "packetMessages" : [ {
        "hex_index" : "00000000",
        "hexs" : [ "fa", "16", "54", "64", "c8", "55", "fa", "16", "3f", "01", "a1", "cc", "08", "00", "45", "28" ],
        "utf8_String" : ".\u0016Td.U.\u0016?.....E("
      }, {
        "hex_index" : "00000010",
        "hexs" : [ "00", "69", "5c", "f3", "40", "00", "30", "06", "a1", "fd", "64", "55", "ee", "90", "64", "5f" ],
        "utf8_String" : ".i\\.@.0...dU.d_"
      }, {
        "hex_index" : "00000020",
        "hexs" : [ "94", "31", "c4", "d0", "1f", "90", "74", "c1", "d6", "b3", "f3", "cf", "3e", "ba", "80", "18" ],
        "utf8_String" : ".1..\u001F.t.ֳ..>..."
      }, {
        "hex_index" : "00000030",
        "hexs" : [ "00", "e5", "72", "35", "00", "00", "01", "01", "08", "0a", "3a", "e6", "8a", "45", "5b", "f4" ],
        "utf8_String" : "..r5......:.E[."
      }, {
        "hex_index" : "00000040",
        "hexs" : [ "92", "c2", "47", "45", "54", "20", "2f", "6e", "69", "63", "65", "25", "32", "30", "70", "6f" ],
        "utf8_String" : "..GET /nice%20po"
      }, {
        "hex_index" : "00000050",
        "hexs" : [ "72", "74", "73", "25", "32", "43", "2f", "54", "72", "69", "25", "36", "45", "69", "74", "79" ],
        "utf8_String" : "rts%2C/Tri%6Eity"
      }, {
        "hex_index" : "00000060",
        "hexs" : [ "2e", "74", "78", "74", "25", "32", "65", "62", "61", "6b", "20", "48", "54", "54", "50", "2f" ],
        "utf8_String" : ".txt%2ebak HTTP/"
      }, {
        "hex_index" : "00000070",
        "hexs" : [ "31", "2e", "30", "0d", "0a", "0d", "0a" ],
        "utf8_String" : "1.0\r.\r."
      } ],
      "packet_length" : 119,
      "protocol" : "TCP",
      "source" : "0",
      "src_ip" : "100.85.238.144",
      "src_port" : 50384
    } ],
    "total" : 1
  }
}

状态码: 400

Bad Request

{
  "error_code" : "00500002",
  "error_msg" : "时间间距错误"
}

SDK代码示例

SDK代码示例如下。

Java

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
package com.huaweicloud.sdk.test;

import com.huaweicloud.sdk.core.auth.ICredential;
import com.huaweicloud.sdk.core.auth.BasicCredentials;
import com.huaweicloud.sdk.core.exception.ConnectionException;
import com.huaweicloud.sdk.core.exception.RequestTimeoutException;
import com.huaweicloud.sdk.core.exception.ServiceResponseException;
import com.huaweicloud.sdk.cfw.v1.region.CfwRegion;
import com.huaweicloud.sdk.cfw.v1.*;
import com.huaweicloud.sdk.cfw.v1.model.*;


public class ListAttackLogsSolution {

    public static void main(String[] args) {
        // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
        // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
        String ak = System.getenv("CLOUD_SDK_AK");
        String sk = System.getenv("CLOUD_SDK_SK");

        ICredential auth = new BasicCredentials()
                .withAk(ak)
                .withSk(sk);

        CfwClient client = CfwClient.newBuilder()
                .withCredential(auth)
                .withRegion(CfwRegion.valueOf("<YOUR REGION>"))
                .build();
        ListAttackLogsRequest request = new ListAttackLogsRequest();
        request.withStartTime(<start_time>L);
        request.withEndTime(<end_time>L);
        request.withSrcIp("<src_ip>");
        request.withSrcPort(<src_port>);
        request.withDstIp("<dst_ip>");
        request.withDstPort(<dst_port>);
        request.withProtocol(ListAttackLogsRequest.ProtocolEnum.fromValue("<protocol>"));
        request.withApp("<app>");
        request.withLogId("<log_id>");
        request.withNextDate(<next_date>L);
        request.withOffset(<offset>);
        request.withLimit(<limit>);
        request.withFwInstanceId("<fw_instance_id>");
        request.withAction(ListAttackLogsRequest.ActionEnum.fromValue("<action>"));
        request.withDirection(ListAttackLogsRequest.DirectionEnum.fromValue("<direction>"));
        request.withAttackType("<attack_type>");
        request.withAttackRule("<attack_rule>");
        request.withLevel("<level>");
        request.withSource("<source>");
        request.withEnterpriseProjectId("<enterprise_project_id>");
        request.withDstHost("<dst_host>");
        request.withLogType(ListAttackLogsRequest.LogTypeEnum.fromValue("<log_type>"));
        try {
            ListAttackLogsResponse response = client.listAttackLogs(request);
            System.out.println(response.toString());
        } catch (ConnectionException e) {
            e.printStackTrace();
        } catch (RequestTimeoutException e) {
            e.printStackTrace();
        } catch (ServiceResponseException e) {
            e.printStackTrace();
            System.out.println(e.getHttpStatusCode());
            System.out.println(e.getRequestId());
            System.out.println(e.getErrorCode());
            System.out.println(e.getErrorMsg());
        }
    }
}

Python

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
# coding: utf-8

from huaweicloudsdkcore.auth.credentials import BasicCredentials
from huaweicloudsdkcfw.v1.region.cfw_region import CfwRegion
from huaweicloudsdkcore.exceptions import exceptions
from huaweicloudsdkcfw.v1 import *

if __name__ == "__main__":
    # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak = __import__('os').getenv("CLOUD_SDK_AK")
    sk = __import__('os').getenv("CLOUD_SDK_SK")

    credentials = BasicCredentials(ak, sk) \

    client = CfwClient.new_builder() \
        .with_credentials(credentials) \
        .with_region(CfwRegion.value_of("<YOUR REGION>")) \
        .build()

    try:
        request = ListAttackLogsRequest()
        request.start_time = <start_time>
        request.end_time = <end_time>
        request.src_ip = "<src_ip>"
        request.src_port = <src_port>
        request.dst_ip = "<dst_ip>"
        request.dst_port = <dst_port>
        request.protocol = "<protocol>"
        request.app = "<app>"
        request.log_id = "<log_id>"
        request.next_date = <next_date>
        request.offset = <offset>
        request.limit = <limit>
        request.fw_instance_id = "<fw_instance_id>"
        request.action = "<action>"
        request.direction = "<direction>"
        request.attack_type = "<attack_type>"
        request.attack_rule = "<attack_rule>"
        request.level = "<level>"
        request.source = "<source>"
        request.enterprise_project_id = "<enterprise_project_id>"
        request.dst_host = "<dst_host>"
        request.log_type = "<log_type>"
        response = client.list_attack_logs(request)
        print(response)
    except exceptions.ClientRequestException as e:
        print(e.status_code)
        print(e.request_id)
        print(e.error_code)
        print(e.error_msg)

Go

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
package main

import (
	"fmt"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic"
    cfw "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/cfw/v1"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/services/cfw/v1/model"
    region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/cfw/v1/region"
)

func main() {
    // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak := os.Getenv("CLOUD_SDK_AK")
    sk := os.Getenv("CLOUD_SDK_SK")

    auth := basic.NewCredentialsBuilder().
        WithAk(ak).
        WithSk(sk).
        Build()

    client := cfw.NewCfwClient(
        cfw.CfwClientBuilder().
            WithRegion(region.ValueOf("<YOUR REGION>")).
            WithCredential(auth).
            Build())

    request := &model.ListAttackLogsRequest{}
	request.StartTime = int64(<start_time>)
	request.EndTime = int64(<end_time>)
	srcIpRequest:= "<src_ip>"
	request.SrcIp = &srcIpRequest
	srcPortRequest:= int32(<src_port>)
	request.SrcPort = &srcPortRequest
	dstIpRequest:= "<dst_ip>"
	request.DstIp = &dstIpRequest
	dstPortRequest:= int32(<dst_port>)
	request.DstPort = &dstPortRequest
	protocolRequest:= model.GetListAttackLogsRequestProtocolEnum().<PROTOCOL>
	request.Protocol = &protocolRequest
	appRequest:= "<app>"
	request.App = &appRequest
	logIdRequest:= "<log_id>"
	request.LogId = &logIdRequest
	nextDateRequest:= int64(<next_date>)
	request.NextDate = &nextDateRequest
	offsetRequest:= int32(<offset>)
	request.Offset = &offsetRequest
	request.Limit = int32(<limit>)
	request.FwInstanceId = "<fw_instance_id>"
	actionRequest:= model.GetListAttackLogsRequestActionEnum().<ACTION>
	request.Action = &actionRequest
	directionRequest:= model.GetListAttackLogsRequestDirectionEnum().<DIRECTION>
	request.Direction = &directionRequest
	attackTypeRequest:= "<attack_type>"
	request.AttackType = &attackTypeRequest
	attackRuleRequest:= "<attack_rule>"
	request.AttackRule = &attackRuleRequest
	levelRequest:= "<level>"
	request.Level = &levelRequest
	sourceRequest:= "<source>"
	request.Source = &sourceRequest
	enterpriseProjectIdRequest:= "<enterprise_project_id>"
	request.EnterpriseProjectId = &enterpriseProjectIdRequest
	dstHostRequest:= "<dst_host>"
	request.DstHost = &dstHostRequest
	logTypeRequest:= model.GetListAttackLogsRequestLogTypeEnum().<LOG_TYPE>
	request.LogType = &logTypeRequest
	response, err := client.ListAttackLogs(request)
	if err == nil {
        fmt.Printf("%+v\n", response)
    } else {
        fmt.Println(err)
    }
}

更多

更多编程语言的SDK代码示例,请参见API Explorer的代码示例页签,可生成自动对应的SDK代码示例。

状态码

状态码

描述

200

OK

400

Bad Request

401

Unauthorized

403

Forbidden

404

Not Found

500

Internal Server Error

错误码

请参见错误码

分享:

    相关文档

    相关产品