Configuring a Denylist
You can configure a denylist for API data security protection. The access that matches the denylist will be denied. The risk severity of the audit logs that hit the denylist will be marked as unauthorized.
Scenarios
When an enterprise detects malicious calling from some sources, for example, blocked former employee accounts still attempt to access sensitive data APIs, external IP addresses frequently and violently pull user information query APIs, third-party systems that have terminated cooperation still continuously call data sharing APIs, or requests with attack features such as SQL injection and XSS are detected, the security administrator can add the malicious IP addresses, user accounts, or request features to the denylist. Access requests that match the denylist will be directly blocked and cannot reach the backend application server. In addition, these requests will be marked as invalid in audit logs, enabling the security team to quickly identify threat sources and generate compliance audit reports.
Prerequisites
You have added an application asset.
Configuring a Denylist
- Log in to the API data security protection web console as user sysadmin.
- In the navigation pane on the left, choose Security Policies > Access Control.
- Click the Denylist tab and click Add in the upper right corner.
- In the Add Rule dialog box, configure the denylist, as shown in Figure 1.
- After the configuration is complete, click OK to save the denylist.
Verifying a Denylist
- Enter the proxy connection IP address and port (172.16.35.44:8182) of the application in the address box of the browser as the client IP address 172.16.212.65. If the access is denied, the denylist takes effect. The following figure shows an example. Figure 2 Access denied
- Log in to the API data security protection web console as user sysadmin.
- Choose Log Management > Alerts, locate the target request record, and click Details.
- If the request matches the configured denylist and the access risk severity is marked as unauthorized, the denylist takes effect.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot
