Updated on 2024-03-27 GMT+08:00

Modifying Ransomware Protection Policies

Function

This API is used to modify ransomware protection policies.

Calling Method

For details, see Calling APIs.

URI

PUT /v5/{project_id}/ransomware/protection/policy

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

project_id

Yes

String

Project ID

Minimum: 1

Maximum: 256

Table 2 Query Parameters

Parameter

Mandatory

Type

Description

enterprise_project_id

No

String

Enterprise project ID. To query all enterprise projects, set this parameter to all_granted_eps.

Default: 0

Minimum: 1

Maximum: 256

Request Parameters

Table 3 Request header parameters

Parameter

Mandatory

Type

Description

X-Auth-Token

Yes

String

User token. It can be obtained by calling the IAM API used to obtain a user token. The value of X-Subject-Token in the response header is a token.

Minimum: 1

Maximum: 32768

region

Yes

String

Region ID

Minimum: 0

Maximum: 128

Table 4 Request body parameters

Parameter

Mandatory

Type

Description

policy_id

Yes

String

Policy ID

Minimum: 0

Maximum: 128

policy_name

Yes

String

Policy name

Minimum: 0

Maximum: 128

protection_mode

Yes

String

Action. Its value can be:

  • alarm_and_isolation: Report an alarm and isolate.

  • alarm_only: Only report alarms.

Minimum: 0

Maximum: 128

bait_protection_status

No

String

Whether to enable honeypot protection. By default, the protection is enabled. Its value can be:

  • opened

  • closed

Minimum: 0

Maximum: 128

protection_directory

Yes

String

Protected directory. Separate multiple directories with semicolons (;). You can configure up to 20 directories.

Minimum: 1

Maximum: 128

protection_type

Yes

String

Protected file type, for example, .docx, .txt, and .avi.

Minimum: 1

Maximum: 128

exclude_directory

No

String

(Optional) Excluded directory. Separate multiple directories with semicolons (;). You can configure up to 20 directories.

Minimum: 1

Maximum: 128

agent_id_list

No

Array of strings

Specifies the IDs of agents for which the ransomware protection policy is enabled.

Minimum: 1

Maximum: 128

Array Length: 0 - 10000

operating_system

Yes

String

OSs supported by the policy. The options are as follows:

  • Windows

  • Linux

Minimum: 0

Maximum: 64

runtime_detection_status

No

String

Whether to perform runtime checks. The options are as follows. Currently, it can only be disabled. This field is reserved.

  • opened

  • closed

Minimum: 0

Maximum: 128

process_whitelist

No

Array of TrustProcessInfo objects

Process whitelist

Array Length: 0 - 20

Table 5 TrustProcessInfo

Parameter

Mandatory

Type

Description

path

No

String

Indicates the process path.

Minimum: 0

Maximum: 128

hash

No

String

Process hash

Minimum: 0

Maximum: 128

Response Parameters

None

Example Requests

Modify the ransomware protection policy. Set the OS type to Linux, protection policy ID to 0253edfd-30e7-439d-8f3f-17c54c997064, and protection action to alert only.

PUT https://{endpoint}/v5/{project_id}/ransomware/protection/policy

{
  "bait_protection_status" : "opened",
  "protection_type" : "docx",
  "exclude_directory" : "",
  "operating_system" : "Linux",
  "policy_id" : "0253edfd-30e7-439d-8f3f-17c54c997064",
  "policy_name" : "aaa",
  "protection_mode" : "alarm_only",
  "protection_directory" : "/root",
  "runtime_detection_status" : "closed",
  "agent_id_list" : [ "" ]
}

Example Responses

None

SDK Sample Code

The SDK sample code is as follows.

Modify the ransomware protection policy. Set the OS type to Linux, protection policy ID to 0253edfd-30e7-439d-8f3f-17c54c997064, and protection action to alert only.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
package com.huaweicloud.sdk.test;

import com.huaweicloud.sdk.core.auth.ICredential;
import com.huaweicloud.sdk.core.auth.BasicCredentials;
import com.huaweicloud.sdk.core.exception.ConnectionException;
import com.huaweicloud.sdk.core.exception.RequestTimeoutException;
import com.huaweicloud.sdk.core.exception.ServiceResponseException;
import com.huaweicloud.sdk.hss.v5.region.HssRegion;
import com.huaweicloud.sdk.hss.v5.*;
import com.huaweicloud.sdk.hss.v5.model.*;

import java.util.List;
import java.util.ArrayList;

public class UpdateProtectionPolicySolution {

    public static void main(String[] args) {
        // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
        // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
        String ak = System.getenv("CLOUD_SDK_AK");
        String sk = System.getenv("CLOUD_SDK_SK");

        ICredential auth = new BasicCredentials()
                .withAk(ak)
                .withSk(sk);

        HssClient client = HssClient.newBuilder()
                .withCredential(auth)
                .withRegion(HssRegion.valueOf("<YOUR REGION>"))
                .build();
        UpdateProtectionPolicyRequest request = new UpdateProtectionPolicyRequest();
        request.withEnterpriseProjectId("<enterprise_project_id>");
        UpdateProtectionPolicyInfoRequestInfo body = new UpdateProtectionPolicyInfoRequestInfo();
        List<String> listbodyAgentIdList = new ArrayList<>();
        listbodyAgentIdList.add("");
        body.withRuntimeDetectionStatus("closed");
        body.withOperatingSystem("Linux");
        body.withAgentIdList(listbodyAgentIdList);
        body.withExcludeDirectory("");
        body.withProtectionType("docx");
        body.withProtectionDirectory("/root");
        body.withBaitProtectionStatus("opened");
        body.withProtectionMode("alarm_only");
        body.withPolicyName("aaa");
        body.withPolicyId("0253edfd-30e7-439d-8f3f-17c54c997064");
        request.withBody(body);
        try {
            UpdateProtectionPolicyResponse response = client.updateProtectionPolicy(request);
            System.out.println(response.toString());
        } catch (ConnectionException e) {
            e.printStackTrace();
        } catch (RequestTimeoutException e) {
            e.printStackTrace();
        } catch (ServiceResponseException e) {
            e.printStackTrace();
            System.out.println(e.getHttpStatusCode());
            System.out.println(e.getRequestId());
            System.out.println(e.getErrorCode());
            System.out.println(e.getErrorMsg());
        }
    }
}

Modify the ransomware protection policy. Set the OS type to Linux, protection policy ID to 0253edfd-30e7-439d-8f3f-17c54c997064, and protection action to alert only.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
# coding: utf-8

from huaweicloudsdkcore.auth.credentials import BasicCredentials
from huaweicloudsdkhss.v5.region.hss_region import HssRegion
from huaweicloudsdkcore.exceptions import exceptions
from huaweicloudsdkhss.v5 import *

if __name__ == "__main__":
    # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak = __import__('os').getenv("CLOUD_SDK_AK")
    sk = __import__('os').getenv("CLOUD_SDK_SK")

    credentials = BasicCredentials(ak, sk) \

    client = HssClient.new_builder() \
        .with_credentials(credentials) \
        .with_region(HssRegion.value_of("<YOUR REGION>")) \
        .build()

    try:
        request = UpdateProtectionPolicyRequest()
        request.enterprise_project_id = "<enterprise_project_id>"
        listAgentIdListbody = [
            ""
        ]
        request.body = UpdateProtectionPolicyInfoRequestInfo(
            runtime_detection_status="closed",
            operating_system="Linux",
            agent_id_list=listAgentIdListbody,
            exclude_directory="",
            protection_type="docx",
            protection_directory="/root",
            bait_protection_status="opened",
            protection_mode="alarm_only",
            policy_name="aaa",
            policy_id="0253edfd-30e7-439d-8f3f-17c54c997064"
        )
        response = client.update_protection_policy(request)
        print(response)
    except exceptions.ClientRequestException as e:
        print(e.status_code)
        print(e.request_id)
        print(e.error_code)
        print(e.error_msg)

Modify the ransomware protection policy. Set the OS type to Linux, protection policy ID to 0253edfd-30e7-439d-8f3f-17c54c997064, and protection action to alert only.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
package main

import (
	"fmt"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic"
    hss "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/hss/v5"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/services/hss/v5/model"
    region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/hss/v5/region"
)

func main() {
    // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak := os.Getenv("CLOUD_SDK_AK")
    sk := os.Getenv("CLOUD_SDK_SK")

    auth := basic.NewCredentialsBuilder().
        WithAk(ak).
        WithSk(sk).
        Build()

    client := hss.NewHssClient(
        hss.HssClientBuilder().
            WithRegion(region.ValueOf("<YOUR REGION>")).
            WithCredential(auth).
            Build())

    request := &model.UpdateProtectionPolicyRequest{}
	enterpriseProjectIdRequest:= "<enterprise_project_id>"
	request.EnterpriseProjectId = &enterpriseProjectIdRequest
	var listAgentIdListbody = []string{
        "",
    }
	runtimeDetectionStatusUpdateProtectionPolicyInfoRequestInfo:= "closed"
	excludeDirectoryUpdateProtectionPolicyInfoRequestInfo:= ""
	baitProtectionStatusUpdateProtectionPolicyInfoRequestInfo:= "opened"
	request.Body = &model.UpdateProtectionPolicyInfoRequestInfo{
		RuntimeDetectionStatus: &runtimeDetectionStatusUpdateProtectionPolicyInfoRequestInfo,
		OperatingSystem: "Linux",
		AgentIdList: &listAgentIdListbody,
		ExcludeDirectory: &excludeDirectoryUpdateProtectionPolicyInfoRequestInfo,
		ProtectionType: "docx",
		ProtectionDirectory: "/root",
		BaitProtectionStatus: &baitProtectionStatusUpdateProtectionPolicyInfoRequestInfo,
		ProtectionMode: "alarm_only",
		PolicyName: "aaa",
		PolicyId: "0253edfd-30e7-439d-8f3f-17c54c997064",
	}
	response, err := client.UpdateProtectionPolicy(request)
	if err == nil {
        fmt.Printf("%+v\n", response)
    } else {
        fmt.Println(err)
    }
}

For SDK sample code of more programming languages, see the Sample Code tab in API Explorer. SDK sample code can be automatically generated.

Status Codes

Status Code

Description

200

success

Error Codes

See Error Codes.