Updated on 2026-07-28 GMT+08:00

Functions

An API data security protection instance is deployed on an independent system. To log in to an API data security protection instance using a browser, you must bind an EIP to the instance. For details, see Logging In to the Instance Web Console.

API data security protection includes the basic and professional editions. For details about the differences between editions, see Edition Differences.

  • Basic edition: applicable to basic protection requirements.
  • Professional edition: applicable to medium protection requirements.

This document describes the functions supported by the API Data Security Protection system.

Feature Description

Table 1 Functions

Feature

Description

Reference

Dashboard

  • Asset overview: Collects statistics on the number of assets such as applications, APIs, accounts, and sensitive data.
  • Access popularity: Displays access information for the last 7 or 30 days from various dimensions.

Viewing the Home Page

Log center

Records alarm logs and traffic logs, supporting log queries based on multiple conditions.

  • Alarm logs: Allows you to view details about blacklist hits, risk protection, and access control rules.
  • Retrieval logs: Allow you to view the access traffic to a specific service.

Log Center

Asset center

  • Application assets: Gateways can be deployed as proxies by configuring domain names or IP addresses and ports. Multiple proxy types (e.g., HTTP, HTTPS) are available to meet various security and application requirements.
  • API assets: After the proxy is used, the system automatically scans APIs in application assets based on the access status to ensure that no API is missing.
  • Account assets: Accounts and sessions can be identified based on account parsing rules to facilitate targeted management. Various protection rules can be configured based on identified accounts.
  • Built-in sensitive data identification algorithms detect multiple types of sensitive data such as passwords, ID card numbers, and bank card numbers.

Asset Center

Security policy

  • Whitelist: Allows you to configure whitelists with different effective scopes based on conditions such as client IP address, account, and sensitivity label.
  • Access control: Allows you to configure security protection rules for applications based on different combinations of conditions.
  • Risk prevention: Supports built-in attack identification rules and performs blocking or log audit based on the set actions. Custom attack blocking policies can also be defined for automatic attack handling.
  • Blacklist: Allows you to configure a blacklist to block accesses based on any combination of client IP addresses, accounts, and sensitive labels.
  • Masking: Provides built-in common sensitive data labels and corresponding masking algorithms and allows you to add masking templates and configure sensitive data labels and algorithms in batches. Sensitive data returned by APIs can be masked based on different conditions to prevent sensitive data leakage.
  • Watermarking: Allows you to add different types of watermarks to application services, including web page watermarks, dot matrix watermarks, document watermarks, and traceless watermarks. In case of a data leakage incident, the leakage source can be traced based on the watermark content.

Security Policies

Service configuration

  • Sensitive data labels: Allow you to manage sensitive data labels by specifying key values, value keywords, and regular expressions. You can manually add exceptions and sensitive data.
  • Client IP address parsing: By configuring client IP parsing rules, you can parse the identified content at the corresponding identification location to obtain the client IP address.
  • Certificate Management: Allows you to manage SSL certificates in the system.
  • Classification and grading: The system provides built-in sensitive data classification and grading rules, which can be customized.

Service Configuration

System management

  • Network management: Allows you to configure the NIC, route, and DNS information via a web page, or enable bypass status with one click for system troubleshooting.
  • Backup and restoration: Allows you to back up audit logs and configuration files, which can be restored in case of issues or misoperations.
  • Data clearance: Service logs and system logs can be cleared periodically or manually.

System Management

User management

Built-in system administrator, audit administrator, and security administrator are included.

  • System administrator: Responsible for routine system operation and maintenance.
  • Security administrator: Handles routine security management, including granting and revoking user permissions.
  • Audit administrator: Responsible for auditing, tracing, analyzing, and supervising the actions of the system administrator and security administrator.

User Management

System O&M

  • System monitoring: Displays device status and system resource usage in real time to facilitate troubleshooting.
  • System overload: Allows you to configure the system to bypass some traffic when the API data security system is overloaded to reduce pressure.

System O&M