防攻击数据列表(attack)
接口描述:
防攻击数据列表
请求参数:
参数名 | 必选 | 类型 | 说明 |
---|---|---|---|
Offset | 否 | string | 偏移量 |
Limit | 否 | string | 数量 |
响应参数:
参数名 | 说明 |
---|---|
destIP | 被攻击主机的公网IP |
severity | 重要性【hight、low、mid】 |
type | 类型 |
totalFlow | 攻击流量(单位:B) |
top10srcIP | TOP10攻击源 |
top10srcPORT | TOP10源端口 |
top10destPORT | TOP10目标端口 |
attackLog | 攻击日志 |
Resource_Name | 关联主机名 |
响应示例:
{ "code": 200, "msg": "success", "time": "1506750598", "data": { "count": 4, "list": [ { "eventID": "1135385960384922366", "destIP": "10.241.232.164", "userID": "2000000130", "severity": "high", "type": "DNS RESPONSE FLOOD", "pps": 72500, "bps": 743.58, "totalFlow": 27208.89, "top10srcIP": "{\"data\":[{\"ip\":\"177.136.33.50\",\"bps\":607200,\"zone\":\"other\"},{\"ip\":\"180.173.216.216\",\"bps\":597600,\"zone\":\"CT_ShangHai\"}]}", "top10srcPORT": "{\"data\":[{\"ip\":\"53\",\"bps\":525793200}]}", "top10destPORT": "{\"data\":[{\"ip\":\"9491\",\"bps\":607200},{\"ip\":\"421\",\"bps\":597600}]}", "begintime": 1506333125, "endtime": 1506337337, "attackLog": "2017-01-04 16:55:13net.ipv4.sfw_attack_info = UDP-Flood src=103.60.182.70 dst=43.247.90.202 sport=0 dport=0 flag=Fragnet.ipv4.sfw_attack_info = SYN-Flood src=78.232.5.156 dst=43.247.90.202 sport=26565 dport=23 flag=SYN_INVALIDnet.ipv4.sfw_attack_info = UDP-Flood src=77.221.207.162 dst=43.247.90.202 sport=0 dport=0 flag=Frag", "read_time": 1486454368, "start_time": "2017-09-25 17:52", "total_time": "01:10:12", "Resource_Name": "vip_cc" }... ] } }