防攻击数据列表(attack)
接口描述:
防攻击数据列表
请求参数:
| 参数名 | 必选 | 类型 | 说明 |
|---|---|---|---|
| Offset | 否 | string | 偏移量 |
| Limit | 否 | string | 数量 |
响应参数:
| 参数名 | 说明 |
|---|---|
| destIP | 被攻击主机的公网IP |
| severity | 重要性【hight、low、mid】 |
| type | 类型 |
| totalFlow | 攻击流量(单位:B) |
| top10srcIP | TOP10攻击源 |
| top10srcPORT | TOP10源端口 |
| top10destPORT | TOP10目标端口 |
| attackLog | 攻击日志 |
| Resource_Name | 关联主机名 |
响应示例:
{
"code": 200,
"msg": "success",
"time": "1506750598",
"data": {
"count": 4,
"list": [
{
"eventID": "1135385960384922366",
"destIP": "10.241.232.164",
"userID": "2000000130",
"severity": "high",
"type": "DNS RESPONSE FLOOD",
"pps": 72500,
"bps": 743.58,
"totalFlow": 27208.89,
"top10srcIP": "{\"data\":[{\"ip\":\"177.136.33.50\",\"bps\":607200,\"zone\":\"other\"},{\"ip\":\"180.173.216.216\",\"bps\":597600,\"zone\":\"CT_ShangHai\"}]}",
"top10srcPORT": "{\"data\":[{\"ip\":\"53\",\"bps\":525793200}]}",
"top10destPORT": "{\"data\":[{\"ip\":\"9491\",\"bps\":607200},{\"ip\":\"421\",\"bps\":597600}]}",
"begintime": 1506333125,
"endtime": 1506337337,
"attackLog": "2017-01-04 16:55:13net.ipv4.sfw_attack_info = UDP-Flood src=103.60.182.70 dst=43.247.90.202 sport=0 dport=0 flag=Fragnet.ipv4.sfw_attack_info = SYN-Flood src=78.232.5.156 dst=43.247.90.202 sport=26565 dport=23 flag=SYN_INVALIDnet.ipv4.sfw_attack_info = UDP-Flood src=77.221.207.162 dst=43.247.90.202 sport=0 dport=0 flag=Frag",
"read_time": 1486454368,
"start_time": "2017-09-25 17:52",
"total_time": "01:10:12",
"Resource_Name": "vip_cc"
}...
]
}
}