This URL adds a new advanced malware policy.
Resource URL
POST /malwarepolicyRequest Parameters
Payload Request Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| properties | Basic properties of the malware policy | Object | Yes |
| scanningOptions | List of scanning options per file type | Array | No |
Details of properties:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| policyName | Policy name | String | Yes |
| description | Description | String | No |
| domainId | Domain id | Number | Yes |
| visibleToChild | Is the policy visible to child | Boolean | Yes |
| protocolsToScan | List of protocols supported | Array | No |
Details of object in protocolsToScan:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| protocolName | Protocol name | String | Yes |
| protocolNumber | Protocol number | Number | Yes |
| enabled | Protocol status | Boolean | Yes |
Details of object in scanningOptions:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| fileType | Type of the file | String | Yes |
| malwareEngines | List of malware engines supported | Array | Yes |
| actionThresholds | Action threshold details | Object | Yes |
| maximumFileSizeScannedInKB | Maximum file size scanned in KB | Number | Yes |
Details of object in malwareEngines:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| name | Malware engine name | String | Yes |
| status | Status can be DISABLED/UNCHECKED/CHECKED | String | Yes |
| id | Malware engine id | Number | Yes |
Details of actionThresholds:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| alert | Alert to be sent, can be "DISABLED" / "VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" | String | Yes |
| block | Blocking settings, can be "DISABLED" / "VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" | String | Yes |
| sendTcpReset | Send TCP reset, can be "DISABLED" / "VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" | String | Yes |
| saveFile | Save file can be "DISABLED" / "ALWAYS" /"VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" | String | Yes |
| addToBlockList | Add to block list can be "DISABLED" / "VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" | String | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| createdResourceId | Unique id of the created malware policy | Number |
Example
Request
POST https://%3CNSM_IP%3E/sdkapi/malwarepolicy
{
"properties":
{
"policyName": "Test",
"description": "Add Malware Policy",
"domainId": 0,
"visibleToChild": true,
"protocolsToScan":
[
{
"protocolName": "HTTP",
"protocolNumber": 16,
"enabled": true
},
{
"protocolName": "SMTP",
"protocolNumber": 12,
"enabled": true
}
]
},
"scanningOptions":
[
{
"fileType": "Executables",
"maximumFileSizeScannedInKB": 5120,
"malwareEngines":
[
{
"name": "GTI File Reputation",
"id": 1,
"status": "UNCHECKED"
},
{
"name": " Blocklist and Allowlist",
"id": 2,
"status": "UNCHECKED"
},
{
"name": "PDF Emulation",
"id": 8,
"status": "DISABLED"
},
{
"name": "NTBA",
"id": 16,
"status": "CHECKED"
},
{
"name": "Advanced Threat Defense",
"id": 64,
"status": "CHECKED"
}
],
"actionThresholds":
{
"alert": "LOW",
"block": "HIGH",
"sendTcpReset": "HIGH",
"saveFile": "DISABLED",
"addToBlockList": "DISABLED"
}
},
{
"fileType": "MS Office Files",
"maximumFileSizeScannedInKB": 1024,
"malwareEngines":
[
{
"name": "GTI File Reputation",
"id": 1,
"status": "DISABLED"
},
{
"name": "Blocklist and Allowlist ",
"id": 2,
"status": "CHECKED"
},
{
"name": "PDF Emulation",
"id": 8,
"status": "DISABLED"
},
{
"name": "NTBA",
"id": 16,
"status": "CHECKED"
},
{
"name": "Advanced Threat Defense",
"id": 64,
"status": "CHECKED"
}
],
"actionThresholds":
{
"alert": "MEDIUM",
"block": "HIGH",
"sendTcpReset": "HIGH",
"saveFile": "DISABLED",
"addToBlockList": "DISABLED"
}
},
{
"fileType": "PDF Files",
"maximumFileSizeScannedInKB": 1024,
"malwareEngines":
[
{
"name": "GTI File Reputation",
"id": 1,
"status": "UNCHECKED"
},
{
"name": " Blocklist and Allowlist ",
"id": 2,
"status": "UNCHECKED"
},
{
"name": "PDF Emulation",
"id": 8,
"status": "CHECKED"
},
{
"name": "NTBA",
"id": 16,
"status": "CHECKED"
},
{
"name": "Advanced Threat Defense",
"id": 64,
"status": "CHECKED"
}
],
"actionThresholds":
{
"alert": "VERY_LOW",
"block": "HIGH",
"sendTcpReset": "HIGH",
"saveFile": "DISABLED",
"addToBlockList": "DISABLED"
}
},
{
"fileType": "Compressed Files",
"maximumFileSizeScannedInKB": 5120,
"malwareEngines":
[
{
"name": "GTI File Reputation",
"id": 1,
"status": "DISABLED"
},
{
"name": " Blocklist and Allowlist ",
"id": 2,
"status": "UNCHECKED"
},
{
"name": "PDF Emulation",
"id": 8,
"status": "DISABLED"
},
{
"name": "NTBA",
"id": 16,
"status": "UNCHECKED"
},
{
"name": "Advanced Threat Defense",
"id": 64,
"status": "CHECKED"
}
],
"actionThresholds":
{
"alert": "VERY_LOW",
"block": "HIGH",
"sendTcpReset": "HIGH",
"saveFile": "DISABLED",
"addToBlockList": "DISABLED"
}
},
{
"fileType": "Android Application Package",
"maximumFileSizeScannedInKB": 2048,
"malwareEngines":
[
{
"name": "GTI File Reputation",
"id": 1,
"status": "CHECKED"
},
{
"name": " Blocklist and Allowlist ",
"id": 2,
"status": "UNCHECKED"
},
{
"name": "PDF Emulation",
"id": 8,
"status": "DISABLED"
},
{
"name": "NTBA",
"id": 16,
"status": "DISABLED"
},
{
"name": "Advanced Threat Defense",
"id": 64,
"status": "CHECKED"
}
],
"actionThresholds":
{
"alert": "VERY_LOW",
"block": "HIGH",
"sendTcpReset": "HIGH",
"saveFile": "DISABLED",
"addToBlockList": "DISABLED"
}
},
{
"fileType": "Java Archive",
"maximumFileSizeScannedInKB": 2048,
"malwareEngines":
[
{
"name": "GTI File Reputation",
"id": 1,
"status": "DISABLED"
},
{
"name": " Blocklist and Allowlist ",
"id": 2,
"status": "UNCHECKED"
},
{
"name": "PDF Emulation",
"id": 8,
"status": "DISABLED"
},
{
"name": "NTBA",
"id": 16,
"status": "UNCHECKED"
},
{
"name": "Advanced Threat Defense",
"id": 64,
"status": "CHECKED"
}
],
"actionThresholds":
{
"alert": "VERY_LOW",
"block": "HIGH",
"sendTcpReset": "HIGH",
"saveFile": "DISABLED",
"addToBlockList": "DISABLED"
}
}
]
}
Response
{
"createdResourceId": 301
}
Error Information
Following error codes are returned by this URL:
| S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 400 | 1105 | Invalid domain |
| 2 | 400 | 2508 | Malware policy name is required |
| 3 | 400 | 2509 | Invalid protocol list |
| 4 | 400 | 2513 | Name must contain only letters, numerical, spaces, commas, periods, hyphens or underscore |
| 5 | 400 | 2514 | Name already in use |
| 6 | 400 | 2516 | Length of name field cannot exceed 40 characters |
| 7 | 400 | 2517 | Length of description field cannot exceed 149 characters |