This URL adds a new advanced malware policy.
Resource URL
POST /malwarepolicy
Request Parameters
Payload Request Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Basic properties of the malware policy | Object | Yes |
| List of scanning options per file type | Array | No |
Details of properties:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Policy name | String | Yes |
| Description | String | No |
| Domain id | Number | Yes |
| Is the policy visible to child | Boolean | Yes |
| List of protocols supported | Array | No |
Details of object in protocolsToScan:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Protocol name | String | Yes |
| Protocol number | Number | Yes |
| Protocol status | Boolean | Yes |
Details of object in scanningOptions:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Type of the file | String | Yes |
| List of malware engines supported | Array | Yes |
| Action threshold details | Object | Yes |
| Maximum file size scanned in KB | Number | Yes |
Details of object in malwareEngines:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Malware engine name | String | Yes |
| Status can be DISABLED/UNCHECKED/CHECKED | String | Yes |
| Malware engine id | Number | Yes |
Details of actionThresholds:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Alert to be sent, can be "DISABLED" / "VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" | String | Yes |
| Blocking settings, can be "DISABLED" / "VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" | String | Yes |
| Send TCP reset, can be "DISABLED" / "VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" | String | Yes |
| Save file can be "DISABLED" / "ALWAYS" /"VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" | String | Yes |
| Add to block list can be "DISABLED" / "VERY_LOW" / "LOW" / "MEDIUM" / "HIGH" / "VERY_HIGH" | String | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| Unique id of the created malware policy | Number |
Example
Request
POST https://<NSM_IP>/sdkapi/malwarepolicy
{
"properties":
{
"policyName": "Test",
"description": "Add Malware Policy",
"domainId": 0,
"visibleToChild": true,
"protocolsToScan":
[
{
"protocolName": "HTTP",
"protocolNumber": 16,
"enabled": true
},
{
"protocolName": "SMTP",
"protocolNumber": 12,
"enabled": true
}
]
},
"scanningOptions":
[
{
"fileType": "Executables",
"maximumFileSizeScannedInKB": 5120,
"malwareEngines":
[
{
"name": "GTI File Reputation",
"id": 1,
"status": "UNCHECKED"
},
{
"name": " Blocklist and Allowlist",
"id": 2,
"status": "UNCHECKED"
},
{
"name": "PDF Emulation",
"id": 8,
"status": "DISABLED"
},
{
"name": "NTBA",
"id": 16,
"status": "CHECKED"
},
{
"name": "Advanced Threat Defense",
"id": 64,
"status": "CHECKED"
}
],
"actionThresholds":
{
"alert": "LOW",
"block": "HIGH",
"sendTcpReset": "HIGH",
"saveFile": "DISABLED",
"addToBlockList": "DISABLED"
}
},
{
"fileType": "MS Office Files",
"maximumFileSizeScannedInKB": 1024,
"malwareEngines":
[
{
"name": "GTI File Reputation",
"id": 1,
"status": "DISABLED"
},
{
"name": "Blocklist and Allowlist ",
"id": 2,
"status": "CHECKED"
},
{
"name": "PDF Emulation",
"id": 8,
"status": "DISABLED"
},
{
"name": "NTBA",
"id": 16,
"status": "CHECKED"
},
{
"name": "Advanced Threat Defense",
"id": 64,
"status": "CHECKED"
}
],
"actionThresholds":
{
"alert": "MEDIUM",
"block": "HIGH",
"sendTcpReset": "HIGH",
"saveFile": "DISABLED",
"addToBlockList": "DISABLED"
}
},
{
"fileType": "PDF Files",
"maximumFileSizeScannedInKB": 1024,
"malwareEngines":
[
{
"name": "GTI File Reputation",
"id": 1,
"status": "UNCHECKED"
},
{
"name": " Blocklist and Allowlist ",
"id": 2,
"status": "UNCHECKED"
},
{
"name": "PDF Emulation",
"id": 8,
"status": "CHECKED"
},
{
"name": "NTBA",
"id": 16,
"status": "CHECKED"
},
{
"name": "Advanced Threat Defense",
"id": 64,
"status": "CHECKED"
}
],
"actionThresholds":
{
"alert": "VERY_LOW",
"block": "HIGH",
"sendTcpReset": "HIGH",
"saveFile": "DISABLED",
"addToBlockList": "DISABLED"
}
},
{
"fileType": "Compressed Files",
"maximumFileSizeScannedInKB": 5120,
"malwareEngines":
[
{
"name": "GTI File Reputation",
"id": 1,
"status": "DISABLED"
},
{
"name": " Blocklist and Allowlist ",
"id": 2,
"status": "UNCHECKED"
},
{
"name": "PDF Emulation",
"id": 8,
"status": "DISABLED"
},
{
"name": "NTBA",
"id": 16,
"status": "UNCHECKED"
},
{
"name": "Advanced Threat Defense",
"id": 64,
"status": "CHECKED"
}
],
"actionThresholds":
{
"alert": "VERY_LOW",
"block": "HIGH",
"sendTcpReset": "HIGH",
"saveFile": "DISABLED",
"addToBlockList": "DISABLED"
}
},
{
"fileType": "Android Application Package",
"maximumFileSizeScannedInKB": 2048,
"malwareEngines":
[
{
"name": "GTI File Reputation",
"id": 1,
"status": "CHECKED"
},
{
"name": " Blocklist and Allowlist ",
"id": 2,
"status": "UNCHECKED"
},
{
"name": "PDF Emulation",
"id": 8,
"status": "DISABLED"
},
{
"name": "NTBA",
"id": 16,
"status": "DISABLED"
},
{
"name": "Advanced Threat Defense",
"id": 64,
"status": "CHECKED"
}
],
"actionThresholds":
{
"alert": "VERY_LOW",
"block": "HIGH",
"sendTcpReset": "HIGH",
"saveFile": "DISABLED",
"addToBlockList": "DISABLED"
}
},
{
"fileType": "Java Archive",
"maximumFileSizeScannedInKB": 2048,
"malwareEngines":
[
{
"name": "GTI File Reputation",
"id": 1,
"status": "DISABLED"
},
{
"name": " Blocklist and Allowlist ",
"id": 2,
"status": "UNCHECKED"
},
{
"name": "PDF Emulation",
"id": 8,
"status": "DISABLED"
},
{
"name": "NTBA",
"id": 16,
"status": "UNCHECKED"
},
{
"name": "Advanced Threat Defense",
"id": 64,
"status": "CHECKED"
}
],
"actionThresholds":
{
"alert": "VERY_LOW",
"block": "HIGH",
"sendTcpReset": "HIGH",
"saveFile": "DISABLED",
"addToBlockList": "DISABLED"
}
}
]
}
Response
{
"createdResourceId": 301
}
Error Information
Following error codes are returned by this URL:
S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 400 | 1105 | Invalid domain |
2 | 400 | 2508 | Malware policy name is required |
3 | 400 | 2509 | Invalid protocol list |
4 | 400 | 2513 | Name must contain only letters, numerical, spaces, commas, periods, hyphens or underscore |
5 | 400 | 2514 | Name already in use |
6 | 400 | 2516 | Length of name field cannot exceed 40 characters |
7 | 400 | 2517 | Length of description field cannot exceed 149 characters |