This URL gets all available attack definitions in the Manager.
Resource URL
GET /attacks/
Request Parameters
URL Parameters: None
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| attack_id | Unique attack id | String | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| AttackDescriptorDetailsList | List of attacks with basic information of each attack | Array |
Details of object in AttackDescriptorDetailsList:
| Field Name | Description | Data Type |
|---|---|---|
| attackId | Attack NSP id | String |
| name | Attack name | String |
| DosDirection | Attack direction, can be
"INBOUND" / "OUTBOUND" / "BOTH" |
String |
| Severity | Attack severity, number between 0 and 9 | Number |
| description | Attack details | Object |
Details of description:
| Field Name | Description | Data Type |
|---|---|---|
| definition | Attack definition | String |
| btp | BTP | String |
| rfSB | RFSB | String |
| protectionCategory | Protection category | String |
| target | Attack target | String |
| httpResponseAttack | HTTP response attack | String |
| priority | Priority | String |
| protocols | Protocols | String |
| attackCategory | Attack category | String |
| attackSubCategory | Attack sub category | String |
| snortEngine | Snort engine | String |
| versionAdded | Signature set version in which the attack was added | String |
| versionUpdated | Recent signature set version in which the attack was updated | String |
| reference | References | Object |
| signatures | Signatures | Array |
| componentAttacks | Component attacks | Array |
| comments | Comments | Object |
Details of reference:
| Field Name | Description | Data Type |
|---|---|---|
| nspId | NSP id | String |
| cveId | CVE id list | String |
| microsoftId | Microsoft id list | String |
| bugtraqId | Bug Ttaq id list | String |
| certId | Cert id list | String |
| arachNidsId | ArchNid id list | String |
| additionInfo | Any additional info | String |
Details of object under signatures:
| Field Name | Description | Data Type |
|---|---|---|
| name | Signature name | String |
| conditions | List of conditions | List of string |
Details of object under componentAttacks:
| Field Name | Description | Data Type |
|---|---|---|
| nspId | NSP id | String |
| attackName | Attack name | String |
Details of comments:
| Field Name | Description | Data Type |
|---|---|---|
| comments | Comments | String |
| availabeToChildDomains | Available to child domains or not | Boolean |
| parentDomainComments | Parent domain comments | String |
Example
Request
GET https://<NSM_IP>/sdkapi/attacks
Response
{
"AttackDescriptorDetailsList": [
...
{
"DosDirection": null,
"Severity": 5,
"attackId": "0x00000100",
"name": "IP: IP Fragment too Large",
"description": {
"definition": "The Fragment offset plus the length exceeds 65,535. This generic condition indicates either errors in some network hardware/software, or maliciously constructed fragmented packets.\n\nnull\n\nnull\n\nnull\n\nSoftware Packages <br>any Internet connected machine<ul></ul>",
"btp": "Low",
"rfSB": "No",
"protectionCategory": "[Network Protection/IP]",
"target": "Server",
"httpResponseAttack": "No",
"priority": "High",
"protocols": "ipv4",
"attackCategory": "Exploit",
"attackSubCategory": "Protocol Violation",
"snortEngine": "---",
"versionAdded": "10.8.10.6",
"versionUpdated": "10.8.10.6",
"reference": {
"nspId": "0x00000100",
"cveId": "",
"microsoftId": "",
"bugtraqId": "",
"certId": "",
"arachNidsId": "",
"additionInfo": null
},
"signatures": [
{
"name": "Signature#1",
"conditions": [
"condition 1",
" System Event Name=\"ip-fragment-too-large\" "
]
}
],
"componentAttacks": [],
"comments": {
"comments": "",
"availabeToChildDomains": true,
"parentDomainComments": null
}
}
}
...
]
}
Error Information
Following error code is returned by this URL:
| S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 500 | 1001 | Internal error |