This URL gets details for a particular attack.
Resource URL
GET /attack/<attack_id>
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Unique attack id | String | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| Basic attack information | Object |
Details of AttackDescriptor:
Field Name | Description | Data Type |
|---|---|---|
| Attack id | String |
| Attack name | String |
| Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" | String |
| Attack severity, number between 0 and 9 | Number |
| Attack details | Object |
Details of description:
Field Name | Description | Data Type |
|---|---|---|
| Attack definition | String |
| BTP | String |
| RFSB | String |
| Protection category | String |
| Attack target | String |
| HTTP response attack | String |
| Priority | String |
| Protocols | String |
| Attack category | String |
| Attack sub category | String |
| Snort engine | String |
| Signature set version in which the attack was added | String |
| Recent signature set version in which the attack was updated | String |
| References | Object |
| Signatures | Array |
| Component attacks | Array |
| Comments | Object |
Details of reference:
Field Name | Description | Data Type |
|---|---|---|
| NSP id | String |
| CVE did list | String |
| Microsoft id list | String |
| Bug traq id list | String |
| Cert id list | String |
| ArchNid id list | String |
| Any additional info | String |
Details of object under signatures:
Field Name | Description | Data Type |
|---|---|---|
| Signature name | String |
| List of conditions | List of string |
Details of object under componentAttacks:
Field Name | Description | Data Type |
|---|---|---|
| NSP id | String |
| Attack name | String |
Details of comments:
Field Name | Description | Data Type |
|---|---|---|
| Comments | String |
| Available to child domains or not | Boolean |
| Parent domain comments | String |
Example
Request
GET https://<NSM_IP>/attack/0x00000100
Response
{
"AttackDescriptor":
{
"DosDirection": null,
"Severity": 5,
"attackId": "0x00000100",
"name": "IP: IP Fragment too Large",
"description": {
"definition": "The Fragment offset plus the length exceeds 65,535. This generic condition indicates either errors in some network hardware/software, or maliciously constructed fragmented packets.\n\nnull\n\nnull\n\nnull\n\nSoftware Packages <br>any Internet connected machine<ul></ul>",
"btp": "Low",
"rfSB": "No",
"protectionCategory": "[Network Protection/IP]",
"target": "Server",
"httpResponseAttack": "No",
"priority": "High",
"protocols": "ipv4",
"attackCategory": "Exploit",
"attackSubCategory": "Protocol Violation",
"snortEngine": "---",
"versionAdded": "10.8.10.6",
"versionUpdated": "10.8.10.6",
"reference": {
"nspId": "0x00000100",
"cveId": "",
"microsoftId": "",
"bugtraqId": "",
"certId": "",
"arachNidsId": "",
"additionInfo": null
},
"signatures": [
{
"name": "Signature#1",
"conditions": [
"condition 1",
" System Event Name=\"ip-fragment-too-large\" "
]
}
],
"componentAttacks": [],
"comments": {
"comments": "",
"availabeToChildDomains": true,
"parentDomainComments": null
}
}
}
}
Error Information
Following error codes are returned by this URL:
S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 500 | 1001 | Internal error |
2 | 404 | 1402 | Invalid attack id |