This URL gets the policy details (including attack set and response actions) for the specific IPS policy.
Resource URL
GET /ipspolicy/<policy_id>
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| IPS policy id | Number | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| Baseline IPS policy details | Object |
Details of PolicyDescriptor:
Field Name | Description | Data Type |
|---|---|---|
| Baseline IPS policy name | String |
| Policy description | String |
| Is policy visible to child domain | Boolean |
| Inbound policy rule set | String |
| Outbound policy rule set | String |
| Attack category | Object |
| Outbound attack category | Object |
| DoS policy | Object |
| DoS response sensitivity level | Number |
| Is policy editable | Boolean |
| Time stamp at which the policy was added | String |
| Policy version number | Number |
| Is light weight policy configured | Boolean |
Details of object in AttackCategory:
Field Name | Description | Data Type |
|---|---|---|
| List of exploit attacks | Array |
Details of object in ExpolitAttackList:
Field Name | Description | Data Type |
|---|---|---|
| Attack name | String |
| NSP id of the attack | String |
| Attack severity, number between 0 & 9 | Number |
| Is attack severity customized | Boolean |
| Is attack enabled | Boolean |
| Is alert customized | Boolean |
| Is attack recommended for smart blocking | Boolean |
| Attack response | Object |
| Notifications configured | Object |
| List of protocols | Array |
| List of applications impacted | Array |
| List of attack vectors | Array |
| Attack benign trigger probability | String |
| Attack target, can be "Server" or "Client" | String |
| Blocking type, can be "Attack Packet" | String |
| Attack sub category | String |
| Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" | String |
| Is attack customized | Boolean |
Details of object in AttackResponse:
Field Name | Description | Data Type |
|---|---|---|
| TCP reset option, can be “DISABLED” / “SOURCE” / “DESTINATION” / “BOTH” | String |
| Is TCP reset customized | Boolean |
| Send ICMP host unreachable to Source | Boolean |
| Send ICMP host unreachable to Source customized | Boolean |
| NAC notification configured, can be “DISABLED” / “ALL_HOSTS” / “MCAFEE_NAC_UNMANAGED_HOSTS” | String |
| Is NAC notification enabled | Boolean |
| Is quarantine customized | Boolean |
| Is remediate enabled | Boolean |
| Blocking option configured, can be “DISABLE” / “ENABLE” / “ENABLE_SMART_BLOCKING” | String |
| Is blocking option customized | Boolean |
| Should application data be captured prior to attack | Boolean |
| Should application data be captured prior to attack customized | Boolean |
| Action to be taken on attack, can be “DO_NOTHING” / “SEND_ALERT_AND_LOG_PACKETS” / “SEND_ALERT_ONLY” | String |
| Is logging customized | Boolean |
| Customixe flow, can be “SINGLE_FLOW” / “FORENSIC_ANALYSIS” | String |
| Customize flow type | Boolean |
| Is logging N bytes in each packet customized | Boolean |
| Number of bytes to be logged in each packet | Object |
| Packet logging duration | Object |
| Time stamp | String |
Details of object in numberOfBytesInEachPacket (Can be either of the below mentioned):
Field Name | Description | Data Type |
|---|---|---|
| Log entire packet | Object |
| Capture N bytes | Object |
Details of object in CaptureNBytes:
Field Name | Description | Data Type |
|---|---|---|
| Number of bytes to log | Number |
Details of object in loggingDuration (Can be either of the below mentioned):
Field Name | Description | Data Type |
|---|---|---|
| Log attack packet only | Object |
| Capture N packets | Object |
| Capture for a time duration | Object |
| Capture rest of flow | Object |
Details of object in CaptureNPackets:
Field Name | Description | Data Type |
|---|---|---|
| Log n packets | Number |
Details of object in CaptureTimeDuration:
Field Name | Description | Data Type |
|---|---|---|
| Capture time | String |
| Time unit, can be "SECONDS" / "MINUTES" / "HOURS" / "DAYS" | String |
Details of object in notification:
Field Name | Description | Data Type |
|---|---|---|
| Is notification configured through email | Boolean |
| Is notification configured through pager | Boolean |
| Is notification configured through script | Boolean |
| Is notification configured through auto ack | Boolean |
| Is notification configured through SNMP | Boolean |
| Is notification configured through syslog | Boolean |
| Is notification through email customized | Boolean |
| Is notification through pager customized | Boolean |
| Is notification through script customized | Boolean |
| Is notification through auto ack customized | Boolean |
| Is notification through SNMP customized | Boolean |
| Is notification through syslog customized | Boolean |
Details of object in DosPolicy:
Field Name | Description | Data Type |
|---|---|---|
| List of learning attacks | Array |
| List of threshold attacks | Array |
| Time stamp | String |
Details of object in LearningAttack:
Field Name | Description | Data Type |
|---|---|---|
| Attack name | String |
| NSP ID of the attack | String |
| Is attack severity customized | Boolean |
| Attack severity, number between 0 & 9 | Number |
| Is blocking customized | Boolean |
| Drop DoS attack packets of this attack type when detected | Boolean |
| Is alert customized | Boolean |
| Is alert notification to be sent to Manager configured | String |
| Time stamp | String |
| Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" | String |
| Notification to be sent via | Object |
| Is DoS learning attack customized | Boolean |
Details of object in ThresholdAttack:
Field Name | Description | Data Type |
|---|---|---|
| Attack name | String |
| NSP id of the attack | String |
| Is attack severity customized | Boolean |
| Attack severity, number between 0 & 9 | Number |
| Is threshold value customized | Boolean |
| is threshold duration customized | Boolean |
| Threshold values | Number |
| Threshold Interval (Seconds) | Number |
| Is alert customized | Boolean |
| Is alert notification to be sent to Manager configured | String |
| Time stamp | String |
| Notification to be sent | Object |
| Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" | String |
| Is DoS threshold attack customized | Boolean |
Example
Request
GET https://<NSM_IP>/sdkapi/ipspolicy/0
Response
{
"PolicyDescriptor":
{
"PolicyName": "IpsPolicy",
"Description": "To test the IPS policy",
"IsVisibleToChildren": true,
"InboundRuleSet": "TestIPS",
"OutboundRuleSet": "Null",
"AttackCategory":
{
"ExpolitAttackList":
[
{
"attackName": "FTP: VMware Flaw in NAT Function",
"nspId": "0x4050b400",
"severity": 7,
"isSeverityCustomized": false,
"isEnabled": true,
"isAlertCustomized": false,
"isRecommendedForSmartBlocking": false,
"AttackResponse":
{
"TCPReset": "DISABLED",
"isTcpResetCustomized": false,
"isICMPSend": false,
"isICMPSendCustomized": false,
"mcAfeeNACNotification": "DISABLED",
"isMcAfeeNACNotificationEnabled": false,
"isQuarantineCustomized": false,
"isRemediateEnabled": false,
"blockingOption": "DISABLE",
"isBlockingOptionCustomized": false,
"isCapturedPrior": true,
"isCapturedPriorCustomized": false,
"action": "SEND_ALERT_ONLY",
"isLogCustomized": false,
"isFlowCustomized": false,
"isNbytesCustomized": false,
"numberOfBytesInEachPacket":
{
"LogEntirePacket":
{
}
}
},
"notification":
{
"isEmail": false,
"isPager": false,
"isScript": false,
"isAutoAck": false,
"isSnmp": false,
"isSyslog": false,
"isEmailCustomized": false,
"isPagerCustomized": false,
"isScriptCustomized": false,
"isAutoAckCustomized": false,
"isSnmpCustomized": false,
"isSyslogCustomized": false
},
"protocolList":
[
"ftp"
],
"benignTriggerProbability": "1 (Low)",
"blockingType": "attack-packet",
"subCategory": "code-execution",
"direction": "INBOUND",
"isAttackCustomized": false
}
]
},
"OutboundAttackCategory":
{
},
"DosPolicy":
{
"LearningAttack":
[
{
"attackName": "TCP Control Segment Anomaly",
"nspId": "0x40008700",
"isSeverityCustomized": false,
"severity": 7,
"isBlockingSettingCustomized": false,
"isDropPacket": false,
"IsAlertCustomized": false,
"isSendAlertToManager": true,
"direction": "BOTH",
"notification":
{
"isEmail": false,
"isPager": false,
"isScript": false,
"isAutoAck": false,
"isSnmp": false,
"isSyslog": false,
"isEmailCustomized": false,
"isPagerCustomized": false,
"isScriptCustomized": false,
"isAutoAckCustomized": false,
"isSnmpCustomized": false,
"isSyslogCustomized": false
},
"isAttackCustomized": false
}
],
"ThresholdAttack":
[
{
"attackName": "Too Many Inbound TCP SYNs",
"nspId": "0x40008c00",
"isSeverityCustomized": false,
"severity": 6,
"isThresholdValueCustomized": false,
"isThresholdDurationCustomized": false,
"ThresholdValue": 2000,
"ThresholdDuration": 5,
"isAlertCustomized": false,
"isSendAlertToManager": false,
"Notification":
{
"isEmail": false,
"isPager": false,
"isScript": false,
"isAutoAck": false,
"isSnmp": false,
"isSyslog": false,
"isEmailCustomized": false,
"isPagerCustomized": false,
"isScriptCustomized": false,
"isAutoAckCustomized": false,
"isSnmpCustomized": false,
"isSyslogCustomized": false
},
"direction": "INBOUND",
"isAttackCustomized": false
}
],
"TimeStamp": "2012-06-20 18:44:55.000"
},
"DosResponseSensitivityLevel": 0,
"IsEditable": false,
"Timestamp": "2012-06-20 18:44:55.000",
"VersionNum": 1,
"IsLightWeightPolicy": false
}
}
Error Information
Following error code is returned by this URL:
S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 404 | 1108 | Invalid policy Id |