This URL retrieves the top attacks.
Resource URL
GET /alerts/TopN/attacks
Request Parameters
URL Parameters: None
Payload Request Parameters: None
Query Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| duration | Indicates the start time for the alerts. The default value is LAST_14_DAYS. Duration can be:
|
String | No |
Response Parameters
Following fields are returned.
| Field Name | Description | Data Type |
|---|---|---|
| TopAttacksList |
List of top attacks |
Array |
Details of fields in TopAttacksList:
| Field Name | Description | Data Type |
|---|---|---|
| attackName | Name of the attack | String |
| attackCount | Count of the attack | Number |
Example
Request
GET https://<NSM_IP>/sdkapi/alerts/TopN/attacks?duration=LAST_14_DAYS
Payload
None
Response
{
"TopAttacksList":[{"attackName":"NETBIOS-SS:
Microsoft Windows SMB Client Race Condition Vulnerability","attackCount":84637.0},
{"attackName":"HTTP: KeepAlive Request Detected","attackCount":62959.0},
{"attackName":"SSL: Client-Initiated Key Renegotiation Detected","attackCount":56981.0},
{"attackName":"P2P: BitTorrent Meta-Info Retrieving","attackCount":52976.0},
{"attackName":"P2P: Ares/Warez-Gnutella Traffic Detected","attackCount":52540.0},
{"attackName":"SSL: Server-Initiated Key Renegotiation Detected","attackCount":41306.0},
{"attackName":"IPv4: TCP Session Hijacking Attempt Detected","attackCount":40540.0},
{"attackName":"HTTP: Carberp Trojan Traffic Detected","attackCount":32008.0},
{"attackName":"P2P: BitTorrent File Transfer HandShaking","attackCount":21072.0},
{"attackName":"HTTP: IIS root.exe Execute Command","attackCount":20739.0}]
}
Error Information
Following error codes are returned by this URL:
| No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 500 | 1001 | Internal error |
| 2 | 400 | 3601 | Invalid duration |