This URL is used to retrieve traffic statistics for advance callback detection for a Sensor.
Resource URL
GET /sensor/{sensorId}/trafficstats/advcallbackdetectionstats
Request Parameters
URL Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| sensorId | Sensor id | Number | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| callbackDetectorsAlerts | Number of alerts generated due to advanced callback detection | String |
| dgaZombieDetectionAlerts | Number of alerts due to dga zombie detection | String |
| dgaCncServerDetectionAlerts | Number of alerts due to dga cnc server detection | String |
| dgaCncServerConnectionAlerts | Number of alerts due to dga cnc server connection | String |
| fastFluxDnsDetectionAlerts | Number of alerts due to fast flux dns detection | String |
| connectionToFastFluxAgentsAlerts | Number of alerts due to connection to fast flux agents | String |
| zeroDayBotnetDetectionAlerts | Number of alerts due to zero day botnet detection | String |
| knownBotnetDetectionAlerts | Number of known botnet detection alerts | String |
Example
Request
GET https://<NSM_IP>/sdkapi/sensor/1009/trafficstats/advcallbackdetectionstats
Response
{
"callbackDetectorsAlerts": 39,
"dgaZombieDetectionAlerts": 90,
"dgaCncServerDetectionAlerts": 40,
"dgaCncServerConnectionAlerts": 30,
"fastFluxDnsDetectionAlerts": 1,
"connectionToFastFluxAgentsAlerts": 1,
"zeroDayBotnetDetectionAlerts": 3,
"knownBotnetDetectionAlerts": 0
}
Error Information
Following error code is returned by this URL:
| No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 404 | Invalid Sensor: When the device id given is not valid |