This URL is used to retrieve traffic statistics for advance callback detection for a Sensor.
Resource URL
GET /sensor/{sensorId}/trafficstats/advcallbackdetectionstats
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Sensor id | Number | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| Number of alerts generated due to advanced callback detection | String |
| Number of alerts due to dga zombie detection | String |
| Number of alerts due to dga cnc server detection | String |
| Number of alerts due to dga cnc server connection | String |
| Number of alerts due to fast flux dns detection | String |
| Number of alerts due to connection to fast flux agents | String |
| Number of alerts due to zero day botnet detection | String |
| Number of known botnet detection alerts | String |
Example
Request
GET https://<NSM_IP>/sdkapi/sensor/1009/trafficstats/advcallbackdetectionstats
Response
{
"callbackDetectorsAlerts": 39,
"dgaZombieDetectionAlerts": 90,
"dgaCncServerDetectionAlerts": 40,
"dgaCncServerConnectionAlerts": 30,
"fastFluxDnsDetectionAlerts": 1,
"connectionToFastFluxAgentsAlerts": 1,
"zeroDayBotnetDetectionAlerts": 3,
"knownBotnetDetectionAlerts": 0
}
Error Information
Following error code is returned by this URL:
No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 404 | Invalid Sensor: When the device id given is not valid |