tencent cloud

Web Application Firewall

Risk Event

Download
Mode fokus
Ukuran font
Terakhir diperbarui: 2026-08-03 16:49:34
Diterjemahkan oleh AI

Feature Introduction

The Risk Events feature supports viewing, analyzing, and handling API risk events. It classifies and converges risks based on expert recommendations and continuously operates protection policies. The following risk event detections are currently supported:
Service Exception
Web Attack
Permission Exception
Account Exception
Resource Abuse
Sensitive Information Exception
Response Exceptions
Event type
Event description
API calls from abnormal regions
Requests that normally access this API are concentrated in a specific region. A large number of requests from other regions are found to have called this API, indicating a potential abnormal call.
API calls from abnormal source IPs
IP addresses that normally access this API are concentrated in a specific network segment. A large number of abnormal IP address segments are found to have called this API, indicating a potential abnormal call.
API calls from abnormal clients
Clients that normally access this API are primarily of a specific type. A large number of requests are found to have called this API through other types of clients, indicating a potential abnormal call.
Event type
Event description
Web Attacks
The API is frequently subjected to more than ten types of Web attacks, including SQL injection, XSS attacks, command injection, unauthorized access to core files, file upload attacks, malicious scanning, trojan backdoor attacks, XML injection, Web application vulnerability attacks, LDAP injection, server-side request forgery, server-side template injection vulnerabilities, unauthorized access vulnerabilities, and non-compliant protocols.
Event type
Event description
Unauthorized Access Successful
The interface exhibits suspected unauthorized access. This means that users are accessing and performing CRUD operations on resources that require authentication without any authorization.
Vertical Privilege Escalation
The interface exhibits suspected vertical privilege escalation. This type of escalation occurs when a user attempts to elevate their own permission level to access or operate on resources or data that are above their current permission level.
Horizontal Privilege Escalation
The interface exhibits suspected horizontal privilege escalation. This type of escalation occurs when a user attempts to access resources or data belonging to other users at the same permission level.
Missing Username and Password
The request lacks the necessary user and password information, which may indicate that an attacker is attempting to attack the business, such as through Fuzzing.
Missing User Value
The request lacks the necessary user information, such as user ID or username, which may indicate that an attacker is attempting to attack the business, such as through Fuzzing.
Missing Login Action
The request lacks the necessary login action, for example, the login request is missing the login action parameter, which may indicate that an attacker is attempting to attack the business, such as through Fuzzing.
Event type
Event description
Brute-force attack
Attackers use automated tools to perform brute-force attacks on target system passwords. Attackers typically use dictionary attacks or brute-force tools to try multiple password combinations until the correct one is found.
Credential stuffing attack
Attackers use known username and password combinations to attempt to log in to target systems, typically by leveraging leaked user information for the attack. Attackers commonly use leaked username and password combinations to try logging in to other websites or systems to see if they can gain access to the target system.
Malicious registration
This means that attackers use false or stolen user information to register, typically to carry out other malicious activities, such as sending spam emails.
Event type
Event description
API abuse
Users or attackers make frequent requests to the API, exceeding normal usage limits, which may impose a burden on the system or create security risks. Attackers typically use automated tools to send a large number of requests in an attempt to consume system resources or perform other malicious actions.
SMS API flooding
Attackers use automated tools to make frequent requests to the SMS API, typically to conduct malicious activities such as SMS bombing or consuming SMS resources.
Captcha API flooding
Attackers use automated tools to make frequent requests to the Captcha API, typically to conduct malicious activities such as Captcha bypass or Captcha resource consumption.
Event type
Event description
Excessive Sensitive Data Retrieval
Users or attackers obtain a significant volume of sensitive data by calling this API, which may lead to sensitive data leaks and internal information insecurity.
Unauthorized Access to Obtain Sensitive Information
Users or attackers access sensitive data within the system without authorization, leading to sensitive data leaks and internal information insecurity.
Weak Encryption Transmission
Passwords, keys, and other sensitive content transmitted in the request body only use reversible encoding methods such as Base64 and Hex (hexadecimal), or employ encryption algorithms with insufficient strength (such as DES and RC4), rather than secure encryption methods that meet security standards (such as AES and RSA). Attackers can easily decode or crack this content, leading to sensitive information leaks.
Event type
Event description
API returns abnormal error messages.
The interface returns unhandled error messages, such as stack traces and framework default errors. This information may expose code logic, dependency library versions, or server configurations, helping attackers precisely locate vulnerabilities.
API returns server sensitive information
The API returns server sensitive data, such as server paths, key files, and cloud service AK/SK. This data may be used for lateral movement, privilege escalation, or direct intrusion into the production environment. Immediately block and fix the source of the leak.
API returns database error messages.
The API returns database-related error messages. This may expose table structures, SQL statements, or database types, which attackers can leverage to construct SQL injection or targeted attacks.
Abnormal API response status
The API continuously returns abnormal server response statuses. This behavior may indicate malicious stress testing, resource exhaustion attacks, or origin server failures. Investigate whether it involves DDoS or application-layer vulnerability exploitation.

Prerequisites

1. You have purchased a WAF yearly/monthly subscription instance and enabled API security.
3. You have enabled the API security switch for the corresponding domain on the Domain Onboarding page. After it is enabled, the analysis is expected to be completed within 30 minutes, after which relevant statistical data will be displayed.


Event List

1. Log in to the WAF console, and choose API Security > Risk Event in the left sidebar.
2. Click the domain drop-down list in the upper-left corner of the Risk Event page and select the domain you want to view. Alternatively, you can select All Domains.
3. In the Event Statistics area of the Risk Event page, the Security events, Detected today, Detected, Handle, In progress, Ignored and Disabled events are displayed. Each metric shows its current value and the change compared to the previous day.

Field Name
Description
Security events
Total number of risk events under the current domain.
Detected today
Total number of newly added risk events under the current domain today.
Detected
Total number of risk events in the newly discovered state under the current domain.
Handle
Total number of risk events in the resolved state under the current domain.
In progress
Total number of risk events in the in-process state under the current domain.
Ignored
Total number of risk events in the ignored state under the current domain.
Disabled
Total number of risk events in the closed state under the current domain.
4. On the Risk Event page, you can search for risk event data within a specified time range. The time range supports selection of Today, Yesterday, Last week, or a custom date range.
5. On the Risk Event page, the left side displays an event classification tree, which shows all risk events categorized by event type.
The event classification tree contains all event types, including major exception categories such as Service Exception, Web Attack, Permission Exception, Account Exception, Resource Abuse, Sensitive Information Exception and Response Exception, along with their specific subcategories.
The number of events under each category is indicated by the numbers in the event classification tree.
Click a node in the event classification tree, and the corresponding risk events are displayed in the list on the right.
6. In the Event List area, you can view the data list, search, export a custom list, perform batch operations, change statuses, and view details.
Event Data List: You can view the list of risk events for the current domain within the selected time range.
Field Name
Description
Event ID
Risk event name.
Event Type
Risk event type.
Event Level
Risk level of the risk event.
Related Domain
Domain to which the risk event belongs.
Related API
Name of the API associated with the risk event.
Status
Current status of the risk event.
Newly Discovered: Risk events that are newly discovered and not yet confirmed.
In Progress: Risk events that are being confirmed and for which relevant rules are being configured. This status provides handling suggestions (such as CC/Access Control/BOT) for the event type, allowing you to add the corresponding rules with one click.
Confirmed: Risk events for which the risk has been confirmed and handling rules have been added.
Ignored: The risk event has been confirmed as not requiring handling and has been ignored.
Closed: The event has been closed after the access and attack traffic are observed and it is confirmed that the event can be completely closed.
Detection Time
The earliest time when the risk event was detected.
Last Update
The latest time when the risk event was updated.
Operation
Handle event and View details.
Search Events: You can search by API name and domain name.
Custom List Export: Click

, select the required fields, and then click Export to download the data list.
Batch Operations: You can select events in batches and perform batch ignore and batch delete operations.
Add Rule: Choose Handle event > Add now. The system provides corresponding handling suggestions based on the event type. You can click Add now to add the corresponding handling rule. For details about the operation parameters of handling rules, see Custom Policy.
Change Status: Choose Handle event > Event status change, select the status you want to change, and then click Submit to change the status of the current risk event.
View Details: Click View details to view the details of the current risk event.
Field Name
Description
Basic information
Includes Event ID, Event type, Occurred, Update time, Related API, Associated domain, and Event details.
Suggestion Rule
Provides corresponding event handling recommendations based on the event type. You can click Add now to add the corresponding handling rule.
Rule added
Status of Added Rules.
Attacker details
Event Attack Source Details.
Change history
Event Status Change History.

Event alarm

1. Log in to the WAF console, and choose System Management in the left sidebar.
2. On the System Settings page, you can change the event alarm switch by enabling Event alarm or clicking Settings.
Alarm Switch: Click

to enable the switch. The switch is enabled by default. After it is enabled, newly discovered risk events in the Event Management feature are summarized daily/hourly, and notifications are pushed via channels such as in-site messages. Notifications are not repeatedly sent for known risk events.
Settings: Custom alarm types and frequencies are supported.
Alarm Types: You can select BOT events and API risk events for alarms by selecting events of different risk levels. It is recommended to select all.
Alarm Frequency: You can choose to summarize alarms daily or hourly. By default, alarms are triggered at 10:00 AM daily.
Daily Summary: You can set the notification time for daily alarms. All new event alarms are summarized only once at the specified time each day.
Hourly Summary: You can set the time range for notifications. Alarms are pushed once at the top of every hour within the specified time range. No notifications are sent outside the set time points or range.
Receiving channels and recipient settings: To modify message Recipient or Message Type, please go to Recipient Management to configure.

Bantuan dan Dukungan

Apakah halaman ini membantu?

masukan