tencent cloud

Web Application Firewall

Asset Management

Download
フォーカスモード
フォントサイズ
最終更新日: 2026-08-03 16:49:34
AI翻訳

Feature Introduction

The Asset Management feature analyzes API asset status, API activity level, API sensitivity involvement, and API asset disposal, presenting the current status of API assets across various dimensions.

Prerequisites

1. You have purchased a WAF yearly/monthly subscription instance and enabled API security.
3. You have enabled the API security switch for the corresponding domain on the Domain Onboarding page. After it is enabled, the analysis is expected to be completed within 30 minutes, after which relevant statistical data will be displayed.


Asset List

1. Log in to the WAF console. In the left sidebar, choose API Security > Asset Management.
2. The following quick action buttons are provided in the upper-right corner of the Asset Management page. After you click a button, you can follow the on-page instructions to proceed.
Usage scenes: View the tutorial on using the API Security feature.
Connect More Traffic Logs: Configure the ingestion of more traffic logs.
API Configuration Definition: Import an API document (Swagger 2.0 file) for parsing.
3. Click the domain drop-down list in the upper-left corner of the Asset Management page and select the domain you want to view. Alternatively, you can select All Domains.
4. Five metric cards are displayed at the top of the Asset Management page. Each metric shows its current value and the change compared to the previous day.
Metric Value
Description
Total APIs
Total APIs under the current domain.
Discovered APIs
Number of APIs with the asset status of newly discovered under the current domain. Click to filter APIs with the asset status of Detected.
Active APIs
Number of API assets accessed in the past 7 days under the current domain. Click to filter APIs with the activity status of Active.
Inactive APIs
Number of API assets not accessed in the past 7 days under the current domain. Click to filter APIs with the activity status of Deactivate.
Scenes
Total number of scenarios associated with API assets under the current domain.
5. The Asset Management page supports multiple filtering and search methods:
Time Range: Filters API data whose last update time falls within the query time range.
Refresh: Manually refresh the data.
View Only sensitive APIs: When it is selected, only sensitive APIs are displayed.
View Authentication-Free APIs Only: When it is selected, only APIs without authentication are displayed.
Search: Search by keywords such as API name, related domain, and asset status.
6. In the asset list area, it mainly includes features such as API asset data list, API asset status change, API asset detail display, API asset reinforcement, API asset search, and API asset download.
API Asset Data List: allows you to view the list of API assets identified within the selected domain and time range.
Field Name
Description
API
API request method and API name.
Risk level
Risk Level, which is determined based on sensitivity involvement and asset risk events.
Related domain
Domain.
Associated CLB Instance ID
The CLB instance ID to which the API belongs.
Calls in 30 days
The API's invocation volume in the last 30 days since its discovery is updated every 30 minutes.
Use case
The Tag for the feature scenario to which the API belongs, including built-in and custom scenarios.
Tag
The Tag for sensitive-involved data of the API, including built-in rules and custom rules.
Active
Whether the API has been active in the last 7 days.
Whether to Authenticate
Whether the API has an authentication mechanism, including built-in rules and custom rules.
Asset status
The current asset status of the API.
Asset Status includes: Newly Discovered; Under Verification; Confirmed; Offlined; Marked as Ignored.
Remarks
The remarks of the API asset.
Last update
The last update time of the API asset information.
Detection time
The first update time of the API asset information.
Operation
Supports Status changed and Asset Reinforcement operations for assets.
Status changed: Click Status changed to process status changes for the current API asset.
Username: non-empty, populated by default with the current console account name.
Remarks: You can fill in the corresponding remarks information.
API Asset Hardening: Allows rapid Add input parameter detection rule and Add rate limiting rule for APIs to enhance protection effectiveness.
API Asset Search: You can search by keywords such as "API name, Related domain, Asset status" and other keywords.
API Asset Download: Click

, select the required fields, and click Export to download the data list.

Asset Details

1. Log in to the WAF console. In the left sidebar, click API Security > Asset Management.
2. On the Asset Management page, click API Name.
3. On the API details page, you can view the following details of the current API.
On the API details page, you can view the API details in the top section.
Scene: Click the

next to Scene to add feature scenario identification rules.
Scenario name: The scenario name, with a maximum length of 10 characters.
Condition: You must add at least one condition and can add up to five.
Field
Parameter
Operator
Content
API name
-

Supports selecting matching conditions Equal to One of Them (OR), Include any (AND), or Regex match (whether it matches a specific regular expression).
Enter multiple values separated by carriage return, up to 20 values.
GET parameter name
-
GET parameter value
Enter a parameter name. If it is empty, all parameters are selected.
POST parameter name
-
POST parameter value
Enter a parameter name. If it is empty, all parameters are selected.
Cookie parameter name
-
Cookie parameter value
Enter a parameter name. If it is empty, all parameters are selected.
Header parameter name
-
Header parameter value
Enter a parameter name. If it is empty, all parameters are selected.
Response parameter name
-
Response parameter value
Enter a parameter name. If it is empty, all parameters are selected.
On/Off: supports enabling or disabling this rule.
Status changed: Click Status changed to process status changes for the current API asset.
Username: non-empty, populated by default with the current console account name.
Remarks: You can fill in the corresponding remarks information.
Click API status to view the API access trends, access source distribution, and access request characteristics over the last 7 days.
Click API attacks to view the API attack trends over the last 7 days, TOP statistics of abnormal access requests over the last 7 days, and so on. Among them, BOT attacks, Web attacks, CC attacks, and custom policy attacks respectively display the quantity and trends of corresponding risk types in the attack logs for this API.
Click Parameter example to view request and response information for the current or other samples, supporting filtering to display only sensitive parameters or generalized parameters.
Save Sample: Click Save Sample, enter the sample name, and click OK to save the current parameter sample. After saving, you can view details of saved parameter samples via the drop-down menu in the upper-left corner. The system supports saving up to three parameter samples. If you enter an existing sample name, clicking OK will directly overwrite the previously saved sample with the same name.
Click

to switch between JSON view and parameter view for request and response information.
Click Parameter list to view parameter names, types, locations, sensitivity status, and remarks in requests and responses, and to generalize parameters or edit parameter tags.
Whether to authenticate: After

is clicked, supports adding authentication credential identification rules to set specified fields as authentication parameters for this API asset.
Parameter general: After generalization is selected, the parameter value in the corresponding API asset parameter sample will display generalized data.
Edit Parameters: After clicking Edit, you can modify the parameter type, whether the parameter is generalized, parameter data tags, remarks, and so on.
Click Associated event to view risk events related to this API and handle them.
Click Change history to view the change timestamp, operator, and details for this API, and trace the change history.

Issues and Handling Recommendations

When using the API Asset Management feature, if you encounter the following issues, see the corresponding troubleshooting recommendations for investigation and resolution:

Issue Description

Problem 1: Access requests have been initiated to an API, but the API is not displayed in the asset list.
Problem 2: An API is not displayed in the asset list.

Possible Causes

Insufficient access frequency: The number of API accesses has not reached the trigger threshold for system asset refresh.
Refresh cycle not reached: The current time has not met the system-default fixed 20-minute refresh cycle.
Access source restricted: The source IP address initiating the access is in the precise allowlist, IP address allowlist, or IP address blocklist, resulting in the request not being detected by the API security module.

Problem-solving Ideas

API Security provides multi-faceted and continuous API asset discovery capabilities. If an API is missing from the asset list, you can adjust the asset refresh policy, wait for the system to complete the refresh cycle, or optimize source IP address configuration to ensure API access requests are properly monitored and included in the asset list.

Handling Recommendation

If it is not displayed due to insufficient access frequency: Lower the trigger threshold for API asset refresh to increase detection sensitivity. For example, on the API Asset Management page, click API Interface Configuration Definition in the upper-right corner and adjust the asset refresh cycle to once every 20 minutes.
If it is not displayed due to the refresh cycle not being reached: Wait for the system to complete the fixed-cycle asset refresh. For example, if you have initiated an API access request but less than 20 minutes have passed, wait until 20 minutes after initiating the request to check the asset list and confirm whether the API is displayed.
If not displayed due to restricted access source IP address: Adjust the allowlist/blocklist configuration or change the source IP address and retry. For example, if the source IP address is in the IP address allowlist, requests will be bypassed by the API security module. The recommended solution is to remove the IP address from the allowlist, configure a precise allowlist instead, and deselect API Security in the allowlisting module.



ヘルプとサポート

この記事はお役に立ちましたか?

フィードバック