Risk Category | Typical Event |
Permission Anomalies | Unauthorized access, privilege escalation, and similar actions |
Account Anomalies | Account brute-force attacks, abnormal logins, and similar events |
Resource Abuse | High-frequency calls, API stress testing, and similar activities |
Business Issues | Parameter exceptions, business logic bypasses, and similar issues |
Sensitive Data Anomalies | Sensitive data leakage, batch data export, and similar incidents |
Web Attacks | SQL injection, XSS, command injection, and similar attacks |
Field | Parameter Description | Operator | Matching Content Description |
Request method | - | Belong to Not belong to | Select or enter the custom content. |
Header parameter name | - | Exist Do not exist Belong to Not belong to Start with End with | 20 values (one per line). |
Header parameter value | Enter parameter name. | Include Do not include Belong to Not belong to Start with End with | 20 values (one per line). |
| | Length longer than Length equal to Length shorter than | Enter an integer from 0 to 1,000. |
GET parameter name | - | Exist Do not exist Belong to Not belong to Start with End with | 20 values (one per line). |
GET parameter value | Enter parameter name. | Include Not included Belong to Not belong to Start with End with | 20 values (one per line). |
| | Length longer than Length equal to Length shorter than | Enter an integer from 0 to 1,000. |
POST parameter name | - | Exist Do not exist Belong to Not belong to Start with End with | 20 values (one per line). |
POST parameter value | Enter parameter name. | Include Not included Belong to Not belong to Start with End with | 20 values (one per line). |
| | Length longer than Length equal to Length shorter than | Enter an integer from 0 to 1,000. |
Cookie parameter name | - | Exist Do not exist Belong to Not belong to Start with End with | 20 values (one per line). |
Cookie parameter value | Enter parameter name. | Include Not included Belong to Not belong to Start with End with | 20 values (one per line). |
| | Length longer than Length equal to Length shorter than | Enter an integer from 0 to 1,000. |
Response parameter name | - | Exist Do not exist Belong to Not belong to Start with End with | 20 values (one per line). |
Response parameter value | Enter parameter name. | Include Not included Belong to Not belong to Start with End with | 20 values (one per line). |
| | Length longer than Length equal to Length shorter than | Enter an integer from 0 to 1,000. |
User-Agent | - | Include Not included Belong to Not belong to | 20 values (one per line). |
Response status code | - | Belong to Not belong to | Select or enter content (such as 403), up to 5 entries. |
Use case | - | Belong to Not belong to | Select the feature scene tag. |
Authentication attribute | - | Is | Yes/No |
Data type of sensitive requests | - | Belong to Not belong to | Select the sensitive data type. |
Data type of sensitive responses | - | Belong to Not belong to | Select the sensitive data type. |
Field | Parameter | Operator | Matching Content Description |
Response status code | Please select an item or enter content. | Greater than | Enter an integer between 0-100000. |
Header value | Enter the parameter name. | > < | Enter an integer from 0 to 1,000. |
GET parameter value | Enter the parameter name. | > < | Enter an integer from 0 to 1,000. |
POST parameter value | Enter the parameter name. | > < | Enter an integer from 0 to 1,000. |
Cookie parameter value | Enter the parameter name. | > < | Enter an integer from 0 to 1,000. |
Data type of sensitive requests | - | > | Enter an integer from 0 to 100. |
Data type of sensitive responses | - | > | Enter an integer from 0 to 100. |
Request sensitive data volume | - | > | Enter an integer between 0-100000. |
Sensitive data response volume | - | > < Greater than after deduplication Less than after deduplication | Enter an integer between 0-100000. |
Requests | - | > < | Enter an integer between 0-100000. |
Number of response(s) | - | > < | Enter an integer between 0-100000. |
フィードバック