tencent cloud

Web Application Firewall

Security Event Detection Rule

Download
フォーカスモード
フォントサイズ
最終更新日: 2026-08-03 15:53:20
AI翻訳
After you enable the security event detection rule, the system continuously monitors access behavior to API assets. It identifies abnormal activities such as unauthorized access, privilege escalation, credential stuffing, high-frequency calls, sensitive data leakage, and Web attacks, and generates corresponding API risk events.

Enabling System-Built-in Rules

On the API Security > Rule Configuration > Security Event Detection Rule page, after you enable the security event detection rule, the system enables the built-in rules by default to detect whether there are corresponding security event alarms for API assets. The built-in rules can be enabled or disabled, but they cannot be edited or deleted. By default, the system can detect 32 common API security events, which fall into the following 6 categories:
Risk Category
Typical Event
Permission Anomalies
Unauthorized access, privilege escalation, and similar actions
Account Anomalies
Account brute-force attacks, abnormal logins, and similar events
Resource Abuse
High-frequency calls, API stress testing, and similar activities
Business Issues
Parameter exceptions, business logic bypasses, and similar issues
Sensitive Data Anomalies
Sensitive data leakage, batch data export, and similar incidents
Web Attacks
SQL injection, XSS, command injection, and similar attacks

Adding a Custom Rule

After you enable the security event detection rule, you can customize security event detection rules based on your business scenarios to detect whether there are corresponding security event alarms for API assets.
Note:
A maximum of 20 custom security event detection rules can be manually added to a single domain.
2. On the Add Rule page, configure the relevant parameters and click Save to create the corresponding detection rule.
3. After you add a rule, you can edit or delete the corresponding rule.
Configuration Item Description
Event Name: Supports custom input, must be unique, and cannot exceed 10 characters.
Event Details: Event details are displayed in the event generated after a match, which helps distinguish the purpose and impact of the event.
Detection Objects
Custom: When you select manual entry, you can configure the detection path scope. After configuration, all API assets under the specified path are detected. The detection scope can be matched using four logical operators: belongs to, contains, prefix match, and suffix match.
Select assets from existing API assets: Select discovered API assets from the asset list in the shuttle box. The feature supports sorting by the number of calls in the last 30 days and filtering by data Tags.
All APIs under the current domain name: When you select a domain, you do not need to select an API name below. All API assets under that domain are detected.
Condition: You must add at least one condition and can add up to five.
Field
Parameter Description
Operator
Matching Content Description
Request method
-
Belong to
Not belong to
Select or enter the custom content.
Header parameter name
-
Exist
Do not exist
Belong to
Not belong to
Start with
End with
20 values (one per line).
Header parameter value
Enter parameter name.
Include
Do not include
Belong to
Not belong to
Start with
End with
20 values (one per line).
Length longer than
Length equal to
Length shorter than
Enter an integer from 0 to 1,000.
GET parameter name
-
Exist
Do not exist
Belong to
Not belong to
Start with
End with
20 values (one per line).
GET parameter value
Enter parameter name.
Include
Not included
Belong to
Not belong to
Start with
End with
20 values (one per line).
Length longer than
Length equal to
Length shorter than
Enter an integer from 0 to 1,000.
POST parameter name
-
Exist
Do not exist
Belong to
Not belong to
Start with
End with
20 values (one per line).
POST parameter value
Enter parameter name.
Include
Not included
Belong to
Not belong to
Start with
End with
20 values (one per line).
Length longer than
Length equal to
Length shorter than
Enter an integer from 0 to 1,000.
Cookie parameter name
-
Exist
Do not exist
Belong to
Not belong to
Start with
End with
20 values (one per line).
Cookie parameter value
Enter parameter name.
Include
Not included
Belong to
Not belong to
Start with
End with
20 values (one per line).
Length longer than
Length equal to
Length shorter than
Enter an integer from 0 to 1,000.
Response parameter name
-
Exist
Do not exist
Belong to
Not belong to
Start with
End with
20 values (one per line).
Response parameter value
Enter parameter name.
Include
Not included
Belong to
Not belong to
Start with
End with
20 values (one per line).
Length longer than
Length equal to
Length shorter than
Enter an integer from 0 to 1,000.
User-Agent
-
Include
Not included
Belong to
Not belong to
20 values (one per line).
Response status code
-
Belong to
Not belong to
Select or enter content (such as 403), up to 5 entries.
Use case
-
Belong to
Not belong to
Select the feature scene tag.
Authentication attribute
-
Is
Yes/No
Data type of sensitive requests
-
Belong to
Not belong to
Select the sensitive data type.
Data type of sensitive responses
-
Belong to
Not belong to
Select the sensitive data type.
Data Statistics: Optional. By default, no conditions are selected. You can select up to five statistical fields.
Field
Parameter
Operator
Matching Content Description
Response status code
Please select an item or enter content.
Greater than
Enter an integer between 0-100000.
Header value
Enter the parameter name.
>
<
Enter an integer from 0 to 1,000.
GET parameter value
Enter the parameter name.
>
<
Enter an integer from 0 to 1,000.
POST parameter value
Enter the parameter name.
>
<
Enter an integer from 0 to 1,000.
Cookie parameter value
Enter the parameter name.
>
<
Enter an integer from 0 to 1,000.
Data type of sensitive requests
-
>
Enter an integer from 0 to 100.
Data type of sensitive responses
-
>
Enter an integer from 0 to 100.
Request sensitive data volume
-
>
Enter an integer between 0-100000.
Sensitive data response volume
-
>
<
Greater than after deduplication
Less than after deduplication
Enter an integer between 0-100000.
Requests
-
>
<
Enter an integer between 0-100000.
Number of response(s)
-
>
<
Enter an integer between 0-100000.
Statistics Frequency: Supports input of 1-100,000 times and 1-20 minutes.
Risk Level: Supports selection of ultra-high-risk, high-risk, medium-risk, and low-risk to indicate the risk level of corresponding security events.
On/Off: Controls whether to enable or disable this rule. The default setting is On.


ヘルプとサポート

この記事はお役に立ちましたか?

フィードバック