Feature Introduction
The Asset Management feature analyzes API asset status, API activity level, API sensitivity involvement, and API asset disposal, presenting the current status of API assets across various dimensions.
Prerequisites
3. You have enabled the API security switch for the corresponding domain on the Domain Onboarding page. After it is enabled, the analysis is expected to be completed within 30 minutes, after which relevant statistical data will be displayed. Asset List
1. Log in to the WAF console. In the left sidebar, choose API Security > Asset Management. 2. The following quick action buttons are provided in the upper-right corner of the Asset Management page. After you click a button, you can follow the on-page instructions to proceed.
Usage scenes: View the tutorial on using the API Security feature.
Connect More Traffic Logs: Configure the ingestion of more traffic logs.
API Configuration Definition: Import an API document (Swagger 2.0 file) for parsing.
3. Click the domain drop-down list in the upper-left corner of the Asset Management page and select the domain you want to view. Alternatively, you can select All Domains.
4. Five metric cards are displayed at the top of the Asset Management page. Each metric shows its current value and the change compared to the previous day.
|
Total APIs | Total APIs under the current domain. |
Discovered APIs | Number of APIs with the asset status of newly discovered under the current domain. Click to filter APIs with the asset status of Detected. |
Active APIs | Number of API assets accessed in the past 7 days under the current domain. Click to filter APIs with the activity status of Active. |
Inactive APIs | Number of API assets not accessed in the past 7 days under the current domain. Click to filter APIs with the activity status of Deactivate. |
Scenes | Total number of scenarios associated with API assets under the current domain. |
5. The Asset Management page supports multiple filtering and search methods:
Time Range: Filters API data whose last update time falls within the query time range.
Refresh: Manually refresh the data.
View Only sensitive APIs: When it is selected, only sensitive APIs are displayed.
View Authentication-Free APIs Only: When it is selected, only APIs without authentication are displayed.
Search: Search by keywords such as API name, related domain, and asset status.
6. In the asset list area, it mainly includes features such as API asset data list, API asset status change, API asset detail display, API asset reinforcement, API asset search, and API asset download.
API Asset Data List: allows you to view the list of API assets identified within the selected domain and time range.
|
API | API request method and API name. |
Risk level | Risk Level, which is determined based on sensitivity involvement and asset risk events. |
Related domain | Domain. |
Associated CLB Instance ID | The CLB instance ID to which the API belongs. |
Calls in 30 days | The API's invocation volume in the last 30 days since its discovery is updated every 30 minutes. |
Use case | The Tag for the feature scenario to which the API belongs, including built-in and custom scenarios. |
Tag | The Tag for sensitive-involved data of the API, including built-in rules and custom rules. |
Active | Whether the API has been active in the last 7 days. |
Whether to Authenticate | Whether the API has an authentication mechanism, including built-in rules and custom rules. |
Asset status | The current asset status of the API. Asset Status includes: Newly Discovered; Under Verification; Confirmed; Offlined; Marked as Ignored. |
Remarks | The remarks of the API asset. |
Last update | The last update time of the API asset information. |
Detection time | The first update time of the API asset information. |
Operation | Supports Status changed and Asset Reinforcement operations for assets. |
Status changed: Click Status changed to process status changes for the current API asset.
Username: non-empty, populated by default with the current console account name.
Remarks: You can fill in the corresponding remarks information.
API Asset Hardening: Allows rapid Add input parameter detection rule and Add rate limiting rule for APIs to enhance protection effectiveness.
API Asset Search: You can search by keywords such as "API name, Related domain, Asset status" and other keywords.
API Asset Download: Click , select the required fields, and click Export to download the data list. Asset Details
1. Log in to the WAF console. In the left sidebar, click API Security > Asset Management. 2. On the Asset Management page, click API Name.
3. On the API details page, you can view the following details of the current API.
On the API details page, you can view the API details in the top section.
Scene: Click the next to Scene to add feature scenario identification rules. Scenario name: The scenario name, with a maximum length of 10 characters.
Condition: You must add at least one condition and can add up to five.
|
API name | - |
Supports selecting matching conditions Equal to One of Them (OR), Include any (AND), or Regex match (whether it matches a specific regular expression). | Enter multiple values separated by carriage return, up to 20 values. |
GET parameter name | - |
|
|
GET parameter value | Enter a parameter name. If it is empty, all parameters are selected. |
|
|
POST parameter name | - |
|
|
POST parameter value | Enter a parameter name. If it is empty, all parameters are selected. |
|
|
Cookie parameter name | - |
|
|
Cookie parameter value | Enter a parameter name. If it is empty, all parameters are selected. |
|
|
Header parameter name | - |
|
|
Header parameter value | Enter a parameter name. If it is empty, all parameters are selected. |
|
|
Response parameter name | - |
|
|
Response parameter value | Enter a parameter name. If it is empty, all parameters are selected. |
|
|
On/Off: supports enabling or disabling this rule.
Status changed: Click Status changed to process status changes for the current API asset.
Username: non-empty, populated by default with the current console account name.
Remarks: You can fill in the corresponding remarks information.
Click API status to view the API access trends, access source distribution, and access request characteristics over the last 7 days.
Click API attacks to view the API attack trends over the last 7 days, TOP statistics of abnormal access requests over the last 7 days, and so on. Among them, BOT attacks, Web attacks, CC attacks, and custom policy attacks respectively display the quantity and trends of corresponding risk types in the attack logs for this API.
Click Parameter example to view request and response information for the current or other samples, supporting filtering to display only sensitive parameters or generalized parameters.
Save Sample: Click Save Sample, enter the sample name, and click OK to save the current parameter sample. After saving, you can view details of saved parameter samples via the drop-down menu in the upper-left corner. The system supports saving up to three parameter samples. If you enter an existing sample name, clicking OK will directly overwrite the previously saved sample with the same name.
Click to switch between JSON view and parameter view for request and response information. Click Parameter list to view parameter names, types, locations, sensitivity status, and remarks in requests and responses, and to generalize parameters or edit parameter tags.
Whether to authenticate: After is clicked, supports adding authentication credential identification rules to set specified fields as authentication parameters for this API asset. Parameter general: After generalization is selected, the parameter value in the corresponding API asset parameter sample will display generalized data.
Edit Parameters: After clicking Edit, you can modify the parameter type, whether the parameter is generalized, parameter data tags, remarks, and so on.
Click Associated event to view risk events related to this API and handle them.
Click Change history to view the change timestamp, operator, and details for this API, and trace the change history.
Issues and Handling Recommendations
When using the API Asset Management feature, if you encounter the following issues, see the corresponding troubleshooting recommendations for investigation and resolution:
Issue Description
Problem 1: Access requests have been initiated to an API, but the API is not displayed in the asset list.
Problem 2: An API is not displayed in the asset list.
Possible Causes
Insufficient access frequency: The number of API accesses has not reached the trigger threshold for system asset refresh.
Refresh cycle not reached: The current time has not met the system-default fixed 20-minute refresh cycle.
Access source restricted: The source IP address initiating the access is in the precise allowlist, IP address allowlist, or IP address blocklist, resulting in the request not being detected by the API security module.
Problem-solving Ideas
API Security provides multi-faceted and continuous API asset discovery capabilities. If an API is missing from the asset list, you can adjust the asset refresh policy, wait for the system to complete the refresh cycle, or optimize source IP address configuration to ensure API access requests are properly monitored and included in the asset list.
Handling Recommendation
If it is not displayed due to insufficient access frequency: Lower the trigger threshold for API asset refresh to increase detection sensitivity. For example, on the API Asset Management page, click API Interface Configuration Definition in the upper-right corner and adjust the asset refresh cycle to once every 20 minutes. If it is not displayed due to the refresh cycle not being reached: Wait for the system to complete the fixed-cycle asset refresh. For example, if you have initiated an API access request but less than 20 minutes have passed, wait until 20 minutes after initiating the request to check the asset list and confirm whether the API is displayed.
If not displayed due to restricted access source IP address: Adjust the allowlist/blocklist configuration or change the source IP address and retry. For example, if the source IP address is in the IP address allowlist, requests will be bypassed by the API security module. The recommended solution is to remove the IP address from the allowlist, configure a precise allowlist instead, and deselect API Security in the allowlisting module.