ãã®ããŒãžã§ã¯ãGoogle Cloud Armor ã®ã»ãã¥ãªã㣠ããªã·ãŒã®äžè¬çãªãŠãŒã¹ã±ãŒã¹ã«ã€ããŠèª¬æããŸããCloud Armor ã»ãã¥ãªã㣠ããªã·ãŒã§ã¯ãIP ã¢ãã¬ã¹ã®èš±å¯ãªã¹ã / æåŠãªã¹ãã®ãããªæ©èœãäžè¬çãªãŠã§ãæ»æã黿¢ããäºåæ§æã«ãŒã«ã䜿çšããŠãã¢ããªã±ãŒã·ã§ã³ãä¿è·ã§ããŸãã
ãŠã§ã ã¢ããªã±ãŒã·ã§ã³ãšãµãŒãã¹ãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ãã
ãã®ã»ã¯ã·ã§ã³ã§ã¯ãCloud Armor ã»ãã¥ãªã㣠ããªã·ãŒã䜿çšããŠã¢ããªã±ãŒã·ã§ã³ããµãŒãã¹ãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããæ¹æ³ã«ã€ããŠèª¬æããŸãã
èš±å¯ãªã¹ãã䜿çšããŠç¹å®ã® IP ã¢ãã¬ã¹ã§ã®ãŠãŒã¶ãŒã®ã¢ã¯ã»ã¹ãæå¹ã«ãã
ãŠãŒã¶ãŒ IP ã¢ãã¬ã¹ãèš±å¯ãªã¹ãã«èšå®ããäžè¬çãªãŠãŒã¹ã±ãŒã¹ã¯ãã°ããŒãã«å€éšã¢ããªã±ãŒã·ã§ã³ ããŒããã©ã³ãµãŸãã¯åŸæ¥ã®ã¢ããªã±ãŒã·ã§ã³ ããŒããã©ã³ãµã«ç¹å®ã®ãŠãŒã¶ãŒã»ããã®ã¿ãã¢ã¯ã»ã¹ããå Žåã§ããæ¬¡ã®äŸã§ã¯ãçµç¹ã®ãŠãŒã¶ãŒã ãã«ãããŒããã©ã³ãµã®èåŸã®ãµãŒãã¹ãžã®ã¢ã¯ã»ã¹ãèš±å¯ãããŠããŸãããããã®ãŠãŒã¶ãŒã«ã¯ãçµç¹ããå²ãåœãŠããã IP ã¢ãã¬ã¹ãŸãã¯ã¢ãã¬ã¹ ãããã¯ããããŸãããããã® IP ã¢ãã¬ã¹ãŸã㯠CIDR ç¯å²ãèš±å¯ãªã¹ãã«è¿œå ãããšããããã®ãŠãŒã¶ãŒã®ã¿ãããŒããã©ã³ãµã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸãã
ã°ããŒãã«å€éšã¢ããªã±ãŒã·ã§ã³ ããŒããã©ã³ãµãŸãã¯åŸæ¥ã®ã¢ããªã±ãŒã·ã§ã³ ããŒããã©ã³ãµãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããã«ã¯ãããŒããã©ã³ãµãžã®ã¢ã¯ã»ã¹ãèš±å¯ããéä¿¡å IP ã¢ãã¬ã¹ãŸãã¯éä¿¡å CIDR ç¯å²ãå«ãèš±å¯ãªã¹ããæ§æããŸããæ¬¡ã®ã»ã¯ã·ã§ã³ã§ã¯ããã®æ§æã«ã€ããŠè©³çްã«èª¬æããŸãã
ãã®æ§æã§ã¯ãIP ç¯å²ã® IP ã¢ãã¬ã¹ã䜿çšããçµç¹å ã®ãŠãŒã¶ãŒã«ã®ã¿ãã°ããŒãã«å€éšã¢ããªã±ãŒã·ã§ã³ ããŒããã©ã³ãµãŸãã¯åŸæ¥ã®ã¢ããªã±ãŒã·ã§ã³ ããŒããã©ã³ãµãžã®ã¢ã¯ã»ã¹ãèš±å¯ããŸããä»ã®ãã©ãã£ãã¯ã¯ãã¹ãŠæåŠããŸãã
ãã®æ§æã¯æ¬¡ã®æé ã«æ²¿ã£ãŠäœæããŸãã
- Cloud Armor ã»ãã¥ãªã㣠ããªã·ãŒãäœæããŸãã
- ã»ãã¥ãªã㣠ããªã·ãŒå
ã®æåã®ã«ãŒã«ãšããŠãèš±å¯ãªã¹ãã«ç¯å²ã远å ããã«ãŒã«ã远å ããŸãããã®ã«ãŒã«ã®èª¬æã¯
allow [RANGE]
ãšããŸããããã§ã[RANGE]
ã¯ã察象㮠IP ç¯å²ãèšè¿°ããŸãã - ããªã·ãŒã®ããã©ã«ã ã«ãŒã«ã allow ã«ãŒã«ãã deny ã«ãŒã«ã«å€æŽããŸããããã©ã«ã ã«ãŒã«ã¯ãããã«å
ç«ã€ã«ãŒã«ã«äžèŽããªããã©ãã£ãã¯ã«é©çšãããŸããããã©ã«ã ã«ãŒã«ã¯ããªã·ãŒå
ã®æçµã«ãŒã«ã§ããã«ãŒã«ã
allow
ããdeny
ã«å€æŽãããšãèš±å¯ãªã¹ãã®ç¯å²å€ã®ãã©ãã£ãã¯ã¯ãã¹ãŠãããã¯ãããŸãã - ãã®ããªã·ãŒãã°ããŒãã«å€éšã¢ããªã±ãŒã·ã§ã³ ããŒããã©ã³ãµãŸãã¯åŸæ¥ã®ã¢ããªã±ãŒã·ã§ã³ ããŒããã©ã³ãµã®ããã¯ãšã³ã ãµãŒãã¹ã«é¢é£ä»ããŸãã
çµç¹ã§ãµãŒãããŒãã£ã®ã»ãã¥ãªã㣠ãããã€ãã䜿çšããŠãã©ãã£ãã¯ãã¹ã¯ã©ãããŠããå Žåã¯ãã»ãã¥ãªã㣠ãããã€ãã® IP ã¢ãã¬ã¹ãèš±å¯ãªã¹ãã«è¿œå ããŠãã¹ã¯ã©ãããããã©ãã£ãã¯ã ããã°ããŒãã«å€éšã¢ããªã±ãŒã·ã§ã³ ããŒããã©ã³ãµãŸãã¯åŸæ¥ã®ã¢ããªã±ãŒã·ã§ã³ ããŒããã©ã³ãµãšããã¯ãšã³ãã«ã¢ã¯ã»ã¹ããããã«ã§ããŸãã
次ã®å³ã§ã¯ããµãŒãããŒã㣠ãããã€ãã CIDR ç¯å² 192.0.2.0/24 ã§èå¥ãããŠããããã®ç¯å²ãèš±å¯ãªã¹ãã«å«ãŸããŠããŸãã
æåŠãªã¹ãã䜿çšããŠç¹å®ã® IP ã¢ãã¬ã¹ã®ãŠãŒã¶ãŒã«ããã¢ã¯ã»ã¹ããããã¯ãã
æåŠãªã¹ãã䜿çšããŠãããç¹å®ã® IP ã¢ãã¬ã¹ãŸã㯠CIDR ç¯å²ããã®ãã©ãã£ãã¯ãæåŠãã Cloud Armor ã»ãã¥ãªã㣠ããªã·ãŒãäœæããŸããæ¬¡ã®å³ã§ã¯ãæªæã®ãããŠãŒã¶ãŒãèå¥ããã IP ã¢ãã¬ã¹ 198.51.100.1 ããã®ãã©ãã£ãã¯ããããã¯ãã deny
ã«ãŒã«ã Cloud Armor ã»ãã¥ãªã㣠ããªã·ãŒã«èšå®ãããŠããŸãã
ã¬ã€ã€ 3 ããã¬ã€ã€ 7 ã®ãã©ã¡ãŒã¿ã«åºã¥ããŠãã£ã«ã¿ãªã³ã°ããã«ã¹ã¿ã ã«ãŒã«
Cloud Armor ã«ã¹ã¿ã ã«ãŒã«èšèªã䜿çšããŠãã«ãŒã«ã®äžèŽæ¡ä»¶ã§ 1 ã€ä»¥äžã®åŒãå®çŸ©ããŸããCloud Armor ã¯ãªã¯ãšã¹ããåä¿¡ãããšããããã®åŒã«å¯ŸããŠãªã¯ãšã¹ããè©äŸ¡ããŸããäžèŽãããå Žåãã«ãŒã«ã®ã¢ã¯ã·ã§ã³ãæå¹ã«ãªããåä¿¡ãã©ãã£ãã¯ãæåŠãŸãã¯èš±å¯ãããŸãã
Cloud Armor ã® Common Expression LanguageïŒCELïŒæ¡åŒµæ©èœã§èšè¿°ãããåŒã®äŸã以äžã«ç€ºããŸãã詳现ã«ã€ããŠã¯ãã«ã¹ã¿ã ã«ãŒã«èšèªãªãã¡ã¬ã³ã¹ãã芧ãã ããã
ã«ãŒã«ã§åŒãå®çŸ©ããã«ã¯ãgcloud --expression
ãã©ã°ãŸãã¯Google Cloud ã³ã³ãœãŒã«ã䜿çšããŸãã詳现ã«ã€ããŠã¯ãCloud Armor ã®ã»ãã¥ãªã㣠ããªã·ãŒãã«ãŒã«ãåŒã®äœæãã芧ãã ããã
次ã®åŒã¯ãAU
ãªãŒãžã§ã³ã® 2001:db8::/32
ïŒã¢ã«ãã¡ ãã¹ã¿ãŒãªã©ïŒããã®ãªã¯ãšã¹ããšäžèŽããŸãã
origin.region_code == "AU" && inIpRange(origin.ip, '2001:db8::/32')
次ã®äŸã¯ããŠãŒã¶ãŒ ãšãŒãžã§ã³ãã«æåå WordPress
ãå«ãŸããŠãã 192.0.2.0/24
ããã®ãªã¯ãšã¹ãã«äžèŽããŸãã
inIpRange(origin.ip, '192.0.2.0/24') && has(request.headers['user-agent']) && request.headers['user-agent'].contains('WordPress')
ãã®ä»ã®äŸã«ã€ããŠã¯ãã«ãŒã«èšèªãªãã¡ã¬ã³ã¹ã®åŒã®äŸãã芧ãã ããã
ã¢ããªã±ãŒã·ã§ã³ ã¬ã€ã€ãžã®æ»æãããããã€ãä¿è·ããOWASP ããã 10 ãªã¹ã¯ã軜æžãã
Cloud Armor ã䜿çšãããšãSQL ã€ã³ãžã§ã¯ã·ã§ã³ïŒSQLiïŒãã¯ãã¹ãµã€ã ã¹ã¯ãªããã£ã³ã°ïŒXSSïŒãªã©ã®ã¢ããªã±ãŒã·ã§ã³ ã¬ã€ã€ïŒL7ïŒæ»æãã Cloud CDN ãªãªãžã³ ãµãŒããŒãä¿è·ã§ããŸãããã£ãã·ã¥å ã®ã³ã³ãã³ãã¯éçã§ããããããããŠã§ãããã®æšçåæ»æã®ãªã¹ã¯ãçºçããããšã¯ãããŸããããã ããåºã«ãªãã³ã³ãã³ãã®ãªãªãžã³ ãµãŒããŒã¯ããŠã§ãã¢ããªã®æ¢ç¥ã®è匱æ§ãŸãã¯æœåšçãªè匱æ§ãããåçã¢ããªã±ãŒã·ã§ã³ã§ããå¯èœæ§ããããŸããã»ãã¥ãªãã£ãŸãã¯ã³ã³ãã©ã€ã¢ã³ã¹ã®èŠä»¶ã«ããããããããªã¹ã¯ã軜æžããŠãã€ã³ã¿ãŒãããã®è匱æ§ãæªçšããŠãªãªãžã³ ãµãŒããŒãæ»æãããã®ãé²ãå¿ èŠããããŸãã
ãã®ãªã¹ã¯ãäœæžããæé ã¯æ¬¡ã®ãšããã§ãã
- CDN ãæå¹ã«ããŠããã¯ãšã³ã ãµãŒãã¹ãäœæãŸãã¯èå¥ããŸãã
- Cloud Armor ã»ãã¥ãªã㣠ããªã·ãŒãäœæããŸãã
- ã»ãã¥ãªã㣠ããªã·ãŒã«ãL7 æ»æãæåŠããã«ãŒã«ã 1 ã€ä»¥äžäœæããŸãã
- ã»ãã¥ãªã㣠ããªã·ãŒã®ã¿ãŒã²ããã®ããããããã¹ããã 1 ã§äœæãŸãã¯ç¹å®ããããã¯ãšã³ã ãµãŒãã¹ãšããŠæ§æããŸãã
äºåæ§æãããã«ãŒã«ã䜿çšããŠãäžè¬çãªã¢ããªã±ãŒã·ã§ã³ ã¬ã€ã€ã®æ»æãæ€åºããŠãããã¯ããããšãã§ããŸããäºåæ§ææžã¿ã®ã«ãŒã«ã¯ãCloud Armor ã»ãã¥ãªã㣠ããªã·ãŒã«è¿œå ã§ããäºåå®çŸ©ãããåŒã®ã»ããã§ãããããã®åŒã»ãããã«ãŒã«ã«è¿œå ããã«ã¯ãgcloud --expression
ãã©ã°ãŸã㯠Google Cloud ã³ã³ãœãŒã«ã䜿çšããŸãã詳现ã«ã€ããŠã¯ãã»ãã¥ãªã㣠ããªã·ãŒãã«ãŒã«ãåŒã®äœæãã芧ãã ããã
äºåæ§ææžã¿ã®ã«ãŒã«ã¯ãããã©ã«ãã§ãªã¯ãšã¹ãæ¬æã®æåã®æå€§ 8 KB ãæ€æ»ããŸãããã ããããªã·ãŒããšã«ãã®äžéãæ§æã§ããŸããäºåæ§ææžã¿ã® WAF ã«ãŒã«ã䜿çšããå Žåã«ãã®ãªã¯ãšã¹ãæ¬æã®æ€æ»äžéãæ§æããæ¹æ³ã®è©³çްã«ã€ããŠã¯ãPOST ããã³ PATCH æ¬æã®æ€æ»ã«ãããå¶éãã芧ãã ããã
äºåæ§ææžã¿ã«ãŒã«ã®è©³çްã«ã€ããŠã¯ãã«ã¹ã¿ã ã«ãŒã«èšèªãªãã¡ã¬ã³ã¹ã®äºåæ§ææžã¿ã«ãŒã«ãã芧ãã ããã
次ã®äŸã§ã¯ãäºåæ§ææžã¿ã®ã«ãŒã«ã䜿çšããŠãã¯ãã¹ãµã€ã ã¹ã¯ãªããã£ã³ã°ïŒXSSïŒæ»æã軜æžããŠããŸãã
evaluatePreconfiguredWaf('xss-stable')
次ã®äŸã§ã¯ãäºåæ§ææžã¿ã®ã«ãŒã«ã䜿çšããŠãSQL ã€ã³ãžã§ã¯ã·ã§ã³ïŒSQLiïŒæ»æã軜æžããŠããŸãã
evaluatePreconfiguredWaf('sqli-stable')
ãŸããäºåæ§ææžã¿ã®ã«ãŒã«ãä»ã®åŒãšçµã¿åãããããšãã§ããŸããæ¬¡ã®äŸã§ã¯ãäºåæ§ææžã¿ã®ã«ãŒã«ã䜿çšããŠã192.0.2.1/24
IP ã¢ãã¬ã¹ç¯å²ããã® SQLi æ»æã軜æžããŠããŸãã
inIpRange(origin.ip, '192.0.2.1/24') && evaluatePreconfiguredWaf('sqli-stable')
ãã€ããªãã ã¯ãŒã¯ããŒãã«ããã OWASP ããã 10 ãªã¹ã¯ã®ç·©åç
Cloud Armor ã«ã¯ããããã€å ã Google Cloudããªã³ãã¬ãã¹ããµãŒãããŒã㣠ãããã€ãã®ãããã§ããããåãããæ¬¡ã®æ»æã«å¯Ÿããç·©åçãçšæãããŠããŸãã
- SQL ã€ã³ãžã§ã¯ã·ã§ã³ïŒSQLiïŒ
- ã¯ãã¹ãµã€ã ã¹ã¯ãªããã£ã³ã°ïŒXSSïŒ
- ããŒã«ã« ãã¡ã€ã« ã€ã³ã¯ã«ãŒãïŒLFIïŒ
- ãªã¢ãŒã ãã¡ã€ã« ã€ã³ã¯ã«ãŒãïŒRFIïŒ
- ãªã¢ãŒãã³ãŒãå®è¡ïŒRCEïŒ
ãããã®æ©èœãå©çšããŠãOWASP ããã 10 ãªã¹ãã«èšèŒãããŠãããªã¹ã¯ãªã©ããŠã§ã ã¢ããªã±ãŒã·ã§ã³ã§äžè¬çãªã»ãã¥ãªã㣠ãªã¹ã¯ã«å¯ŸåŠã§ããŸãã
SQLi ã XSS ã®è©Šè¡ãå«ãæãŸãããªãã¬ã€ã€ 7 ãªã¯ãšã¹ããæ€åºããŠæåŠãããããCloud Armor ã®äºåæ§ææžã¿ WAF ã«ãŒã«ãã»ãã¥ãªã㣠ããªã·ãŒã«è¿œå ã§ããŸããCloud Armor ã¯æªæã®ãããªã¯ãšã¹ããæ€åºããGoogle ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ãšããžã§ããããããŸããããã¯ãšã³ã ãµãŒãã¹ããããã€ãããŠããå Žæã«é¢ä¿ãªãããããã®ãªã¯ãšã¹ãã¯ããã¯ãšã³ã ãµãŒãã¹ã«ãããã·ãããŸããã
Google Cloudã§ãã¹ããããŠããã¯ãŒã¯ããŒãã Google ãããã¯ãŒã¯ã®ãšããžã§äžèšã®æ»æããé²åŸ¡ããã«ã¯ãæ¬¡ã®æäœãè¡ããŸãã
- ã€ã³ã¿ãŒããã NEG ãããã¯ãšã³ããšããŠæã€ããã¯ãšã³ã ãµãŒãã¹ã䜿çšããŠãã°ããŒãã«å€éšã¢ããªã±ãŒã·ã§ã³ ããŒããã©ã³ãµãŸãã¯åŸæ¥ã®ã¢ããªã±ãŒã·ã§ã³ ããŒããã©ã³ãµãæ§æããŸãã
- Cloud Armor ã»ãã¥ãªã㣠ããªã·ãŒãäœæããŸãã
- äºåæ§æããã SQLi ã«ãŒã«ãš XSS ã«ãŒã«ãããªã·ãŒã«è¿œå ããŸãã
- æé 1 ã§äœæããããã¯ãšã³ã ãµãŒãã¹ã«ã»ãã¥ãªã㣠ããªã·ãŒãæ¥ç¶ããŸãã
- Cloud LoggingãCloud MonitoringãSecurity Command Center ã«éä¿¡ãããæ€åºçµæã䜿çšããŠãCloud Armor ã®ã¢ã¯ãã£ããã£ãã¢ãã¿ãªã³ã°ããŸãã
Cloud CDN å€éšãªãªãžã³ ãµãŒããŒã® DDoS é²åŸ¡ãšã¬ã€ã€ 7 ã¢ãã¿ãªã³ã°
å€éšã®ãªãªãžã³ ãµãŒããŒã䜿çšãã Cloud CDN ãããã€ã§ã¯ããããã·ã³ã°ããã£ãã·ã³ã°ãCloud Armor ã¬ã€ã€ 7 ãã£ã«ã¿ãªã³ã°ã®ããã³ããšã³ããšããŠãGoogle ã®ãšããž ã€ã³ãã©ã¹ãã©ã¯ãã£ã䜿çšã§ããŸããã€ã³ã¿ãŒããã NEG ã䜿çšãããšããªãªãžã³ ãµãŒããŒããªã³ãã¬ãã¹äžã«é 眮ã§ããŸãããŸããµãŒãããŒãã£ã®ã€ã³ãã©ã¹ãã©ã¯ã㣠ãããã€ããšãšãã«é 眮ããããšãã§ããŸãã
Cloud Armor ãš Google ã®ãã®ä»ã®ãšããž ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ãL3 / L4 æ»æãç·©åããã³é»æ¢ããçãããã¬ã€ã€ 7 ã¢ã¯ãã£ããã£ã«é¢ããã¢ã©ãŒããåºããã«ã¹ã¿ã ã«ãŒã«ã䜿çšããŠæãŸãããªãã¬ã€ã€ 7 ãªã¯ãšã¹ããæåŠã§ããããã«ããŸããCloud LoggingãCloud MonitoringãSecurity Command Center ã䜿çšãã Cloud Armor ã®ãã®ã³ã°ãšãã¬ã¡ããªãŒã«ããããããã€ãããŠããå Žæã«é¢ä¿ãªããä¿è·å¯Ÿè±¡ã®ã¢ããªã±ãŒã·ã§ã³ã«é¢ããå®çšçãªåææ å ±ãæäŸãããŸãã
CDN å€éšãªãªãžã³ ãµãŒããŒã«å¯Ÿã㊠Cloud Armor ä¿è·ãæå¹ã«ããæé ã¯æ¬¡ã®ãšããã§ãã
- ã€ã³ã¿ãŒããã NEG ãããã¯ãšã³ããšããŠæã€ããã¯ãšã³ã ãµãŒãã¹ã䜿çšããŠãã°ããŒãã«å€éšã¢ããªã±ãŒã·ã§ã³ ããŒããã©ã³ãµãŸãã¯åŸæ¥ã®ã¢ããªã±ãŒã·ã§ã³ ããŒããã©ã³ãµãæ§æããŸãã
- ãã®ããã¯ãšã³ã ãµãŒãã¹ã«å¯Ÿã㊠Cloud CDN ãæå¹ã«ããŸãã
- Cloud Armor ã»ãã¥ãªã㣠ããªã·ãŒãäœæããŸãã
- æé 1 ã§äœæããããã¯ãšã³ã ãµãŒãã¹ã«ã»ãã¥ãªã㣠ããªã·ãŒãæ¥ç¶ããŸãã
- Security Command CenterãCloud LoggingãCloud Monitoring ã§ãCloud Armor ã®ã¢ã©ãŒãããã®ã³ã°ããã¬ã¡ããªãŒã«ã¢ã¯ã»ã¹ããŸãã
ããã«ããšããž ã»ãã¥ãªã㣠ããªã·ãŒã䜿çšããŠããã£ãã·ã¥ã«ä¿åãããã³ã³ãã³ããä¿è·ããããšãã§ããŸãããšããž ã»ãã¥ãªã㣠ããªã·ãŒã®è©³çްã«ã€ããŠã¯ãã»ãã¥ãªã㣠ããªã·ãŒã®æŠèŠãã芧ãã ããã
ã¬ã€ã€ 7 ã¢ã¯ã»ã¹å¶åŸ¡ãšãã£ãã·ã¥ç¡å¹åæ»æ
ã¢ããªã±ãŒã·ã§ã³ ã¢ãŒããã¯ãã£ã«å¿ããŠããã£ãã·ã¥å¯èœãªã³ã³ãã³ããšãã£ãã·ã¥äžå¯èœãªã³ã³ãã³ããå«ãããŸããŸãª URL ã®ãªã¯ãšã¹ããåŠçããããã«åäžã®ããã¯ãšã³ã ãµãŒãã¹ãæ§æã§ããŸãããã®ãããªããã〠ã·ããªãªã§ã¯ãç¹å®ã®ãªã¯ãšã¹ããã¹ã§ã®æãŸãããªããã©ãã£ãã¯ã¯æåŠããªããããã¹ãŠã®ã¯ã©ã€ã¢ã³ããå¥ã®ãªã¯ãšã¹ããã¹ã®éçã³ã³ãã³ãã«ã¢ã¯ã»ã¹ã§ããããã«ãã Cloud Armor ã»ãã¥ãªã㣠ããªã·ãŒãäœæããŸãã
ä»ã®ç¶æ³ã§ã¯ãã³ã³ãã³ãããã£ãã·ã¥ã§å¹ççã«åŠçãããŠããå Žåã§ããæªæã®ããã¯ã©ã€ã¢ã³ããé害ã®ããã¯ã©ã€ã¢ã³ãã«ãã£ãŠå€§éã®ãªã¯ãšã¹ããçæãããŠãã£ãã·ã¥ãã¹ãçºçããåºã«ãªããªãªãžã³ ãµãŒããŒããªã¯ãšã¹ããããã³ã³ãã³ãããã§ãããŸãã¯çæããå¿ èŠãçããå ŽåããããŸããããããããšãèµ·ãããšéããããªãœãŒã¹ã«è² æ ããããããã¹ãŠã®ãŠãŒã¶ãŒã®ã¢ããªã±ãŒã·ã§ã³ã®å¯çšæ§ã«æªåœ±é¿ãåºãå¯èœæ§ããããŸããåé¡ãåŒãèµ·ãããŠããã¯ã©ã€ã¢ã³ãã®ã·ã°ããã£ãç §åãããã®ãããªãªã¯ãšã¹ãããªãªãžã³ ãµãŒããŒã«å°éããŠããã©ãŒãã³ã¹ã«åœ±é¿ãäžããåã«æåŠãã Cloud Armor ã»ãã¥ãªã㣠ããªã·ãŒãäœæã§ããŸãã
ãããè¡ãæé ã¯æ¬¡ã®ãšããã§ãã
- Cloud Armor ã»ãã¥ãªã㣠ããªã·ãŒãäœæããŸãã
ã«ãŒã«ãæ§æããŸããããšãã°ã次ã®ã«ãŒã«ã¯
"/admin"
ãžã®ã¢ã¯ã»ã¹ãæåŠããŸããrequest.path.contains("/admin") && !inIpRange(origin.ip, '<allowed_ip_range>')
æé 1 ã®ã»ãã¥ãªã㣠ããªã·ãŒããCloud CDN ãæå¹ã«ãªã£ãŠããããã¯ãšã³ã ãµãŒãã¹ã«æ¥ç¶ããŸãã
次ã®ã¹ããã
- ã»ãã¥ãªã㣠ããªã·ãŒãæ§æãã
- ã«ã¹ã¿ã ã«ãŒã«èšèªã«ã€ããŠåŠç¿ãã
- WAF ã«ãŒã«ã調æŽãã