{"id":30131,"date":"2022-10-26T14:40:33","date_gmt":"2022-10-26T12:40:33","guid":{"rendered":"https:\/\/www.makingscience.com\/?p=30131"},"modified":"2022-10-26T14:40:33","modified_gmt":"2022-10-26T12:40:33","slug":"protect-your-websites-and-applications-with-google-cloud-armor-waf-2","status":"publish","type":"post","link":"https:\/\/www.makingscience.com\/en\/blog\/protect-your-websites-and-applications-with-google-cloud-armor-waf-2\/","title":{"rendered":"Protect your websites and applications with Google Cloud Armor WAF"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Web application security is crucial for protecting organisational and client data. In 2021, cyber \u200b\u200battacks caused approximately 5 trillion GBP in damage, which is expected to <strong>increase by 15%<\/strong> annually over the <strong>next five years<\/strong>. Thus, it is essential to use all possible tools to reduce the risk of these cyber attacks.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Google Cloud Armor is a web-application level \u201cfirewall\u201d (WAF) capable of protecting companies from a wide variety of cyberattacks simply and efficiently. To use this tool, we will have to use<strong> Google Cloud Platform\u2019s load balancers<\/strong> since that is where Cloud Armor can be enabled on the backend services.<\/span><\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"wp-image-30124 aligncenter\" src=\"https:\/\/www.makingscience.co.uk\/wp-content\/uploads\/2022\/09\/cloud-300x157.png\" alt=\"\" width=\"465\" height=\"243\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Once the load balancer has been configured, and a security policy has been activated for a backend service, it is time to adjust which WAF rules should be applied. There is a wide variety available depending on our needs. The following table shows a list of some of these preconfigured rules grouped by categories:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><b>Name of the rule\u00a0<\/b><\/td>\n<td><b>Name of the ModSecurity rule<\/b><\/td>\n<\/tr>\n<tr>\n<td>sqli-stable<\/td>\n<td>SQL injection<\/td>\n<\/tr>\n<tr>\n<td>xss-stable<\/td>\n<td>Cross-site scripting<\/td>\n<\/tr>\n<tr>\n<td>lfi-stable<\/td>\n<td>Local file inclusion<\/td>\n<\/tr>\n<tr>\n<td>rfi-stable<\/td>\n<td>Remote file inclusion<\/td>\n<\/tr>\n<tr>\n<td>rce-stable<\/td>\n<td>Remote code execution<\/td>\n<\/tr>\n<tr>\n<td>scannerdetection-stable<\/td>\n<td>Scanner detection<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">Each of these rules contains dozens of signatures compiled from <\/span><a href=\"https:\/\/github.com\/coreruleset\/coreruleset\/tree\/v3.0\/master\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">ModSecurity v3.0.2<\/span><\/a><span style=\"font-weight: 400;\">. Google Cloud Platform (GCP) provides a <strong>controlled way to debug<\/strong> these rules with real traffic.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The best part is that <strong>users are not affected<\/strong> since we can select them in \u201cpreview only\u201d mode. This means that every time one of these rules is triggered, it will be logged and let the traffic through. Obviously, by activating preview mode, we will not be securing our platform in any way. Still, in this way, we can avoid false positives and gradually add these rules.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In addition to the preview-only mode, GCP uses verbose logging capabilities. What does this mean? For each request blocked by these rules, we will see detailed information in the <\/span><a href=\"https:\/\/cloud.google.com\/logging\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">log<\/span><\/a><span style=\"font-weight: 400;\"> on which signature and what part of the request has caused the block. As previously mentioned, each of the rules listed in the previous table contains several signatures, so some of these may cause false positives and should thus be disabled.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">With this protection, we can avoid the following attacks:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-site scripting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local file inclusion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote file inclusion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote code execution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Method enforcement (public preview)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scanner detection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Protocol attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PHP injection attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session fixation attack<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<blockquote><p><span style=\"font-weight: 400;\">Do you want to know more about how to secure your websites and applications? The Making Science Cloud team can help. Get in touch at <\/span><span style=\"font-weight: 400; color: #ff00ff;\">info@makingscience.com<\/span><span style=\"font-weight: 400;\">. We look forward to hearing from you!<\/span><\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>Web application security is crucial for protecting organisational and client data. In 2021, cyber \u200b\u200battacks caused approximately 5 trillion GBP in damage, which is expected to increase by 15% annually over the next five years. Thus, it is essential to use all possible tools to reduce the risk of these cyber attacks. Google Cloud Armor [&hellip;]<\/p>\n","protected":false},"author":23,"featured_media":30140,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[848],"tags":[66,140,429,427,430,428],"class_list":["post-30131","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-google-cloud-en","tag-cloud","tag-consent-mode-en","tag-google","tag-google-cloud-armor-2-en","tag-security-en","tag-waf-2-en"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/posts\/30131","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/comments?post=30131"}],"version-history":[{"count":0,"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/posts\/30131\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/media\/30140"}],"wp:attachment":[{"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/media?parent=30131"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/categories?post=30131"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.makingscience.com\/en\/wp-json\/wp\/v2\/tags?post=30131"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}