{"id":24539,"date":"2022-05-30T11:38:38","date_gmt":"2022-05-30T09:38:38","guid":{"rendered":"https:\/\/www.makingscience.com\/?p=24539"},"modified":"2022-05-30T11:38:38","modified_gmt":"2022-05-30T09:38:38","slug":"google-cloud-armor-waf-que-es-y-como-usarlo","status":"publish","type":"post","link":"https:\/\/www.makingscience.com\/es\/blog\/google-cloud-armor-waf-que-es-y-como-usarlo\/","title":{"rendered":"Protege tus sitios web y aplicaciones con Google Cloud Armor WAF"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">La seguridad de una aplicaci\u00f3n web es crucial de cara a la protecci\u00f3n de datos no solo de la organizaci\u00f3n, sino tambi\u00e9n de los clientes. <strong>Los ciberataques han causado aproximadamente un total de 6 trillones de USD en da\u00f1os a lo largo de 2021 y se prev\u00e9 que incremente anualmente un 15% en los pr\u00f3ximos 5 a\u00f1os.<\/strong> Es importante usar todas las herramientas posibles para reducir el riesgo de estos ciberataques.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Google cloud armor es un \u201cfirewall\u00bb a nivel de aplicaci\u00f3n el cual es capaz de protegernos de una gran variedad de ciberataques de manera sencilla y eficiente.<\/strong> Para poder utilizar esta herramienta tendremos que hacer uso de los balanceadores de carga que GCP proporciona ya que ser\u00e1 ah\u00ed donde habilitaremos el Cloud Armor sobre los backend services.<\/span><\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone size-large wp-image-24540\" src=\"https:\/\/www.makingscience.com\/wp-content\/uploads\/1\/2022\/05\/Captura-de-pantalla-2022-05-30-a-las-11.22.06-1024x537.png\" alt=\"\" width=\"1024\" height=\"537\" \/><span style=\"font-weight: 400;\">Una vez configurado el balanceador de carga y activado un security policy a un backend service, ser\u00e1 la hora de ajustar qu\u00e9 reglas WAF deseamos aplicar. Hay una gran variedad disponible seg\u00fan nuestras necesidades. En la siguiente tabla veremos un listado de algunas de estas reglas preconfiguradas agrupadas por categor\u00edas:<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><b>Nombre de la regla\u00a0<\/b><\/td>\n<td><b>Nombre de la regla de ModSecurity<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">sqli-stable<\/span><\/td>\n<td><span style=\"font-weight: 400;\">SQL injection<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">xss-stable<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Cross-site scripting<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">lfi-stable<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Local file inclusion<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">rfi-stable<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Remote file inclusion<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">rce-stable<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Remote code execution<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">scannerdetection-stable<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Scanner detection<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">Cada una de estas reglas contienen docenas de firmas que son compiladas de <\/span><a href=\"https:\/\/github.com\/coreruleset\/coreruleset\/tree\/v3.0\/master\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">ModSecurity v3.0.2<\/span><\/a><span style=\"font-weight: 400;\">. GCP proporciona una manera controlada de debugear estas reglas con tr\u00e1fico real sin que el usuario se vea afectado ya que a la hora de habilitarlas podremos selecciona el modo \u201cpreview only\u201d, esto significa que cada vez que una de estas reglas se dispare y vaya a bloquear una petici\u00f3n simplemente lo deje registrado y dejar\u00e1 pasar el tr\u00e1fico. Obviamente al activar el modo preview no estaremos securizando nuestra plataforma de ning\u00fan modo pero podremos evitar falsos positivos y granularmente ir agregando cada una de estas reglas.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Adem\u00e1s del modo preview only GCP otorga la posibilidad de <strong>incrementar el verbose de estas security policies.<\/strong> \u00bfY esto qu\u00e9 significa? Que <strong>por cada petici\u00f3n bloqueada por estas reglas veremos en el <\/strong><\/span><strong><a href=\"https:\/\/cloud.google.com\/logging\" target=\"_blank\" rel=\"noopener\">logging<\/a><\/strong><span style=\"font-weight: 400;\"><strong> informaci\u00f3n detallada de qu\u00e9 firma y que parte de la petici\u00f3n ha causado el bloqueo,<\/strong> como previamente he mencionado cada una de las reglas listadas en la tabla previa contiene un n\u00famero de firmas por lo que puede que alguna de estas firmas cause falsos positivos y deba ser deshabilitada.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Con esta protecci\u00f3n podemos evitar los siguientes ataques:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-site scripting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local file inclusion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote file inclusion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote code execution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Method enforcement (public preview)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scanner detection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Protocol attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PHP injection attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session fixation attack<\/span><\/li>\n<\/ul>\n<blockquote><p><strong>\u00bfQuieres saber m\u00e1s sobre c\u00f3mo securizar mejor tus sitios\u00a0 web y aplicaciones? ?<\/strong> El equipo Cloud de Making Science puede ayudarte en tu caso concreto. No dudes en contactarnos en info@makingscience.com. \u00a1Te esperamos! ?<\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>La seguridad de una aplicaci\u00f3n web es crucial de cara a la protecci\u00f3n de datos no solo de la organizaci\u00f3n, sino tambi\u00e9n de los clientes. Los ciberataques han causado aproximadamente un total de 6 trillones de USD en da\u00f1os a lo largo de 2021 y se prev\u00e9 que incremente anualmente un 15% en los pr\u00f3ximos [&hellip;]<\/p>\n","protected":false},"author":40,"featured_media":24558,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[910],"tags":[302,115,299,301,300],"class_list":["post-24539","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology-ai-es","tag-cloud-es","tag-consent-mode","tag-google-cloud-armor","tag-seguridad","tag-waf"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/posts\/24539","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/users\/40"}],"replies":[{"embeddable":true,"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/comments?post=24539"}],"version-history":[{"count":0,"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/posts\/24539\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/media\/24558"}],"wp:attachment":[{"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/media?parent=24539"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/categories?post=24539"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.makingscience.com\/es\/wp-json\/wp\/v2\/tags?post=24539"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}