預先設定的網路應用程式防火牆規則總覽

Google Cloud Armor 預先設定的 WAF 規則是複雜的網頁應用程式防火牆 (WAF) 規則,包含依開放原始碼業界標準編譯的數十個簽名。每個簽章都對應規則集中的攻擊偵測規則。Google 會照常提供這些規則。這些規則可讓 Cloud Armor 評估數十種不同的流量簽章,方法是參照方便命名的規則,而不是要求您手動定義每個簽章。

您可以調整 Cloud Armor 預先設定的 WAF 規則,使其最符合您的需求。如要進一步瞭解如何調整規則,請參閱「調整 Cloud Armor 預先設定的 WAF 規則」。

下表列出預先設定的 WAF 規則,可用於 Cloud Armor 安全性政策。這些規則是以 OWASP ModSecurity 核心規則集 (CRS) 為依據,例如 OWASP 核心規則集 4.22。建議使用 4.22 版,取得最新防護功能,抵禦現代威脅。雖然我們仍支援 CRS 3.3 和 3.0,但建議您盡量避免使用舊版,尤其是 CRS 3.0 版,並在工作負載允許的情況下使用 4.22 版。

CRS 4.22

Cloud Armor 規則名稱 OWASP 規則名稱 目前狀態
SQL 注入 sqli-v422-stable 已與「sqli-v422-canary」同步
sqli-v422-canary 最新
跨網站指令碼攻擊 xss-v422-stable 已與「xss-v422-canary」同步
xss-v422-canary 最新
本機檔案包含 lfi-v422-stable 已與「lfi-v422-canary」同步
lfi-v422-canary 最新
遠端檔案包含 rfi-v422-stable 已與「rfi-v422-canary」同步
rfi-v422-canary 最新
遠端程式碼執行 rce-v422-stable 已與「rce-v422-canary」同步
rce-v422-canary 最新
方法強制執行 methodenforcement-v422-stable 已與「methodenforcement-v422-canary」同步
methodenforcement-v422-canary 最新
掃描器偵測 scannerdetection-v422-stable 已與「scannerdetection-v422-canary」同步
scannerdetection-v422-canary 最新
通訊協定攻擊 protocolattack-v422-stable 已與「protocolattack-v422-canary」同步
protocolattack-v422-canary 最新
PHP 注入式攻擊 php-v422-stable 已與「php-v422-canary」同步
php-v422-canary 最新
工作階段固定攻擊 sessionfixation-v422-stable 已與「sessionfixation-v422-canary」同步
sessionfixation-v422-canary 最新
Java 攻擊 java-v422-stable 已與「java-v422-canary」同步
java-v422-canary 最新
一般攻擊 generic-v422-stable 已與「generic-v422-canary」同步
generic-v422-canary 最新

CRS 3.3

Cloud Armor 規則名稱 OWASP 規則名稱 目前狀態
SQL 注入 sqli-v33-stable 已與「sqli-v33-canary」同步
sqli-v33-canary 最新
跨網站指令碼攻擊 xss-v33-stable 已與「xss-v33-canary」同步
xss-v33-canary 最新
本機檔案包含 lfi-v33-stable 已與「lfi-v33-canary」同步
lfi-v33-canary 最新
遠端檔案包含 rfi-v33-stable 已與「rfi-v33-canary」同步
rfi-v33-canary 最新
遠端程式碼執行 rce-v33-stable 已與「rce-v33-canary」同步
rce-v33-canary 最新
方法強制執行 methodenforcement-v33-stable 已與「methodenforcement-v33-canary」同步
methodenforcement-v33-canary 最新
掃描器偵測 scannerdetection-v33-stable 已與「scannerdetection-v33-canary」同步
scannerdetection-v33-canary 最新
通訊協定攻擊 protocolattack-v33-stable 已與「protocolattack-v33-canary」同步
protocolattack-v33-canary 最新
PHP 注入式攻擊 php-v33-stable 已與「php-v33-canary」同步
php-v33-canary 最新
工作階段固定攻擊 sessionfixation-v33-stable 已與「sessionfixation-v33-canary」同步
sessionfixation-v33-canary 最新
Java 攻擊 java-v33-stable 已與「java-v33-canary」同步
java-v33-canary 最新
NodeJS 攻擊 nodejs-v33-stable 已與「nodejs-v33-canary」同步
nodejs-v33-canary 最新

CRS 3.0

Cloud Armor 規則名稱 OWASP 規則名稱 目前狀態
SQL 注入 sqli-stable 已與「sqli-canary」同步
sqli-canary 最新
跨網站指令碼攻擊 xss-stable 已與「xss-canary」同步
xss-canary 最新
本機檔案包含 lfi-stable 已與「lfi-canary」同步