跳转到内容
搜索文档

Google Cloud Platform (GCP) Cloud Storage(GCP Cloud Storage 集成)

最后更新 查看 MarkdownAgent 设置

Google Cloud Platform (GCP) Cloud Storage 集成可检测已集成的 GCP account 中的各种数据防泄漏、账户配置错误和用户安全风险,这些风险可能会使您和您的组织易受攻击。

集成前提条件

  • 使用 Cloud Storage 的 GCP 账户。
  • 对于初始设置,需要访问具有创建具有下列范围的新服务账户(Service Account)权限的 GCP 账户。

集成权限

为了使 GCP Cloud Storage 集成正常运行,Cloudflare CASB 需要通过服务账户(Service Account)获取以下访问范围:

  • roles/viewer
  • roles/storage.admin

这些权限遵循最小权限原则,以确保仅授予所需的最小访问权限。要了解有关每个权限范围的更多信息,请参阅 GCP Cloud Storage 的 IAM 角色文档 ↗。

计算账户

您可以将 GCP 计算账户连接到您的 CASB 集成,以在您的 Cloud Storage 存储桶内执行 数据丢失预防 (DLP) 扫描并避免数据流出。CASB 将扫描配置时存储桶中存在的任何对象。

添加计算账户

要将计算账户连接到您的 GCP 集成:

  1. 在 Cloudflare One ↗ 中,转到 Integrations(集成) > Cloud & SaaS integrations(云和 SaaS 集成)。
  2. 找到并选择您的 GCP 集成。
  3. 选择 Open connection instructions(打开连接说明)。
  4. 按照提供的说明连接新的计算账户。
  5. 选择 Refresh(刷新)。

您只能将一个计算账户连接到一个集成。要删除计算账户,请选择 Manage compute accounts(管理计算账户)。

配置计算账户扫描

在您的 GCP 计算账户成功连接到 CASB 集成后,您可以配置在何处以及如何扫描敏感数据:

  1. 在 Cloudflare One ↗ 中,转到 Integrations(集成) > Cloud & SaaS integrations(云和 SaaS 集成)。
  2. 找到并选择您的 GCP 集成。
  3. 选择 Create new configuration(创建新配置)。
  4. 在 Resources(资源) 中,选择您要扫描的存储桶。选择 Continue(继续)。
  5. 选择要扫描的文件类型、采样百分比和 DLP 配置文件。
  6. (可选)配置其他设置,例如 CASB 应遵守的随时间推移的 API 调用限制。
  7. 选择 Continue(继续)。
  8. 审查扫描的详细信息,然后选择 Start scan(开始扫描)。

CASB 最多需要一个小时来开始扫描。要查看扫描结果,请转到 Cloud & SaaS findings(云和 SaaS 发现) > Content Findings(内容发现)。

要管理您的资源,请转到 Cloud & SaaS findings(云和 SaaS 发现) > Integrations(集成),然后找到并选择您的 GCP 集成。在此处,您可以暂停全部或单个扫描、添加或删除资源以及更改扫描设置。

有关更多信息,请参阅 内容发现。

安全发现

GCP Cloud Storage 集成目前会扫描以下发现(或安全风险)。发现按类别分组,然后按严重程度级别排序。

要及时获取新增的 CASB 发现,请将此页面存为书签或订阅其 RSS 源。

Cloud Storage 存储桶安全

标记 Cloud Storage 存储桶中的安全问题,包括过度授权、访问策略以及用户安全最佳实践。

发现类型 FindingTypeID 严重程度
Google Cloud Platform: GCS 存储桶允许公开写入 4583f5a9-a343-4e2f-a8b3-9237a911f337 紧急
Google Cloud Platform: GCS 存储桶 IAM 策略允许公开访问 032c1e88-0cff-47f6-8d75-046e0a7330de 紧急
Google Cloud Platform: GCS 存储桶可公开访问 cc028a95-46d4-4156-ac11-bc5713529824 紧急
Google Cloud Platform: 启用了公开访问预防但策略授予公开权限 cc02680e-9cc3-49d1-99d5-29d425bf142f 紧急
Google Cloud Platform: GCS 存储桶 ACL 授予所有已身份验证的用户访问权限 e1a588af-0500-482e-b59d-fd2693ce7fc0 紧急
Google Cloud Platform: GCS 存储桶 ACL 授予所有用户公开访问权限 1904c004-8d4f-470e-9460-e77db23d6a86 紧急
Google Cloud Platform: 公开访问预防但 ACL 授予 allUsers fcf2e27e-673f-4cd2-9b76-ec89c4c5872c 紧急
Google Cloud Platform: GCS 存储桶版本控制已禁用 bd66e214-f205-4e00-bd68-121dad0a7988 高
Google Cloud Platform: 没有 KMS 加密的 GCS 存储桶 0105d9c4-1a01-4b65-b33e-df6c55905147 高
Google Cloud Platform: GCS 统一存储桶级访问已禁用 6960b459-aa9e-4b41-84f6-26cdb75a1995 高
Google Cloud Platform: GCS 存储桶 IAM 策略允许公开读取 10420f34-8fdd-49cb-8d38-096a2de5824f 高
Google Cloud Platform: GCS 存储桶缺少生命周期规则 edcd5a8b-b128-404b-8207-23a80f669b65 中
Google Cloud Platform: GCS 存储桶日志记录已禁用 d26f43c8-9406-481c-8c8b-1a7f05f3cc27 中
Google Cloud Platform: GCS 存储桶未使用“软删除(Soft Delete)” 5542ed8e-77a6-43c1-8b9e-935e66009d34 中
Google Cloud Platform: GCS 存储桶保留策略已禁用 2d4a247c-8adb-4f2b-ae58-3568d633cb81 中
Google Cloud Platform: GCS 存储桶 IAM 策略不是版本 3 ade2ede6-08c7-4962-b084-f6a29ee4a5b8 低
Google Cloud Platform: GCS 存储桶 IAM 策略使用旧版角色 11a592b9-4f51-4a1a-9925-a48a5ed01521 低

这篇文档对您有帮助吗?