Google Cloud Platform (GCP) Cloud Storage 集成可检测已集成的 GCP account 中的各种数据防泄漏、账户配置错误和用户安全风险,这些风险可能会使您和您的组织易受攻击。
- 使用 Cloud Storage 的 GCP 账户。
- 对于初始设置,需要访问具有创建具有下列范围的新服务账户(Service Account)权限的 GCP 账户。
为了使 GCP Cloud Storage 集成正常运行,Cloudflare CASB 需要通过服务账户(Service Account)获取以下访问范围:
roles/viewerroles/storage.admin
这些权限遵循最小权限原则,以确保仅授予所需的最小访问权限。要了解有关每个权限范围的更多信息,请参阅 GCP Cloud Storage 的 IAM 角色文档 ↗。
您可以将 GCP 计算账户连接到您的 CASB 集成,以在您的 Cloud Storage 存储桶内执行 数据丢失预防 (DLP) 扫描并避免数据流出。CASB 将扫描配置时存储桶中存在的任何对象。
要将计算账户连接到您的 GCP 集成:
- 在 Cloudflare One ↗ 中,转到 Integrations(集成) > Cloud & SaaS integrations(云和 SaaS 集成)。
- 找到并选择您的 GCP 集成。
- 选择 Open connection instructions(打开连接说明)。
- 按照提供的说明连接新的计算账户。
- 选择 Refresh(刷新)。
您只能将一个计算账户连接到一个集成。要删除计算账户,请选择 Manage compute accounts(管理计算账户)。
在您的 GCP 计算账户成功连接到 CASB 集成后,您可以配置在何处以及如何扫描敏感数据:
- 在 Cloudflare One ↗ 中,转到 Integrations(集成) > Cloud & SaaS integrations(云和 SaaS 集成)。
- 找到并选择您的 GCP 集成。
- 选择 Create new configuration(创建新配置)。
- 在 Resources(资源) 中,选择您要扫描的存储桶。选择 Continue(继续)。
- 选择要扫描的文件类型、采样百分比和 DLP 配置文件。
- (可选)配置其他设置,例如 CASB 应遵守的随时间推移的 API 调用限制。
- 选择 Continue(继续)。
- 审查扫描的详细信息,然后选择 Start scan(开始扫描)。
CASB 最多需要一个小时来开始扫描。要查看扫描结果,请转到 Cloud & SaaS findings(云和 SaaS 发现) > Content Findings(内容发现)。
要管理您的资源,请转到 Cloud & SaaS findings(云和 SaaS 发现) > Integrations(集成),然后找到并选择您的 GCP 集成。在此处,您可以暂停全部或单个扫描、添加或删除资源以及更改扫描设置。
有关更多信息,请参阅 内容发现。
GCP Cloud Storage 集成目前会扫描以下发现(或安全风险)。发现按类别分组,然后按严重程度级别排序。
要及时获取新增的 CASB 发现,请将此页面存为书签或订阅其 RSS 源。
标记 Cloud Storage 存储桶中的安全问题,包括过度授权、访问策略以及用户安全最佳实践。
| 发现类型 | FindingTypeID | 严重程度 |
|---|---|---|
| Google Cloud Platform: GCS 存储桶允许公开写入 | 4583f5a9-a343-4e2f-a8b3-9237a911f337 |
紧急 |
| Google Cloud Platform: GCS 存储桶 IAM 策略允许公开访问 | 032c1e88-0cff-47f6-8d75-046e0a7330de |
紧急 |
| Google Cloud Platform: GCS 存储桶可公开访问 | cc028a95-46d4-4156-ac11-bc5713529824 |
紧急 |
| Google Cloud Platform: 启用了公开访问预防但策略授予公开权限 | cc02680e-9cc3-49d1-99d5-29d425bf142f |
紧急 |
| Google Cloud Platform: GCS 存储桶 ACL 授予所有已身份验证的用户访问权限 | e1a588af-0500-482e-b59d-fd2693ce7fc0 |
紧急 |
| Google Cloud Platform: GCS 存储桶 ACL 授予所有用户公开访问权限 | 1904c004-8d4f-470e-9460-e77db23d6a86 |
紧急 |
| Google Cloud Platform: 公开访问预防但 ACL 授予 allUsers | fcf2e27e-673f-4cd2-9b76-ec89c4c5872c |
紧急 |
| Google Cloud Platform: GCS 存储桶版本控制已禁用 | bd66e214-f205-4e00-bd68-121dad0a7988 |
高 |
| Google Cloud Platform: 没有 KMS 加密的 GCS 存储桶 | 0105d9c4-1a01-4b65-b33e-df6c55905147 |
高 |
| Google Cloud Platform: GCS 统一存储桶级访问已禁用 | 6960b459-aa9e-4b41-84f6-26cdb75a1995 |
高 |
| Google Cloud Platform: GCS 存储桶 IAM 策略允许公开读取 | 10420f34-8fdd-49cb-8d38-096a2de5824f |
高 |
| Google Cloud Platform: GCS 存储桶缺少生命周期规则 | edcd5a8b-b128-404b-8207-23a80f669b65 |
中 |
| Google Cloud Platform: GCS 存储桶日志记录已禁用 | d26f43c8-9406-481c-8c8b-1a7f05f3cc27 |
中 |
| Google Cloud Platform: GCS 存储桶未使用“软删除(Soft Delete)” | 5542ed8e-77a6-43c1-8b9e-935e66009d34 |
中 |
| Google Cloud Platform: GCS 存储桶保留策略已禁用 | 2d4a247c-8adb-4f2b-ae58-3568d633cb81 |
中 |
| Google Cloud Platform: GCS 存储桶 IAM 策略不是版本 3 | ade2ede6-08c7-4962-b084-f6a29ee4a5b8 |
低 |
| Google Cloud Platform: GCS 存储桶 IAM 策略使用旧版角色 | 11a592b9-4f51-4a1a-9925-a48a5ed01521 |
低 |