Google Cloud Armor规则偶发绕过问题排查咨询
Google Cloud Armor规则绕过排查问题
我在Google Cloud Armor中配置了50余条规则,其中*优先级最低(Priority:1)*的规则如下,该规则基于Cloud Armor文档中的bad_path URI示例:
request.path.startsWith('/api/foo') Deny 403 Priority: 1 Activated 1st November
通过Google Cloud Logging,我发现该规则存在被绕过的情况,查询语句如下:
resource.type:(http_load_balancer) AND jsonPayload.enforcedSecurityPolicy.name:(rules) AND log_name="projects/foo_bar/logs/requests" AND httpRequest.requestUrl="https://foo.example.io/api/foo" AND
请求模式为:
https://foo.example.io/api/foo
2分钟内采样数据
| 结果 | 状态详情 | HTTP状态码 | 优先级 | 请求方法 | 请求大小 | 时间戳 | 接收时间戳 |
|---|---|---|---|---|---|---|---|
| 拒绝 | denied_by_security_policy | 403 | 1 | POST | 1188 | 12:49:48.746858Z | 12:50:24 |
| 拒绝 | denied_by_security_policy | 403 | 1 | POST | 1191 | 12:49:48.297242Z | 12:50:02 |
| 允许 | response_sent_by_backend | 200 | 60000 | POST | 1189 | 12:49:48.924442Z | 12:50:36 |
| 拒绝 | denied_by_security_policy | 403 | 1 | POST | 1189 | 12:49:48.924468Z | 12:50:29 |
| 拒绝 | denied_by_security_policy | 403 | 1 | POST | 1184 | 12:49:48.990177Z | 12:49:50 |
所有请求的以下字段均相同:
backend_service_name: Same for all above forwarding_rule_name: Same for all above url_map_name: Same for all above
请求示例
403请求
httpRequest: { latency: "0.1" remoteIp: "x.x.x.x" requestMethod: "POST" Requestsize: "1200" requestUrl: https://foo.example.io/api/foo responsesize: "315" status: 403 userAgent: "XYZ" }
200请求
httpRequest: { latency: "0.5" remoteIp: "x.x.x.x" requestMethod: "POST" Requestsize: "1202" requestUrl: https://foo.example.io/api/foo responsesize: "3150" serverIp: "x.x.x" status: 200 userAgent: "XYZ" }
审计日志情况
在Google Cloud Logging(审计日志)中,查询条件为:
cloudaudit.googleapis.com%2Factivity resource.type="network_security_policy"
存在3条Cloud Armor更新记录,但均发生在上述请求时间戳的数小时后:
| 规则 | 仅验证 | 资源 | 时间戳 | 接收时间戳 |
|---|---|---|---|---|
| 2500 | true | network_security_policy | 14:02:03 | 14:02:04 |
| 2500 | N_A | network_security_policy | 14:02:05 | 14:02:06 |
| N_A | N_A | network_security_policy | 14:02:11 | 14:02:12 |
该规则并非仅出现一次偶发绕过情况,我认为“Cloud Armor POST body inspection limitation”与此无关,请问还可采取哪些步骤排查原因?
内容的提问来源于stack exchange,提问作者Fredrik
相关产品推荐
相关产品推荐

