跳转到内容
搜索文档

Google Cloud Platform (GCP) Cloud Storage(GCP Cloud Storage 集成)

最后更新 查看 MarkdownAgent 设置

Google Cloud Platform (GCP) Cloud Storage 集成可检测已集成的 GCP account 中的各种数据防泄漏、账户配置错误和用户安全风险,这些风险可能会使您和您的组织易受攻击。

集成前提条件

  • 使用 Cloud Storage 的 GCP 账户。
  • 对于初始设置,需要访问具有创建具有下列范围的新服务账户(Service Account)权限的 GCP 账户。

集成权限

为了使 GCP Cloud Storage 集成正常运行,Cloudflare CASB 需要通过服务账户(Service Account)获取以下访问范围:

  • roles/viewer
  • roles/storage.admin

这些权限遵循最小权限原则,以确保仅授予所需的最小访问权限。要了解有关每个权限范围的更多信息,请参阅 GCP Cloud Storage 的 IAM 角色文档

计算账户

您可以将 GCP 计算账户连接到您的 CASB 集成,以在您的 Cloud Storage 存储桶内执行 数据丢失预防 (DLP) 扫描并避免数据流出。CASB 将扫描配置时存储桶中存在的任何对象。

添加计算账户

要将计算账户连接到您的 GCP 集成:

  1. Cloudflare One 中,转到 Integrations(集成) > Cloud & SaaS integrations(云和 SaaS 集成)
  2. 找到并选择您的 GCP 集成。
  3. 选择 Open connection instructions(打开连接说明)
  4. 按照提供的说明连接新的计算账户。
  5. 选择 Refresh(刷新)

您只能将一个计算账户连接到一个集成。要删除计算账户,请选择 Manage compute accounts(管理计算账户)

配置计算账户扫描

在您的 GCP 计算账户成功连接到 CASB 集成后,您可以配置在何处以及如何扫描敏感数据:

  1. Cloudflare One 中,转到 Integrations(集成) > Cloud & SaaS integrations(云和 SaaS 集成)
  2. 找到并选择您的 GCP 集成。
  3. 选择 Create new configuration(创建新配置)
  4. Resources(资源) 中,选择您要扫描的存储桶。选择 Continue(继续)
  5. 选择要扫描的文件类型、采样百分比和 DLP 配置文件
  6. (可选)配置其他设置,例如 CASB 应遵守的随时间推移的 API 调用限制。
  7. 选择 Continue(继续)
  8. 审查扫描的详细信息,然后选择 Start scan(开始扫描)

CASB 最多需要一个小时来开始扫描。要查看扫描结果,请转到 Cloud & SaaS findings(云和 SaaS 发现) > Content Findings(内容发现)

要管理您的资源,请转到 Cloud & SaaS findings(云和 SaaS 发现) > Integrations(集成),然后找到并选择您的 GCP 集成。在此处,您可以暂停全部或单个扫描、添加或删除资源以及更改扫描设置。

有关更多信息,请参阅 内容发现

安全发现

GCP Cloud Storage 集成目前会扫描以下发现(或安全风险)。发现按类别分组,然后按严重程度级别排序。

要及时获取新增的 CASB 发现,请将此页面存为书签或订阅其 RSS 源

Cloud Storage 存储桶安全

标记 Cloud Storage 存储桶中的安全问题,包括过度授权、访问策略以及用户安全最佳实践。

发现类型 FindingTypeID 严重程度
Google Cloud Platform: GCS 存储桶允许公开写入 4583f5a9-a343-4e2f-a8b3-9237a911f337 紧急
Google Cloud Platform: GCS 存储桶 IAM 策略允许公开访问 032c1e88-0cff-47f6-8d75-046e0a7330de 紧急
Google Cloud Platform: GCS 存储桶可公开访问 cc028a95-46d4-4156-ac11-bc5713529824 紧急
Google Cloud Platform: 启用了公开访问预防但策略授予公开权限 cc02680e-9cc3-49d1-99d5-29d425bf142f 紧急
Google Cloud Platform: GCS 存储桶 ACL 授予所有已身份验证的用户访问权限 e1a588af-0500-482e-b59d-fd2693ce7fc0 紧急
Google Cloud Platform: GCS 存储桶 ACL 授予所有用户公开访问权限 1904c004-8d4f-470e-9460-e77db23d6a86 紧急
Google Cloud Platform: 公开访问预防但 ACL 授予 allUsers fcf2e27e-673f-4cd2-9b76-ec89c4c5872c 紧急
Google Cloud Platform: GCS 存储桶版本控制已禁用 bd66e214-f205-4e00-bd68-121dad0a7988
Google Cloud Platform: 没有 KMS 加密的 GCS 存储桶 0105d9c4-1a01-4b65-b33e-df6c55905147
Google Cloud Platform: GCS 统一存储桶级访问已禁用 6960b459-aa9e-4b41-84f6-26cdb75a1995
Google Cloud Platform: GCS 存储桶 IAM 策略允许公开读取 10420f34-8fdd-49cb-8d38-096a2de5824f
Google Cloud Platform: GCS 存储桶缺少生命周期规则 edcd5a8b-b128-404b-8207-23a80f669b65
Google Cloud Platform: GCS 存储桶日志记录已禁用 d26f43c8-9406-481c-8c8b-1a7f05f3cc27
Google Cloud Platform: GCS 存储桶未使用“软删除(Soft Delete)” 5542ed8e-77a6-43c1-8b9e-935e66009d34
Google Cloud Platform: GCS 存储桶保留策略已禁用 2d4a247c-8adb-4f2b-ae58-3568d633cb81
Google Cloud Platform: GCS 存储桶 IAM 策略不是版本 3 ade2ede6-08c7-4962-b084-f6a29ee4a5b8
Google Cloud Platform: GCS 存储桶 IAM 策略使用旧版角色 11a592b9-4f51-4a1a-9925-a48a5ed01521

这篇文档对您有帮助吗?