Google Cloud Armor
This section covers DDoS protection and the use of WAFs to provide safety for your web-based infrastructure. You can protect your Google Cloud workloads from a wide range of threats, including DDoS attacks and application attacks, such as XSS and SQL injection, with Cloud Armor (SQLi). Some capabilities are built in to provide automated protection, while others require manual configuration. We will look at those capabilities of WAFs in more detail in this section:
Figure 8.18 – How Google Cloud Armor secures your infrastructure
Cloud Armor leverages Google’s global and distributed infrastructure to detect and absorb attacks and filter traffic through configurable security policies at the edge. It should be kept in mind that several aspects of Google Cloud Armor are only available for applications running behind an external HTTP(S) load balancer. Figure 8.18 illustrates the placement of Cloud Armor, which is in line with...