Preconfigured WAF rules overview

Google Cloud Armor preconfigured WAF rules are complex web application firewall (WAF) rules with dozens of signatures that are compiled from open source industry standards. Each signature corresponds to an attack detection rule in the ruleset. Google offers these rules as is. The rules let Cloud Armor evaluate dozens of distinct traffic signatures by referring to conveniently named rules rather than requiring you to define each signature manually.

Cloud Armor preconfigured WAF rules can be tuned to best suit your needs. For more information about how to tune the rules, see Tune Cloud Armor preconfigured WAF rules.

The following table lists the preconfigured preconfigured WAF rules available for use in a Cloud Armor security policy. These rules are based on the OWASP ModSecurity Core Rule Set (CRS), such as OWASP Core Rule Set 4.22 . We recommend using version 4.22 for the most up-to-date protection against modern threats. While support for CRS 3.3 and 3.0 is ongoing, we recommend avoiding older versions, especially CRS version 3.0, whenever your workloads allow for version 4.22.

CRS 4.22

Cloud Armor rule name OWASP rule name Current status
SQL injection sqli-v422-stable In sync with sqli-v422-canary
sqli-v422-canary Latest
Cross-site scripting xss-v422-stable In sync with xss-v422-canary
xss-v422-canary Latest
Local file inclusion lfi-v422-stable In sync with lfi-v422-canary
lfi-v422-canary Latest
Remote file inclusion rfi-v422-stable In sync with rfi-v422-canary
rfi-v422-canary Latest
Remote code execution rce-v422-stable In sync with rce-v422-canary
rce-v422-canary Latest
Method enforcement methodenforcement-v422-stable In sync with methodenforcement-v422-canary
methodenforcement-v422-canary Latest
Scanner detection scannerdetection-v422-stable In sync with scannerdetection-v422-canary
scannerdetection-v422-canary Latest
Protocol attack protocolattack-v422-stable In sync with protocolattack-v422-canary
protocolattack-v422-canary Latest
PHP injection attack php-v422-stable In sync with php-v422-canary
php-v422-canary Latest
Session fixation attack sessionfixation-v422-stable In sync with sessionfixation-v422-canary
sessionfixation-v422-canary Latest
Java attack java-v422-stable In sync with java-v422-canary
java-v422-canary Latest
Generic attack generic-v422-stable In sync with generic-v422-canary
generic-v422-canary Latest

CRS 3.3

Cloud Armor rule name OWASP rule name Current status
SQL injection sqli-v33-stable In sync with sqli-v33-canary
sqli-v33-canary Latest
Cross-site scripting xss-v33-stable In sync with xss-v33-canary
xss-v33-canary Latest
Local file inclusion lfi-v33-stable In sync with lfi-v33-canary
lfi-v33-canary Latest
Remote file inclusion rfi-v33-stable In sync with rfi-v33-canary
rfi-v33-canary Latest
Remote code execution rce-v33-stable In sync with rce-v33-canary
rce-v33-canary Latest
Method enforcement methodenforcement-v33-stable In sync with methodenforcement-v33-canary
methodenforcement-v33-canary Latest
Scanner detection scannerdetection-v33-stable In sync with scannerdetection-v33-canary
scannerdetection-v33-canary Latest
Protocol attack protocolattack-v33-stable In sync with protocolattack-v33-canary
protocolattack-v33-canary Latest
PHP injection attack php-v33-stable In sync with php-v33-canary
php-v33-canary