Google Cloud Armor preconfigured WAF rules are complex web application firewall (WAF) rules with dozens of signatures that are compiled from open source industry standards. Each signature corresponds to an attack detection rule in the ruleset. Google offers these rules as is. The rules let Cloud Armor evaluate dozens of distinct traffic signatures by referring to conveniently named rules rather than requiring you to define each signature manually.
Cloud Armor preconfigured WAF rules can be tuned to best suit your needs. For more information about how to tune the rules, see Tune Cloud Armor preconfigured WAF rules.
The following table lists the preconfigured preconfigured WAF rules available for use in a Cloud Armor security policy. These rules are based on the OWASP ModSecurity Core Rule Set (CRS), such as OWASP Core Rule Set 4.22 . We recommend using version 4.22 for the most up-to-date protection against modern threats. While support for CRS 3.3 and 3.0 is ongoing, we recommend avoiding older versions, especially CRS version 3.0, whenever your workloads allow for version 4.22.
CRS 4.22
| Cloud Armor rule name | OWASP rule name | Current status |
|---|---|---|
| SQL injection | sqli-v422-stable |
In sync with sqli-v422-canary |
sqli-v422-canary |
Latest | |
| Cross-site scripting | xss-v422-stable |
In sync with xss-v422-canary |
xss-v422-canary |
Latest | |
| Local file inclusion | lfi-v422-stable |
In sync with lfi-v422-canary |
lfi-v422-canary |
Latest | |
| Remote file inclusion | rfi-v422-stable |
In sync with rfi-v422-canary |
rfi-v422-canary |
Latest | |
| Remote code execution | rce-v422-stable |
In sync with rce-v422-canary |
rce-v422-canary |
Latest | |
| Method enforcement | methodenforcement-v422-stable |
In sync with methodenforcement-v422-canary |
methodenforcement-v422-canary |
Latest | |
| Scanner detection | scannerdetection-v422-stable |
In sync with scannerdetection-v422-canary |
scannerdetection-v422-canary |
Latest | |
| Protocol attack | protocolattack-v422-stable |
In sync with protocolattack-v422-canary |
protocolattack-v422-canary |
Latest | |
| PHP injection attack | php-v422-stable |
In sync with php-v422-canary |
php-v422-canary |
Latest | |
| Session fixation attack | sessionfixation-v422-stable |
In sync with sessionfixation-v422-canary |
sessionfixation-v422-canary |
Latest | |
| Java attack | java-v422-stable |
In sync with java-v422-canary |
java-v422-canary |
Latest | |
| Generic attack | generic-v422-stable |
In sync with generic-v422-canary |
generic-v422-canary |
Latest |
CRS 3.3
| Cloud Armor rule name | OWASP rule name | Current status |
|---|---|---|
| SQL injection | sqli-v33-stable |
In sync with sqli-v33-canary |
sqli-v33-canary |
Latest | |
| Cross-site scripting | xss-v33-stable |
In sync with xss-v33-canary |
xss-v33-canary |
Latest | |
| Local file inclusion | lfi-v33-stable |
In sync with lfi-v33-canary |
lfi-v33-canary |
Latest | |
| Remote file inclusion | rfi-v33-stable |
In sync with rfi-v33-canary |
rfi-v33-canary |
Latest | |
| Remote code execution | rce-v33-stable |
In sync with rce-v33-canary |
rce-v33-canary |
Latest | |
| Method enforcement | methodenforcement-v33-stable |
In sync with methodenforcement-v33-canary |
methodenforcement-v33-canary |
Latest | |
| Scanner detection | scannerdetection-v33-stable |
In sync with scannerdetection-v33-canary |
scannerdetection-v33-canary |
Latest | |
| Protocol attack | protocolattack-v33-stable |
In sync with protocolattack-v33-canary |
protocolattack-v33-canary |
Latest | |
| PHP injection attack | php-v33-stable |
In sync with php-v33-canary |
php-v33-canary |