Bảo mật Security សុវត្ថិភាព Cơ bản Entry កម្រិតចាប់ផ្តើម ~7 phút đọc · ~658 từ ~7 min read · ~546 words

WAF là gì? Bảo vệ website Cloudflare theo cách người không chuyên IT cũng hiểu What is a WAF? Cloudflare website protection explained for non-specialists What is a WAF? Cloudflare website protection explained for non-specialists

WAF giống bảo vệ cửa ra vào của website: xem ai đang gõ cửa, chặn hành vi đáng ngờ, rồi mới cho vào bên trong (origin). A WAF is like a doorman for your website: it checks who is knocking, blocks suspicious behavior, then lets safe traffic through to your origin. A WAF is like a doorman for your website: it checks who is knocking, blocks suspicious behavior, then lets safe traffic through to your origin.

Hình 1: Cách Cloudflare nhận diện, chấm điểm và xử lý traffic từ bot.

Quản lý bot Bot management Bot management

Luồng phát hiện, chấm điểm và xử lý bot traffic trên edge — nền tảng cho WAF, rate limit và Bot Management. Cloudflare has bot management capabilities to help identify and mitigate automated traffic to protect domains from bad bots. Cloudflare has bot management capabilities to help identify and mitigate automated traffic to protect domains from bad bots.

Thuật ngữ: Concepts: Concepts: Bot score · Super Bot Fight Mode · WAF · Rate limiting

Sơ đồ chính thức ↗ Official diagram ↗ Official diagram ↗ · Bot Bots Bots

Vì sao website cần “người gác cổng”, không chỉ mật khẩu admin? Why websites need a doorman — not only an admin password Why websites need a doorman — not only an admin password

Nhiều chủ doanh nghiệp nghĩ bảo mật website chỉ là mật khẩu mạnh và chứng chỉ HTTPS. Những thứ đó quan trọng, nhưng phần lớn tấn công tự động không cần biết mật khẩu của bạn. Chúng gửi hàng loạt request thử lỗi phổ biến: chèn mã độc vào form, dò đường dẫn quản trị, lợi dụng lỗ hổng plugin cũ. Many business owners think website security is only a strong password and HTTPS. Those matter, but most automated attacks never need your password. They fire waves of requests probing common flaws: injecting malicious code into forms, guessing admin paths, abusing outdated plugins. Many business owners think website security is only a strong password and HTTPS. Those matter, but most automated attacks never need your password. They fire waves of requests probing common flaws: injecting malicious code into forms, guessing admin paths, abusing outdated plugins.

WAF (Web Application Firewall) đứng giữa Internet và ứng dụng của bạn. Trên Cloudflare, khi site được proxy, WAF có thể kiểm tra request theo quy tắc — managed rules do Cloudflare duy trì, hoặc quy tắc bạn tự thêm — trước khi request chạm origin. A WAF (Web Application Firewall) sits between the Internet and your application. On Cloudflare, once a site is proxied, the WAF can inspect requests against rules — Cloudflare-managed rulesets or your own — before traffic reaches origin. A WAF (Web Application Firewall) sits between the Internet and your application. On Cloudflare, once a site is proxied, the WAF can inspect requests against rules — Cloudflare-managed rulesets or your own — before traffic reaches origin.

Các bài trên blog.cloudflare.com về application security thường nhắc: tấn công thay đổi theo mùa (bot, CVE mới, chiến dịch quét hàng loạt). Managed rules giúp bạn không phải tự theo dõi mọi lỗ hổng một mình — đây là lý do WAF managed hữu ích với team nhỏ. Cloudflare Blog posts on application security often note that attacks shift over time (bots, new CVEs, mass scanning). Managed rules mean you are not tracking every vulnerability alone — which is why a managed WAF helps small teams. Cloudflare Blog posts on application security often note that attacks shift over time (bots, new CVEs, mass scanning). Managed rules mean you are not tracking every vulnerability alone — which is why a managed WAF helps small teams.

Hình 1: Bảo vệ dữ liệu từ thiết bị user đến website/API

Bảo vệ dữ liệu đang truyền (data in transit) Securing data in transit Securing data in transit

Bảo vệ data in transit với Gateway/DLP — inspect TLS traffic trước khi tới SaaS hoặc Internet. Data in transit is often considered vulnerable to interception or tampering during transmission. Data Loss Prevention (DLP) technologies can be used to inspect the contents of network traffic and block sensitive data from going to a risky destination. Data in transit is often considered vulnerable to interception or tampering during transmission. Data Loss Prevention (DLP) technologies can be used to inspect the contents of network traffic and block sensitive data from going to a risky destination.

Thuật ngữ: Concepts: Concepts: Gateway · DLP · TLS · CASB · Inline inspection

Sơ đồ chính thức ↗ Official diagram ↗ Official diagram ↗ · Bảo mật Security Security

WAF khác antivirus và khác “firewall văn phòng” thế nào? How is a WAF different from antivirus or an office firewall? How is a WAF different from antivirus or an office firewall?

Antivirus thường bảo vệ máy tính cá nhân khỏi file độc. Firewall văn phòng thường kiểm soát cổng mạng trong công ty. WAF tập trung vào HTTP/HTTPS — ngôn ngữ của website và API: đường dẫn, tham số, header, body request. Antivirus usually protects a personal computer from malicious files. An office firewall often controls network ports inside a company. A WAF focuses on HTTP/HTTPS — the language of websites and APIs: paths, parameters, headers, and request bodies. Antivirus usually protects a personal computer from malicious files. An office firewall often controls network ports inside a company. A WAF focuses on HTTP/HTTPS — the language of websites and APIs: paths, parameters, headers, and request bodies.

Ví dụ đơn giản: ai đó gửi form liên hệ nhưng nhét đoạn mã thử SQL injection vào ô “Họ tên”. Server yếu có thể hiểu nhầm và lộ dữ liệu. WAF nhận diện mẫu tấn công kiểu này và chặn trước. Bạn không cần nhớ tên kỹ thuật — chỉ cần biết: có một lớp lọc thông minh trước cửa hàng online của bạn. Simple example: someone submits a contact form but stuffs a SQL injection probe into the “Name” field. A weak server might mis-handle it and leak data. A WAF recognizes that attack pattern and blocks it. You do not need the jargon — just know a smarter filter sits in front of your storefront. Simple example: someone submits a contact form but stuffs a SQL injection probe into the “Name” field. A weak server might mis-handle it and leak data. A WAF recognizes that attack pattern and blocks it. You do not need the jargon — just know a smarter filter sits in front of your storefront.

WAF không thay thế việc cập nhật WordPress/plugin, sao lưu, hay phân quyền admin. Nó là lớp giảm rủi ro và mua thời gian. Kết hợp WAF + vá lỗi phần mềm + backup vẫn là bộ ba thực tế cho hầu hết website vừa và nhỏ. A WAF does not replace updating WordPress/plugins, backups, or admin least-privilege. It reduces risk and buys time. WAF + patching + backups remains a practical trio for most small and mid-size sites. A WAF does not replace updating WordPress/plugins, backups, or admin least-privilege. It reduces risk and buys time. WAF + patching + backups remains a practical trio for most small and mid-size sites.

Baseline nên bật trước khi “tinh chỉnh nâng cao” A baseline to enable before advanced tuning A baseline to enable before advanced tuning

Với người mới trên Cloudflare: đảm bảo DNS đang proxy (đám mây cam) cho hostname cần bảo vệ; bật managed rules ở mức hợp lý; cân nhắc rate limiting cho đường dẫn đăng nhập hoặc API nhạy cảm; theo dõi Security events vài ngày đầu để phát hiện chặn nhầm (false positive). For Cloudflare beginners: make sure DNS is proxied (orange cloud) for hostnames you want protected; enable managed rules at a sensible level; consider rate limiting on login paths or sensitive APIs; watch Security events for a few days to catch false positives. For Cloudflare beginners: make sure DNS is proxied (orange cloud) for hostnames you want protected; enable managed rules at a sensible level; consider rate limiting on login paths or sensitive APIs; watch Security events for a few days to catch false positives.

Nếu bạn bán hàng hoặc nhận form, hãy thử chính luồng thanh toán/đăng ký sau khi bật rule. An ninh tốt là an ninh bạn vẫn dùng được sản phẩm. Hub này có trang sản phẩm WAF, use case bảo vệ website, và lộ trình Application Services để bạn luyện theo từng bước. If you sell products or accept forms, test checkout/signup yourself after enabling rules. Good security is security you can still operate. This hub has a WAF product page, a protect-website use case, and the Application Services track for step-by-step practice. If you sell products or accept forms, test checkout/signup yourself after enabling rules. Good security is security you can still operate. This hub has a WAF product page, a protect-website use case, and the Application Services track for step-by-step practice.

Khi đã quen WAF, bài tiếp theo trong chuỗi blog — về Workers và Developer Platform — giúp bạn hiểu thêm cách chặn hoặc xử lý logic ngay tại edge. Còn nếu bạn quan tâm bot và AI abuse, hãy đọc các bài AI Gateway và AI security trong blog này. Once you are comfortable with WAF basics, the next posts in this series — Workers and the Developer Platform — show how logic can run at the edge. If you care about bots and AI abuse, continue with the AI Gateway and AI security posts in this blog. Once you are comfortable with WAF basics, the next posts in this series — Workers and the Developer Platform — show how logic can run at the edge. If you care about bots and AI abuse, continue with the AI Gateway and AI security posts in this blog.

Câu hỏi thường gặp Frequently asked questions Frequently asked questions

Website nhỏ có cần WAF không? Do small websites need a WAF? Do small websites need a WAF?

Có — tấn công tự động không phân biệt bạn là tập đoàn hay cửa hàng nhỏ. WAF managed giúp giảm rủi ro phổ biến với ít công vận hành hơn tự viết mọi rule. Yes — automated attacks do not care whether you are an enterprise or a small shop. A managed WAF reduces common risk with less ops work than writing every rule yourself. Yes — automated attacks do not care whether you are an enterprise or a small shop. A managed WAF reduces common risk with less ops work than writing every rule yourself.

WAF có làm chậm website không? Will a WAF slow my site down? Will a WAF slow my site down?

Trên Cloudflare, kiểm tra diễn ra trên mạng edge toàn cầu, thường đi kèm proxy/CDN. Trải nghiệm thực tế thường là bảo vệ + tốc độ tốt hơn so với origin trần, miễn là cấu hình hợp lý. On Cloudflare, inspection happens on the global edge network, usually alongside proxy/CDN. In practice you often get protection plus better performance than a bare origin — when configuration is sensible. On Cloudflare, inspection happens on the global edge network, usually alongside proxy/CDN. In practice you often get protection plus better performance than a bare origin — when configuration is sensible.

False positive là gì? What is a false positive? What is a false positive?

Khi WAF chặn nhầm request hợp lệ (ví dụ form có ký tự đặc biệt). Vì vậy cần theo dõi log vài ngày đầu và tinh chỉnh rule thay vì tắt hết bảo vệ. When the WAF blocks a legitimate request by mistake (for example a form with special characters). That is why you should watch logs early and tune rules instead of turning protection off entirely. When the WAF blocks a legitimate request by mistake (for example a form with special characters). That is why you should watch logs early and tune rules instead of turning protection off entirely.

Học tiếp trên hub (on-page backlinks) Keep learning on this hub (on-page links) Keep learning on this hub (on-page links)

Nguồn tham khảo (blog.cloudflare.com) Sources (blog.cloudflare.com) Sources (blog.cloudflare.com)

Nội dung được viết lại để dễ hiểu hơn; luôn đọc bài gốc trên blog.cloudflare.com và docs chính thức khi cần chi tiết kỹ thuật hoặc cập nhật mới nhất. Content is rewritten for clarity; always read the original posts on blog.cloudflare.com and official docs for technical detail or the latest updates. Content is rewritten for clarity; always read the original posts on blog.cloudflare.com and official docs for technical detail or the latest updates.

What is a CDN? Understanding Cloudflare Cache in plain language
CDN CDN CDN Cơ bản Entry កម្រិតចាប់ផ្តើម ~6 phút ~6 min ~6 នាទី

CDN là gì? Hiểu Cloudflare Cache như đang giải thích cho bạn bè What is a CDN? Understanding Cloudflare Cache in plain language What is a CDN? Understanding Cloudflare Cache in plain language

CDN giống mạng kho hàng gần người dùng. Cloudflare Cache giữ bản sao nội dung tĩnh gần bạn — trang mở nhanh hơn, server gốc đỡ “mệt”. Think of a CDN as warehouses near your users. Cloudflare Cache keeps copies of static content close by — pages load faster and origin servers work less. Think of a CDN as warehouses near your users. Cloudflare Cache keeps copies of static content close by — pages load faster and origin servers work less.

Đọc bài → Read post → អានអត្ថបទ →

What is AI Gateway? Control, observe, and protect AI traffic on Cloudflare
AI AI AI Trung cấp Intermediate កម្រិតមធ្យម ~8 phút ~8 min ~8 នាទី

AI Gateway là gì? Kiểm soát, quan sát và bảo vệ traffic AI trên Cloudflare What is AI Gateway? Control, observe, and protect AI traffic on Cloudflare What is AI Gateway? Control, observe, and protect AI traffic on Cloudflare

AI Gateway giống trung tâm điều phối cuộc gọi tới các “chuyên gia AI”: ghi nhật ký, giới hạn, đổi hướng — để bạn không mất kiểm soát khi app lớn dần. AI Gateway is like a switchboard for calls to AI specialists: logging, limits, routing — so you keep control as the app grows. AI Gateway is like a switchboard for calls to AI specialists: logging, limits, routing — so you keep control as the app grows.

Đọc bài → Read post → អានអត្ថបទ →

What are Cloudflare Workers? Serverless at the edge, explained simply
Workers Workers Workers Cơ bản Entry កម្រិតចាប់ផ្តើម ~7 phút ~7 min ~7 នាទី

Cloudflare Workers là gì? Serverless ở “mép mạng” giải thích đơn giản What are Cloudflare Workers? Serverless at the edge, explained simply What are Cloudflare Workers? Serverless at the edge, explained simply

Workers giống thuê “người trực” ngay gần khách hàng: nhận request, xử lý nhanh, trả kết quả — bạn không phải tự mua và bảo trì cả tòa nhà server. Workers are like stationing helpers near customers: take a request, handle it quickly, return a result — without buying and maintaining a whole server building. Workers are like stationing helpers near customers: take a request, handle it quickly, return a result — without buying and maintaining a whole server building.

Đọc bài → Read post → អានអត្ថបទ →

Xem tất cả bài blog Browse all blog posts Browse all blog posts

Chuỗi bài AI · Security · CDN · Workers · Developer Platform — viết lại cho người mới và trung cấp. AI · Security · CDN · Workers · Developer Platform — rewritten for entry and intermediate learners. AI · Security · CDN · Workers · Developer Platform — rewritten for entry and intermediate learners.