Module 6 — DLP (Data Loss Prevention)
Mục tiêu: Phát hiện dữ liệu nhạy cảm (số thẻ tín dụng, SSN, khóa API, mã nguồn, mẫu tùy chỉnh) trong lưu lượng web và ngăn nó rời đi tới những nơi sai.
|
|
| 👤 Ai làm việc này |
Đội bảo mật |
| ⏱️ Thời gian |
~45 phút thiết lập + 1–2 tuần giám sát trước khi thực thi |
| 🎯 Kết thúc bạn sẽ có |
Một DLP profile phát hiện dữ liệu nhạy cảm, và một chính sách chặn có phạm vi trên các đích rủi ro cao |
| ✋ Trước khi bắt đầu |
Đã xong Module 5 với TLS decryption ON (DLP chỉ thấy những gì Gateway giải mã được). Cần gói Enterprise. |
⚠️ Kiểm tra gói: Nếu bạn không có Enterprise, tùy chọn DLP Profile sẽ không xuất hiện trong chính sách. Xác nhận gói của bạn trước khi bắt đầu.
🧭 Quy tắc vàng cho DLP: giám sát trước, chặn sau. Bạn sẽ chạy ở chế độ "chỉ ghi log" một hoặc hai tuần để thấy những gì thực sự đang chảy, loại bỏ cảnh báo giả, rồi mới bật chặn. Lao thẳng vào Block gây lũ dương tính giả và người dùng giận dữ.
Phần A — Chọn những gì cần phát hiện (một profile)
Một profile là một bó thứ cần tìm. Cloudflare cung cấp sẵn các profile.
- 👉 Zero Trust → DLP → DLP Profiles.
- 📺 Bạn sẽ thấy: Một danh sách predefined profiles như Credentials and Secrets, Financial Information, Personal Identifiable Information (PII), Source Code.
- 👉 Nhấp một predefined profile để xem — vd. Financial Information.
- 📺 Bên trong, bạn sẽ thấy từng detection entries (Credit Card Number, IBAN, v.v.), mỗi cái bật/tắt được.
- 👉 Tạm thời, để predefined profile như cũ — bạn sẽ tham chiếu nó ngay sau.
(Tùy chọn) Xây một custom profile
- 👉 Trên trang DLP Profiles, nhấp Create profile.
- ⌨️ Đặt tên (vd.
Acme Project Codenames).
- 👉 Add entries — chọn từ:
- Predefined detectors (tái dùng mẫu của Cloudflare)
- Custom regex (mẫu của bạn, vd. định dạng mã nhân viên
EMP-\d{6})
- Dictionaries / Exact Data Match (tải lên các giá trị chính xác cần theo dõi)
- 👉 Nhấp Save.
Phần B — Điều chỉnh độ nhạy (giảm cảnh báo giả)
Hai núm điều khiển mức DLP dễ kích hoạt. Đặt chúng trên profile/entry:
| Núm |
Ở đâu |
Nó làm gì |
Khuyến nghị bắt đầu |
| Confidence |
theo từng detection entry |
DLP phải chắc đến mức nào. Nó tăng confidence khi các từ ngữ cảnh ở gần (vd. từ "SSN" cạnh một số 9 chữ số). |
Medium, tăng lên High nếu ồn |
| Minimum match count |
theo từng profile/entry |
Cần bao nhiêu lần khớp trước khi kích hoạt (vd. 10 = cần 11+) |
1 cho rủi ro cao, cao hơn để cắt nhiễu |
Cũng có sẵn dưới DLP → Settings:
- 👉 AI context analysis — bật On; một mô hình đánh giá ngữ cảnh xung quanh để tăng độ chính xác.
- 👉 Optical Character Recognition (OCR) — bật On để phát hiện văn bản nhạy cảm bên trong ảnh (
.jpg/.png, 4 KB–1 MB).
💡 Lưu ý: Profile PII Record đặc biệt — nó chỉ kích hoạt khi 3 hoặc nhiều loại PII khác nhau xuất hiện gần nhau, giúp không gắn cờ một số điện thoại đơn lẻ.
Phần C — Giám sát trước (chỉ ghi log)
Tạo một chính sách phát hiện nhưng cho phép, để bạn thấy những gì đang chảy mà không làm gián đoạn ai.
- 👉 Zero Trust → Gateway → Firewall Policies → HTTP → Add a policy.
- ⌨️ Name:
DLP MONITOR - financial data.
- 👉 Rule: Selector DLP Profile → in → chọn Financial Information.
- 👉 Action: Allow (việc này vẫn ghi log phát hiện).
- 👉 Nhấp Create policy.
Theo dõi kết quả
- 👉 Sau một hoặc hai ngày, vào Gateway → Logs → HTTP (lọc theo DLP profile của bạn) — hoặc DLP → Logs.
- 📺 Bạn sẽ thấy dữ liệu nhạy cảm đang được gửi đi đâu: người dùng nào, đích nào.
- 👉 Điều chỉnh: nếu một ứng dụng nội bộ đáng tin bị gắn cờ liên tục, thêm chính sách Do Not Scan cho nó, hoặc tăng confidence lên High.
✅ Điểm kiểm tra: Bạn thấy được các phát hiện thật, và đã loại các dương tính giả rõ ràng.
Phần D — Thực thi (mẫu hai chính sách được khuyến nghị)
Giờ hãy chặn các luồng thực sự rủi ro trong khi vẫn giữ tầm nhìn với phần còn lại. Mẫu Cloudflare khuyến nghị là hai chính sách:
Chính sách 1 — tiếp tục ghi log mọi thứ (confidence thấp, allow)
(Đây là chính sách giám sát từ Phần C — để nó chạy nhằm có tầm nhìn liên tục.)
Chính sách 2 — chặn các trường hợp confidence cao, rủi ro cao
- 👉 Add a policy tên
DLP BLOCK - financial to personal storage.
- 👉 Rules (kết hợp bằng And):
| Selector |
Operator |
Value |
| DLP Profile |
in |
Financial Information (đặt High confidence) |
| Destination Domain |
in |
dropbox.com, wetransfer.com, drive.google.com (lưu trữ cá nhân) |
| User Group |
in |
Finance (tùy chọn — giới hạn cho một nhóm) |
- 👉 Action: Block.
- 👉 Sắp xếp NÓ PHÍA TRÊN chính sách giám sát (chính sách đi từ trên xuống).
- 👉 Nhấp Create policy.
⚠️ Lưu ý: Luôn thu hẹp phạm vi lệnh chặn (theo đích, ứng dụng, hoặc nhóm). Một lệnh rộng "chặn mọi dữ liệu tài chính ở mọi nơi" sẽ gắn cờ các công cụ nội bộ hợp lệ và làm người dùng khó chịu.
Phần E — Thử nghiệm an toàn
- 👉 Trên một thiết bị thử nghiệm, tạo một tệp thử vô hại chứa số thẻ tín dụng thử nghiệm giả (vd. số thử chuẩn
4111 1111 1111 1111) — không bao giờ dùng dữ liệu thật.
- 👉 Thử tải nó lên một trong các đích bị chặn (vd. Dropbox cá nhân).
- 📺 Bạn sẽ thấy: Lần tải lên bị chặn và một trang/thông báo chặn xuất hiện.
- 👉 Kiểm tra Gateway → Logs: sự kiện hiện DLP profile đã khớp và confidence.
✅ Điểm kiểm tra: Dữ liệu thử nhạy cảm bị chặn tới các đích rủi ro, được cho phép (nhưng ghi log) ở nơi khác, và hiện trong log. 🎉
✅ Hoàn thành Module 6!
Bây giờ bạn có:
- ✅ Một DLP profile (predefined và/hoặc custom) phát hiện dữ liệu nhạy cảm
- ✅ Độ nhạy đã điều chỉnh (confidence, match count, AI context, OCR)
- ✅ Một chính sách giám sát cho tầm nhìn liên tục
- ✅ Một chính sách chặn có phạm vi trên các đích rủi ro cao
- ✅ Một bài thử an toàn đã xác minh
Khắc phục nhanh
| Vấn đề |
Cách khắc phục |
| Thiếu tùy chọn DLP Profile trong chính sách |
Bạn không ở gói Enterprise, hoặc vai trò quản trị thiếu quyền DLP |
| Không phát hiện được gì |
TLS decryption đang tắt (Module 5 Phần C) — DLP không đọc được phần thân đã mã hóa |
| Quá nhiều dương tính giả |
Tăng Confidence lên High, tăng Minimum match count, hoặc thu hẹp chính sách chặt hơn |
| Một ứng dụng đáng tin liên tục bị gắn cờ |
Thêm chính sách HTTP Do Not Scan cho ứng dụng đó |
| Nó chặn các lần tải lên nghiệp vụ hợp lệ |
Thu hẹp phạm vi Destination/Group; đưa chính sách chặn xuống dưới một Allow cho các đích đã phê duyệt |
Bạn sẽ khám phá và quản trị việc dùng công cụ AI như ChatGPT, Gemini và Claude.
Module 6 — DLP (Data Loss Prevention)
Goal: Detect sensitive data (credit-card numbers, SSNs, API keys, source code, custom patterns) in web traffic and stop it from leaving to the wrong places.
|
|
| 👤 Who does this |
Security team |
| ⏱️ Time |
~45 minutes setup + 1–2 weeks monitoring before enforcing |
| 🎯 You'll finish with |
A DLP profile detecting sensitive data, and a scoped block policy on high-risk destinations |
| ✋ Before you begin |
Module 5 done with TLS decryption ON (DLP can only see what Gateway can decrypt). Requires Enterprise plan. |
⚠️ Plan check: If you don't have Enterprise, the DLP Profile option won't appear in your policies. Confirm your plan before starting.
🧭 The golden rule for DLP: monitor first, block second. You'll run in "log only" mode for a week or two to see what's really flowing, tune out false alarms, then turn on blocking. Rushing straight to Block causes a flood of false positives and angry users.
Part A — Choose what to detect (a profile)
A profile is a bundle of things to look for. Cloudflare ships ready-made ones.
- 👉 Zero Trust → DLP → DLP Profiles.
- 📺 What you'll see: A list of predefined profiles like Credentials and Secrets, Financial Information, Personal Identifiable Information (PII), Source Code.
- 👉 Click a predefined profile to inspect it — e.g. Financial Information.
- 📺 Inside, you'll see individual detection entries (Credit Card Number, IBAN, etc.), each toggleable.
- 👉 For now, leave a predefined profile as-is — you'll reference it shortly.
(Optional) Build a custom profile
- 👉 On the DLP Profiles page, click Create profile.
- ⌨️ Name it (e.g.
Acme Project Codenames).
- 👉 Add entries — choose from:
- Predefined detectors (reuse Cloudflare's patterns)
- Custom regex (your own pattern, e.g. an employee-ID format
EMP-\d{6})
- Dictionaries / Exact Data Match (upload exact values to watch for)
- 👉 Click Save.
Part B — Tune sensitivity (reduce false alarms)
Two dials control how trigger-happy DLP is. Set these on the profile/entry:
| Dial |
Where |
What it does |
Recommended start |
| Confidence |
per detection entry |
How sure DLP must be. It raises confidence when context words are nearby (e.g. the word "SSN" next to a 9-digit number). |
Medium, raise to High if noisy |
| Minimum match count |
per profile/entry |
How many matches before it triggers (e.g. 10 = needs 11+) |
1 for high-risk, higher to cut noise |
Also available under DLP → Settings:
- 👉 AI context analysis — turn On; a model judges surrounding context to improve accuracy.
- 👉 Optical Character Recognition (OCR) — turn On to detect sensitive text inside images (
.jpg/.png, 4 KB–1 MB).
💡 Note: The PII Record profile is special — it only fires when 3 or more different PII types appear close together, which keeps it from flagging a single phone number.
Part C — Monitor first (log-only)
Create a policy that detects but allows, so you can see what's flowing without disrupting anyone.
- 👉 Zero Trust → Gateway → Firewall Policies → HTTP → Add a policy.
- ⌨️ Name:
DLP MONITOR - financial data.
- 👉 Rule: Selector DLP Profile → in → choose Financial Information.
- 👉 Action: Allow (this still logs the detection).
- 👉 Click Create policy.
Watch the results
- 👉 After a day or two, go to Gateway → Logs → HTTP (filter by your DLP profile) — or DLP → Logs.
- 📺 You'll see where sensitive data is being sent: which users, which destinations.
- 👉 Tune: if a trusted internal app is constantly flagged, add a Do Not Scan policy for it, or raise the confidence to High.
✅ Checkpoint: You can see real detections, and you've tuned out the obvious false positives.
Part D — Enforce (the recommended two-policy pattern)
Now block the genuinely risky flows while keeping visibility on the rest. Cloudflare's recommended pattern is two policies:
Policy 1 — keep logging everything (low confidence, allow)
(This is your monitor policy from Part C — leave it running for ongoing visibility.)
Policy 2 — block the high-confidence, high-risk cases
- 👉 Add a policy named
DLP BLOCK - financial to personal storage.
- 👉 Rules (combine with And):
| Selector |
Operator |
Value |
| DLP Profile |
in |
Financial Information (set to High confidence) |
| Destination Domain |
in |
dropbox.com, wetransfer.com, drive.google.com (personal storage) |
| User Group |
in |
Finance (optional — scope to a team) |
- 👉 Action: Block.
- 👉 Order it ABOVE the monitor policy (policies are top-down).
- 👉 Click Create policy.
⚠️ Watch out: Always scope the block (by destination, app, or group). A broad "block all financial data everywhere" will flag legitimate internal tools and frustrate users.
Part E — Test it safely
- 👉 On a pilot device, create a harmless test file containing a fake credit-card test number (e.g. the standard test number
4111 1111 1111 1111) — never use real data.
- 👉 Try to upload it to one of the blocked destinations (e.g. a personal Dropbox).
- 📺 What you'll see: The upload is blocked and a block page/notice appears.
- 👉 Check Gateway → Logs: the event shows the matched DLP profile and confidence.
✅ Checkpoint: Sensitive test data is blocked to risky destinations, allowed (but logged) elsewhere, and visible in logs. 🎉
✅ Module 6 complete!
You now have:
- ✅ A DLP profile (predefined and/or custom) detecting sensitive data
- ✅ Sensitivity tuned (confidence, match count, AI context, OCR)
- ✅ A monitor policy for ongoing visibility
- ✅ A scoped block policy on high-risk destinations
- ✅ A verified safe test
Quick troubleshooting
| Problem |
Fix |
| DLP Profile option missing in the policy |
You're not on Enterprise, or your admin role lacks DLP rights |
| Nothing is detected |
TLS decryption is off (Module 5 Part C) — DLP can't read encrypted bodies |
| Too many false positives |
Raise Confidence to High, increase Minimum match count, or scope the policy tighter |
| A trusted app keeps getting flagged |
Add a Do Not Scan HTTP policy for that application |
| It blocks legitimate business uploads |
Narrow the Destination/Group scope; move the block policy below an Allow for approved destinations |
You'll discover and govern AI tool usage like ChatGPT, Gemini, and Claude.
Nguồn cộng đồng — không phải tài liệu chính thức của Cloudflare: https://zerotrust.cfsase.workers.dev
Community source — not an official Cloudflare publication: https://zerotrust.cfsase.workers.dev