Lộ trình đang học Current learning path Current learning path

Cloudflare One Cloudflare One Cloudflare One

Bảo vệ users, access, SaaS và networks — follow-along từ tài khoản đến go-live. Secure users, access, SaaS, and networks — follow along from account to go-live. Secure users, access, SaaS, and networks — follow along from account to go-live.

Về trang lộ trình Track home Track home

Phần 6: DLP — bảo vệ dữ liệu Part 6: DLP — data protection Part 6: DLP — data protection · Bài 2/2 Lesson 2/2 មេរៀន 2/2

Enforce trên destination rủi ro cao Enforce on high-risk destinations Enforce on high-risk destinations

Module 6 — DLP (Data Loss Prevention)

Mục tiêu: Phát hiện dữ liệu nhạy cảm (số thẻ tín dụng, SSN, khóa API, mã nguồn, mẫu tùy chỉnh) trong lưu lượng web và ngăn nó rời đi tới những nơi sai.

👤 Ai làm việc này Đội bảo mật
⏱️ Thời gian ~45 phút thiết lập + 1–2 tuần giám sát trước khi thực thi
🎯 Kết thúc bạn sẽ có Một DLP profile phát hiện dữ liệu nhạy cảm, và một chính sách chặn có phạm vi trên các đích rủi ro cao
✋ Trước khi bắt đầu Đã xong Module 5 với TLS decryption ON (DLP chỉ thấy những gì Gateway giải mã được). Cần gói Enterprise.

⚠️ Kiểm tra gói: Nếu bạn không có Enterprise, tùy chọn DLP Profile sẽ không xuất hiện trong chính sách. Xác nhận gói của bạn trước khi bắt đầu.

🧭 Quy tắc vàng cho DLP: giám sát trước, chặn sau. Bạn sẽ chạy ở chế độ "chỉ ghi log" một hoặc hai tuần để thấy những gì thực sự đang chảy, loại bỏ cảnh báo giả, rồi mới bật chặn. Lao thẳng vào Block gây lũ dương tính giả và người dùng giận dữ.


Phần A — Chọn những gì cần phát hiện (một profile)

Một profile là một bó thứ cần tìm. Cloudflare cung cấp sẵn các profile.

  1. 👉 Zero Trust → DLP → DLP Profiles.
  2. 📺 Bạn sẽ thấy: Một danh sách predefined profiles như Credentials and Secrets, Financial Information, Personal Identifiable Information (PII), Source Code.
  3. 👉 Nhấp một predefined profile để xem — vd. Financial Information.
  4. 📺 Bên trong, bạn sẽ thấy từng detection entries (Credit Card Number, IBAN, v.v.), mỗi cái bật/tắt được.
  5. 👉 Tạm thời, để predefined profile như cũ — bạn sẽ tham chiếu nó ngay sau.

(Tùy chọn) Xây một custom profile

  1. 👉 Trên trang DLP Profiles, nhấp Create profile.
  2. ⌨️ Đặt tên (vd. Acme Project Codenames).
  3. 👉 Add entries — chọn từ:
    • Predefined detectors (tái dùng mẫu của Cloudflare)
    • Custom regex (mẫu của bạn, vd. định dạng mã nhân viên EMP-\d{6})
    • Dictionaries / Exact Data Match (tải lên các giá trị chính xác cần theo dõi)
  4. 👉 Nhấp Save.

Phần B — Điều chỉnh độ nhạy (giảm cảnh báo giả)

Hai núm điều khiển mức DLP dễ kích hoạt. Đặt chúng trên profile/entry:

Núm Ở đâu Nó làm gì Khuyến nghị bắt đầu
Confidence theo từng detection entry DLP phải chắc đến mức nào. Nó tăng confidence khi các từ ngữ cảnh ở gần (vd. từ "SSN" cạnh một số 9 chữ số). Medium, tăng lên High nếu ồn
Minimum match count theo từng profile/entry Cần bao nhiêu lần khớp trước khi kích hoạt (vd. 10 = cần 11+) 1 cho rủi ro cao, cao hơn để cắt nhiễu

Cũng có sẵn dưới DLP → Settings:

  • 👉 AI context analysis — bật On; một mô hình đánh giá ngữ cảnh xung quanh để tăng độ chính xác.
  • 👉 Optical Character Recognition (OCR) — bật On để phát hiện văn bản nhạy cảm bên trong ảnh (.jpg/.png, 4 KB–1 MB).

💡 Lưu ý: Profile PII Record đặc biệt — nó chỉ kích hoạt khi 3 hoặc nhiều loại PII khác nhau xuất hiện gần nhau, giúp không gắn cờ một số điện thoại đơn lẻ.


Phần C — Giám sát trước (chỉ ghi log)

Tạo một chính sách phát hiện nhưng cho phép, để bạn thấy những gì đang chảy mà không làm gián đoạn ai.

  1. 👉 Zero Trust → Gateway → Firewall Policies → HTTP → Add a policy.
  2. ⌨️ Name: DLP MONITOR - financial data.
  3. 👉 Rule: Selector DLP Profile → in → chọn Financial Information.
  4. 👉 Action: Allow (việc này vẫn ghi log phát hiện).
  5. 👉 Nhấp Create policy.

Theo dõi kết quả

  1. 👉 Sau một hoặc hai ngày, vào Gateway → Logs → HTTP (lọc theo DLP profile của bạn) — hoặc DLP → Logs.
  2. 📺 Bạn sẽ thấy dữ liệu nhạy cảm đang được gửi đi đâu: người dùng nào, đích nào.
  3. 👉 Điều chỉnh: nếu một ứng dụng nội bộ đáng tin bị gắn cờ liên tục, thêm chính sách Do Not Scan cho nó, hoặc tăng confidence lên High.

✅ Điểm kiểm tra: Bạn thấy được các phát hiện thật, và đã loại các dương tính giả rõ ràng.


Giờ hãy chặn các luồng thực sự rủi ro trong khi vẫn giữ tầm nhìn với phần còn lại. Mẫu Cloudflare khuyến nghị là hai chính sách:

Chính sách 1 — tiếp tục ghi log mọi thứ (confidence thấp, allow)

(Đây là chính sách giám sát từ Phần C — để nó chạy nhằm có tầm nhìn liên tục.)

Chính sách 2 — chặn các trường hợp confidence cao, rủi ro cao

  1. 👉 Add a policy tên DLP BLOCK - financial to personal storage.
  2. 👉 Rules (kết hợp bằng And):
    Selector Operator Value
    DLP Profile in Financial Information (đặt High confidence)
    Destination Domain in dropbox.com, wetransfer.com, drive.google.com (lưu trữ cá nhân)
    User Group in Finance (tùy chọn — giới hạn cho một nhóm)
  3. 👉 Action: Block.
  4. 👉 Sắp xếp NÓ PHÍA TRÊN chính sách giám sát (chính sách đi từ trên xuống).
  5. 👉 Nhấp Create policy.

⚠️ Lưu ý: Luôn thu hẹp phạm vi lệnh chặn (theo đích, ứng dụng, hoặc nhóm). Một lệnh rộng "chặn mọi dữ liệu tài chính ở mọi nơi" sẽ gắn cờ các công cụ nội bộ hợp lệ và làm người dùng khó chịu.


Phần E — Thử nghiệm an toàn

  1. 👉 Trên một thiết bị thử nghiệm, tạo một tệp thử vô hại chứa số thẻ tín dụng thử nghiệm giả (vd. số thử chuẩn 4111 1111 1111 1111) — không bao giờ dùng dữ liệu thật.
  2. 👉 Thử tải nó lên một trong các đích bị chặn (vd. Dropbox cá nhân).
  3. 📺 Bạn sẽ thấy: Lần tải lên bị chặn và một trang/thông báo chặn xuất hiện.
  4. 👉 Kiểm tra Gateway → Logs: sự kiện hiện DLP profile đã khớp và confidence.

✅ Điểm kiểm tra: Dữ liệu thử nhạy cảm bị chặn tới các đích rủi ro, được cho phép (nhưng ghi log) ở nơi khác, và hiện trong log. 🎉


✅ Hoàn thành Module 6!

Bây giờ bạn có:

  • ✅ Một DLP profile (predefined và/hoặc custom) phát hiện dữ liệu nhạy cảm
  • ✅ Độ nhạy đã điều chỉnh (confidence, match count, AI context, OCR)
  • ✅ Một chính sách giám sát cho tầm nhìn liên tục
  • ✅ Một chính sách chặn có phạm vi trên các đích rủi ro cao
  • ✅ Một bài thử an toàn đã xác minh

Khắc phục nhanh

Vấn đề Cách khắc phục
Thiếu tùy chọn DLP Profile trong chính sách Bạn không ở gói Enterprise, hoặc vai trò quản trị thiếu quyền DLP
Không phát hiện được gì TLS decryption đang tắt (Module 5 Phần C) — DLP không đọc được phần thân đã mã hóa
Quá nhiều dương tính giả Tăng Confidence lên High, tăng Minimum match count, hoặc thu hẹp chính sách chặt hơn
Một ứng dụng đáng tin liên tục bị gắn cờ Thêm chính sách HTTP Do Not Scan cho ứng dụng đó
Nó chặn các lần tải lên nghiệp vụ hợp lệ Thu hẹp phạm vi Destination/Group; đưa chính sách chặn xuống dưới một Allow cho các đích đã phê duyệt

👉 Tiếp theo: Module 7 — AI Controls

Bạn sẽ khám phá và quản trị việc dùng công cụ AI như ChatGPT, Gemini và Claude.

Module 6 — DLP (Data Loss Prevention)

Goal: Detect sensitive data (credit-card numbers, SSNs, API keys, source code, custom patterns) in web traffic and stop it from leaving to the wrong places.

👤 Who does this Security team
⏱️ Time ~45 minutes setup + 1–2 weeks monitoring before enforcing
🎯 You'll finish with A DLP profile detecting sensitive data, and a scoped block policy on high-risk destinations
✋ Before you begin Module 5 done with TLS decryption ON (DLP can only see what Gateway can decrypt). Requires Enterprise plan.

⚠️ Plan check: If you don't have Enterprise, the DLP Profile option won't appear in your policies. Confirm your plan before starting.

🧭 The golden rule for DLP: monitor first, block second. You'll run in "log only" mode for a week or two to see what's really flowing, tune out false alarms, then turn on blocking. Rushing straight to Block causes a flood of false positives and angry users.


Part A — Choose what to detect (a profile)

A profile is a bundle of things to look for. Cloudflare ships ready-made ones.

  1. 👉 Zero Trust → DLP → DLP Profiles.
  2. 📺 What you'll see: A list of predefined profiles like Credentials and Secrets, Financial Information, Personal Identifiable Information (PII), Source Code.
  3. 👉 Click a predefined profile to inspect it — e.g. Financial Information.
  4. 📺 Inside, you'll see individual detection entries (Credit Card Number, IBAN, etc.), each toggleable.
  5. 👉 For now, leave a predefined profile as-is — you'll reference it shortly.

(Optional) Build a custom profile

  1. 👉 On the DLP Profiles page, click Create profile.
  2. ⌨️ Name it (e.g. Acme Project Codenames).
  3. 👉 Add entries — choose from:
    • Predefined detectors (reuse Cloudflare's patterns)
    • Custom regex (your own pattern, e.g. an employee-ID format EMP-\d{6})
    • Dictionaries / Exact Data Match (upload exact values to watch for)
  4. 👉 Click Save.

Part B — Tune sensitivity (reduce false alarms)

Two dials control how trigger-happy DLP is. Set these on the profile/entry:

Dial Where What it does Recommended start
Confidence per detection entry How sure DLP must be. It raises confidence when context words are nearby (e.g. the word "SSN" next to a 9-digit number). Medium, raise to High if noisy
Minimum match count per profile/entry How many matches before it triggers (e.g. 10 = needs 11+) 1 for high-risk, higher to cut noise

Also available under DLP → Settings:

  • 👉 AI context analysis — turn On; a model judges surrounding context to improve accuracy.
  • 👉 Optical Character Recognition (OCR) — turn On to detect sensitive text inside images (.jpg/.png, 4 KB–1 MB).

💡 Note: The PII Record profile is special — it only fires when 3 or more different PII types appear close together, which keeps it from flagging a single phone number.


Part C — Monitor first (log-only)

Create a policy that detects but allows, so you can see what's flowing without disrupting anyone.

  1. 👉 Zero Trust → Gateway → Firewall Policies → HTTP → Add a policy.
  2. ⌨️ Name: DLP MONITOR - financial data.
  3. 👉 Rule: Selector DLP Profile → in → choose Financial Information.
  4. 👉 Action: Allow (this still logs the detection).
  5. 👉 Click Create policy.

Watch the results

  1. 👉 After a day or two, go to Gateway → Logs → HTTP (filter by your DLP profile) — or DLP → Logs.
  2. 📺 You'll see where sensitive data is being sent: which users, which destinations.
  3. 👉 Tune: if a trusted internal app is constantly flagged, add a Do Not Scan policy for it, or raise the confidence to High.

✅ Checkpoint: You can see real detections, and you've tuned out the obvious false positives.


Now block the genuinely risky flows while keeping visibility on the rest. Cloudflare's recommended pattern is two policies:

Policy 1 — keep logging everything (low confidence, allow)

(This is your monitor policy from Part C — leave it running for ongoing visibility.)

Policy 2 — block the high-confidence, high-risk cases

  1. 👉 Add a policy named DLP BLOCK - financial to personal storage.
  2. 👉 Rules (combine with And):
    Selector Operator Value
    DLP Profile in Financial Information (set to High confidence)
    Destination Domain in dropbox.com, wetransfer.com, drive.google.com (personal storage)
    User Group in Finance (optional — scope to a team)
  3. 👉 Action: Block.
  4. 👉 Order it ABOVE the monitor policy (policies are top-down).
  5. 👉 Click Create policy.

⚠️ Watch out: Always scope the block (by destination, app, or group). A broad "block all financial data everywhere" will flag legitimate internal tools and frustrate users.


Part E — Test it safely

  1. 👉 On a pilot device, create a harmless test file containing a fake credit-card test number (e.g. the standard test number 4111 1111 1111 1111) — never use real data.
  2. 👉 Try to upload it to one of the blocked destinations (e.g. a personal Dropbox).
  3. 📺 What you'll see: The upload is blocked and a block page/notice appears.
  4. 👉 Check Gateway → Logs: the event shows the matched DLP profile and confidence.

✅ Checkpoint: Sensitive test data is blocked to risky destinations, allowed (but logged) elsewhere, and visible in logs. 🎉


✅ Module 6 complete!

You now have:

  • ✅ A DLP profile (predefined and/or custom) detecting sensitive data
  • ✅ Sensitivity tuned (confidence, match count, AI context, OCR)
  • ✅ A monitor policy for ongoing visibility
  • ✅ A scoped block policy on high-risk destinations
  • ✅ A verified safe test

Quick troubleshooting

Problem Fix
DLP Profile option missing in the policy You're not on Enterprise, or your admin role lacks DLP rights
Nothing is detected TLS decryption is off (Module 5 Part C) — DLP can't read encrypted bodies
Too many false positives Raise Confidence to High, increase Minimum match count, or scope the policy tighter
A trusted app keeps getting flagged Add a Do Not Scan HTTP policy for that application
It blocks legitimate business uploads Narrow the Destination/Group scope; move the block policy below an Allow for approved destinations

👉 Next: Module 7 — AI Controls

You'll discover and govern AI tool usage like ChatGPT, Gemini, and Claude.

Nguồn cộng đồng — không phải tài liệu chính thức của Cloudflare: https://zerotrust.cfsase.workers.dev Community source — not an official Cloudflare publication: https://zerotrust.cfsase.workers.dev

Ví dụ triển khai (Cloudflare Resources) Deployment examples (Cloudflare Resources) Deployment examples (Cloudflare Resources)

Ví dụ chính thức từ Cloudflare Resources — gợi ý theo chủ đề bài học trong lộ trình này. Official examples from Cloudflare Resources — matched to this lesson within this path. Official examples from Cloudflare Resources — matched to this lesson within this path.

Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Access một ứng dụng web thông qua tên máy chủ riêng của nó mà không có Cloudflare One Client Access a web application via its private hostname without the Cloudflare One Client Access កម្មវិធីបណ្តាញតាមរយៈឈ្មោះម៉ាស៊ីនឯកជនរបស់វាដោយគ្មាន Cloudflare One Client

Với Cloudflare cách ly trình duyệt và các chính sách giải quyết, người dùng có thể kết nối với các ứng dụng dựa trên web riêng tư thông qua tên máy chủ riêng của họ.

With Cloudflare Browser Isolation and resolver policies, users can connect to private web-based applications via their private hostnames.

ជាមួយនឹង Cloudflare គោលការណ៍ញែកកម្មវិធីរុករក និងដំណោះស្រាយ អ្នកប្រើប្រាស់អាចភ្ជាប់ទៅកម្មវិធីដែលមានមូលដ្ឋានលើបណ្តាញឯកជនតាមរយៈឈ្មោះម៉ាស៊ីនឯកជនរបស់ពួកគេ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Access và bảo mật cơ sở dữ liệu MySQL bằng cách sử dụng Cloudflare Tunnel và chính sách mạng Access and secure a MySQL database using Cloudflare Tunnel and network policies Access និងធានានូវមូលដ្ឋានទិន្នន័យ MySQL ដោយប្រើ Cloudflare Tunnel និងគោលការណ៍បណ្តាញ

Sử dụng mạng riêng của Cloudflare Tunnel, người dùng có thể kết nối với các ứng dụng dựa trên TCP/UDP, chẳng hạn như cơ sở dữ liệu. Bạn có thể thiết lập chính sách mạng thực hiện các điều khiển zero trust để xác định ai và những gì access có thể sử dụng các ứng dụng đó bằng cách sử dụng Cloudflare One Client.

Using Cloudflare Tunnel's private networks, users can connect to arbitrary non-browser based TCP/UDP applications, like databases. You can set up network policies that implement zero trust controls to define who and what can access those applications using the Cloudflare One Client.

ដោយប្រើបណ្តាញឯកជនរបស់ Cloudflare Tunnel អ្នកប្រើប្រាស់អាចភ្ជាប់ទៅកម្មវិធី TCP/UDP ដែលមានមូលដ្ឋានលើកម្មវិធីរុករកតាមអំពើចិត្ត ដូចជាមូលដ្ឋានទិន្នន័យជាដើម។ អ្នកអាចរៀបចំគោលការណ៍បណ្តាញដែលអនុវត្តការគ្រប់គ្រង zero trust ដើម្បីកំណត់ថាតើនរណា និងអ្វីដែលអាច access កម្មវិធីទាំងនោះដោយប្រើ Cloudflare One Client ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Tạo API thành access D1 bằng cách sử dụng Proxy Worker Build an API to access D1 using a proxy Worker បង្កើត API ទៅ access D1 ដោយប្រើប្រូកស៊ីកម្មករ

Hướng dẫn này cho thấy cách tạo một API cho phép bạn chạy truy vấn an toàn chống lại một cơ sở dữ liệu D1. API có thể được sử dụng để tùy chỉnh các điều khiển access và/hoặc giới hạn các bảng có thể được truy vấn.

This tutorial shows how to create an API that allows you to securely run queries against a D1 database. The API can be used to customize access controls and/or limit what tables can be queried.

ការបង្រៀននេះបង្ហាញពីរបៀបបង្កើត API ដែលអនុញ្ញាតឱ្យអ្នកដំណើរការសំណួរដោយសុវត្ថិភាពប្រឆាំងនឹងមូលដ្ឋានទិន្នន័យ D1 ។ API អាចត្រូវបានប្រើដើម្បីប្ដូរតាមបំណង access គ្រប់គ្រង និង/ឬកំណត់តារាងដែលអាចសួរបាន។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Kết nối thông qua Cloudflare Access bằng cách sử dụng CLI Connect through Cloudflare Access using a CLI ការភ្ជាប់តាម Cloudflare Access ដោយប្រើ CLI

Công cụ dòng lệnh đám mây của Cloudflare cho phép bạn tương tác với các điểm cuối được bảo vệ bởi Cloudflare Access.

Cloudflare's cloudflared command-line tool allows you to interact with endpoints protected by Cloudflare Access.

Cloudflare ឧបករណ៍បន្ទាត់បញ្ជាទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យ

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម

Xem thêm ví dụ trong lộ trình → More examples in this path → More examples in this path →

Tài liệu Cloudflare Developers Cloudflare Developer docs Cloudflare Developer docs

Sản phẩm liên quan Related products Related products

Học xong hoặc muốn đổi hướng? Finished or want a different path? Finished or want a different path?

Ba lộ trình độc lập — mỗi lộ trình chỉ gồm bài học và tài liệu trong phạm vi đó. Chọn lộ trình khác khi sẵn sàng, không cần học song song. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel.

Chưa chắc — làm bài chọn lộ trình Not sure — use the path selector Not sure — use the path selector · So sánh cả ba lộ trình Compare all three paths Compare all three paths