AI Security for Apps Reference Architecture AI Security for Apps Reference Architecture AI Security for Apps Reference Architecture
/reference-architecture/architectures/ai-security-for-apps
Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែមLộ trình đang học Current learning path Current learning path
Cloudflare One Cloudflare One Cloudflare One
Bảo vệ users, access, SaaS và networks — follow-along từ tài khoản đến go-live. Secure users, access, SaaS, and networks — follow along from account to go-live. Secure users, access, SaaS, and networks — follow along from account to go-live.
Phần 7: Kiểm soát AI, MCP và crawler Part 7: AI controls, MCP, and crawlers Part 7: AI controls, MCP, and crawlers · Bài 1/4 Lesson 1/4 មេរៀន 1/4
Mục tiêu: Xem nhân viên đang dùng công cụ AI nào, ngăn dữ liệu nhạy cảm bị dán vào chúng, và bảo vệ mọi ứng dụng AI mà bạn tự xây.
| 👤 Ai làm việc này | Nhóm bảo mật |
| ⏱️ Thời gian | ~45 phút |
| 🎯 Kết thúc bạn sẽ có | Tầm nhìn về việc dùng AI, một chính sách cho phép dùng AI an toàn, và bảo vệ dữ liệu ở cấp prompt |
| ✋ Trước khi bắt đầu | Đã xong Mô-đun 3 & 5 (thiết bị đã kết nối, TLS decryption bật). Các phần dựa trên DLP cần Enterprise. |
🧭 Quy tắc vàng cho AI: quản trị, đừng cấm. Nếu bạn chặn cứng ChatGPT, người ta chỉ dùng trên điện thoại — và bạn mất hết tầm nhìn. Mục tiêu là cho phép AI một cách an toàn: nhìn thấy, kiểm soát hành động rủi ro, và ngăn dữ liệu nhạy cảm đi vào.
Mô-đun này (và các Mô-đun 5d, 6, 7b, 7c) cùng tạo nên AI Security Suite của Cloudflare: bảo mật và quản trị AI ở mọi nơi đổi mới diễn ra, xuyên suốt toàn bộ vòng đời AI — để bạn mở rộng việc áp dụng AI mà không hy sinh bảo mật. Nên xem các mảnh ghép khớp nhau thế nào trước khi đi sâu.
Bốn kết quả bộ giải pháp mang lại:
| Kết quả | Ý nghĩa | Ở đâu trong hướng dẫn này |
|---|---|---|
| Giảm rủi ro shadow-AI | Hiểu AI được dùng thế nào; quản lý công cụ rủi ro/chưa được phê duyệt bằng SaaS analytics + chính sách lưu lượng | 5d — Shadow IT |
| Ngăn mất dữ liệu | Phát hiện thông tin nhạy cảm trong lưu lượng hướng tới AI — xuyên suốt yêu cầu mô hình, phiên trình duyệt và đích SaaS | 6 — DLP · mô-đun này |
| Quản trị quyền truy cập công cụ của agent | Tập trung quyền truy cập máy chủ MCP nội bộ/bên thứ ba; chọn lọc công cụ & prompt sau chính sách zero-trust | 7b — Secure AI & MCP |
| Giữ chi phí trong tầm kiểm soát | Giới hạn chi tiêu theo thời gian thực để việc dùng AI luôn dự đoán được trên các mô hình & nhà cung cấp | 7c — AI Gateway |
Bốn trường hợp sử dụng xuyên suốt vòng đời AI:
| Trường hợp sử dụng | Công cụ chính | Mô-đun |
|---|---|---|
| Bảo mật việc dùng AI của nhân viên | SWG, DLP, RBI, CASB | 5 · 6 · 5c · mô-đun này |
| Quản trị AI agent | MCP server portals, ZTNA | 7b |
| Xây dựng AI an toàn | AI Gateway, Workers (host remote MCP servers) | 7c |
| Bảo vệ ứng dụng dùng AI | AI Security for Apps (WAF) | Phần D2 bên dưới |
📎 Một khả năng hướng dẫn này không thiết lập sâu: CASB / AI-SPM. CASB của Cloudflare bổ sung AI Security Posture Management — nó quét các công cụ SaaS và AI đã được phê duyệt để tìm cấu hình sai (dữ liệu chia sẻ quá mức, tích hợp rủi ro, thiết lập yếu) và giúp bạn khắc phục. Nó bổ sung cho các kiểm soát trong lưu lượng của bộ giải pháp này bằng các kiểm tra tư thế khi lưu trữ trên các công cụ AI bạn đã phê duyệt. Nếu bạn đã cấp phép CASB, hãy chạy quét AI-SPM song song với các mô-đun này. (Tham khảo: cloudflare.com/solutions/ai-security.)
Chúng ta sẽ làm: (A) phát hiện những gì đang được dùng → (B) cho phép-nhưng-hạn-chế → (C) bảo vệ prompt bằng DLP → (D) bảo vệ AI bạn tự xây → (E) quản trị AI agent.
✅ Điểm kiểm tra: Bạn giờ có bức tranh dựa trên bằng chứng về việc dùng AI — cơ sở cho chính sách sử dụng AI chấp nhận được của bạn.
🔎 Toàn bộ quy trình phát hiện→xem xét→áp dụng (cho mọi SaaS, không chỉ AI) cùng hành trình áp dụng AI nằm trong Mô-đun 5d — Shadow IT & AI Security Adoption.
Thay vì chặn một ứng dụng AI, hãy cho phép nó đồng thời chặn các phần rủi ro (như tải tệp lên).
AI - allow with guardrails.📺 Việc này làm gì: Người ta có thể trò chuyện với AI, nhưng không thể tải tài liệu của bạn vào đó.
✅ Điểm kiểm tra: Trên thiết bị thí điểm, bạn dùng ChatGPT bình thường, nhưng khi cố tải tệp lên thì bị chặn.
Phần này quét những gì người dùng gõ vào công cụ AI và chặn các prompt chứa dữ liệu nhạy cảm.
AI prompts - MONITOR.AI prompts - BLOCK với Action: Block cho các trường hợp độ tin cậy cao (ví dụ prompt chứa Credentials & Secrets).✅ Điểm kiểm tra: Dán một secret/API key giả vào cuộc trò chuyện AI được phát hiện (và bị chặn bởi chính sách block), thấy được trong log.
Hai công cụ khác nhau, tùy cách AI được dùng:
Nếu lập trình viên của bạn gọi mô hình AI qua Cloudflare AI Gateway:
💡 Cách này hoạt động không cần TLS decryption hay client trên thiết bị — nó kiểm tra lưu lượng ở lớp API. Rất phù hợp để quản trị các cuộc gọi app-to-AI.
🚪 AI Gateway làm nhiều hơn DLP — xác thực, guardrails, giới hạn chi phí/tốc độ, caching và ghi log cho mọi cuộc gọi AI mà ứng dụng của bạn thực hiện. Hướng dẫn đầy đủ: Mô-đun 7c — AI Gateway: Protect & Implement.
Nếu bạn host một ứng dụng/chatbot AI mà người khác truy cập qua web:
💡 Chúng khác nhau thế nào: AI Security for Apps chặn tấn công vào mô hình của bạn (prompt injection); DLP chặn dữ liệu nhạy cảm di chuyển. Dùng cả hai trên lưu lượng AI.
🕷️ Mối đe dọa vào chiều ngược lại: AI crawlers. Ngoài tấn công, bot AI còn crawl nội dung công khai của bạn để huấn luyện mô hình — giờ chiếm phần lớn lưu lượng internet. Để xem, cho phép/chặn, hoặc thậm chí tính phí chúng, xem Mô-đun 7d — The Agentic Internet: AI Crawler & Bot Control.
Nếu bạn mở công cụ cho AI agent qua Model Context Protocol (MCP):
🔐 Đây là một chủ đề lớn riêng. Để có hướng dẫn đầy đủ — bảo mật từng máy chủ MCP, xây MCP portal, Managed OAuth cho AI client, service token cho bot, và ghi log cấp request + DLP — xem trang đi kèm: Mô-đun 7b — Secure AI & MCP with Access (MCP Server Portals).
Bây giờ bạn có:
| Vấn đề | Cách khắc phục |
|---|---|
| Ứng dụng AI không xuất hiện trong Shadow IT | Cần lưu lượng HTTP đi qua Gateway — xác nhận Mô-đun 5 (Gateway with WARP + decryption) |
| Prompt DLP không bắt được gì | TLS decryption tắt, hoặc AI prompt topics chưa bật (Phần C1); cũng cần Enterprise |
| Chặn chi tiết "block upload" không có cho một ứng dụng | Không phải mọi ứng dụng đều hỗ trợ mọi granular control — thay vào đó hãy chặn domain tải lên của ứng dụng, hoặc isolate nó |
| Người dùng phàn nàn AI bị chặn hoàn toàn | Bạn đã tạo Block thay vì Allow+granular — chuyển sang mẫu ở Phần B |
Kết nối cả văn phòng và trung tâm dữ liệu với Cloudflare. (Tùy chọn; cần gói bổ sung mạng Enterprise.)
Goal: See which AI tools your people use, stop sensitive data from being pasted into them, and protect any AI apps you build yourself.
| 👤 Who does this | Security team |
| ⏱️ Time | ~45 minutes |
| 🎯 You'll finish with | Visibility into AI usage, a policy that lets people use AI safely, and prompt-level data protection |
| ✋ Before you begin | Modules 3 & 5 done (devices connected, TLS decryption on). DLP-based parts need Enterprise. |
🧭 The golden rule for AI: govern, don't ban. If you hard-block ChatGPT, people just use it on their phones — and you lose all visibility. The goal is to allow AI safely: see it, control risky actions, and stop sensitive data going in.
This module (and Modules 5d, 6, 7b, 7c) together make up Cloudflare's AI Security Suite: secure and govern AI everywhere innovation happens, across the whole AI lifecycle — so you can scale AI adoption without sacrificing security. It's worth seeing how the pieces fit before diving in.
Four outcomes the suite delivers:
| Outcome | What it means | Where in this guide |
|---|---|---|
| Reduce shadow-AI risk | Understand how AI is used; manage risky/unsanctioned tools with SaaS analytics + traffic policy | 5d — Shadow IT |
| Prevent data loss | Detect sensitive info in AI-bound traffic — across model requests, browser sessions, and SaaS destinations | 6 — DLP · this module |
| Govern agent tool access | Centralize access to internal/third-party MCP servers; curate tools & prompts behind zero-trust policy | 7b — Secure AI & MCP |
| Keep costs under control | Real-time spend limits so AI usage stays predictable across models & providers | 7c — AI Gateway |
Four use cases across the AI lifecycle:
| Use case | Primary tools | Module |
|---|---|---|
| Secure workforce AI use | SWG, DLP, RBI, CASB | 5 · 6 · 5c · this module |
| Govern AI agents | MCP server portals, ZTNA | 7b |
| Build AI securely | AI Gateway, Workers (host remote MCP servers) | 7c |
| Protect AI-powered apps | AI Security for Apps (WAF) | Part D2 below |
📎 One capability this onboarding doesn't set up in depth: CASB / AI-SPM. Cloudflare's CASB adds AI Security Posture Management — it scans your sanctioned SaaS and AI tools for misconfigurations (over-shared data, risky integrations, weak settings) and helps you fix them. It complements the in-traffic controls in this suite with at-rest posture checks on the AI tools you've approved. If you've licensed CASB, run its AI-SPM scans alongside these modules. (Reference: cloudflare.com/solutions/ai-security.)
We'll do: (A) discover what's used → (B) allow-but-restrict → (C) protect prompts with DLP → (D) protect AI you build → (E) govern AI agents.
✅ Checkpoint: You now have an evidence-based picture of AI usage — the basis for your AI acceptable-use policy.
🔎 The full discover→review→enforce workflow (for all SaaS, not just AI) plus the AI-adoption journey is in Module 5d — Shadow IT & AI Security Adoption.
Instead of blocking an AI app, allow it while blocking the risky parts (like file uploads).
AI - allow with guardrails.📺 What this does: People can chat with the AI, but can't upload your documents into it.
✅ Checkpoint: On a pilot device, you can use ChatGPT normally, but attempting to upload a file is blocked.
This scans what users type into AI tools and blocks prompts containing sensitive data.
AI prompts - MONITOR.AI prompts - BLOCK with Action: Block for the high-confidence cases (e.g. prompts containing Credentials & Secrets).✅ Checkpoint: Pasting a fake secret/API key into an AI chat is detected (and blocked by the block policy), visible in logs.
Two different tools, depending on how AI is used:
If your developers call AI models through Cloudflare AI Gateway:
💡 This works without TLS decryption or the device client — it inspects traffic at the API layer. Great for governing app-to-AI calls.
🚪 AI Gateway does much more than DLP — authentication, guardrails, cost/rate limits, caching, and logging for every AI call your apps make. Full walkthrough: Module 7c — AI Gateway: Protect & Implement.
If you host an AI app/chatbot that others reach over the web:
💡 How they differ: AI Security for Apps stops attacks on your model (prompt injection); DLP stops sensitive data moving. Use both on AI traffic.
🕷️ The other inbound threat: AI crawlers. Beyond attacks, AI bots crawl your public content to train models — now the majority of internet traffic. To see, allow/block, or even charge them, see Module 7d — The Agentic Internet: AI Crawler & Bot Control.
If you expose tools to AI agents via the Model Context Protocol (MCP):
🔐 This is a big topic on its own. For the full walkthrough — securing individual MCP servers, building an MCP portal, Managed OAuth for AI clients, service tokens for bots, and request-level logging + DLP — see the companion page: Module 7b — Secure AI & MCP with Access (MCP Server Portals).
You now have:
| Problem | Fix |
|---|---|
| AI apps don't appear in Shadow IT | Needs HTTP traffic through Gateway — confirm Module 5 (Gateway with WARP + decryption) |
| Prompt DLP not catching anything | TLS decryption off, or AI prompt topics not enabled (Part C1); also needs Enterprise |
| Granular "block upload" not available for an app | Not all apps support every granular control — block the app's upload domain instead, or isolate it |
| Users complain AI is fully blocked | You created a Block instead of Allow+granular — switch to the Part B pattern |
Connect whole offices and data centers to Cloudflare. (Optional; requires Enterprise network add-on.)
Nguồn cộng đồng — không phải tài liệu chính thức của Cloudflare: https://zerotrust.cfsase.workers.dev Community source — not an official Cloudflare publication: https://zerotrust.cfsase.workers.dev
Ví dụ chính thức từ Cloudflare Resources — gợi ý theo chủ đề bài học trong lộ trình này. Official examples from Cloudflare Resources — matched to this lesson within this path. Official examples from Cloudflare Resources — matched to this lesson within this path.
/reference-architecture/architectures/ai-security-for-apps
Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែមVới Cloudflare cách ly trình duyệt và các chính sách giải quyết, người dùng có thể kết nối với các ứng dụng dựa trên web riêng tư thông qua tên máy chủ riêng của họ.
With Cloudflare Browser Isolation and resolver policies, users can connect to private web-based applications via their private hostnames.
ជាមួយនឹង Cloudflare គោលការណ៍ញែកកម្មវិធីរុករក និងដំណោះស្រាយ អ្នកប្រើប្រាស់អាចភ្ជាប់ទៅកម្មវិធីដែលមានមូលដ្ឋានលើបណ្តាញឯកជនតាមរយៈឈ្មោះម៉ាស៊ីនឯកជនរបស់ពួកគេ។
Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែមSử dụng mạng riêng của Cloudflare Tunnel, người dùng có thể kết nối với các ứng dụng dựa trên TCP/UDP, chẳng hạn như cơ sở dữ liệu. Bạn có thể thiết lập chính sách mạng thực hiện các điều khiển zero trust để xác định ai và những gì access có thể sử dụng các ứng dụng đó bằng cách sử dụng Cloudflare One Client.
Using Cloudflare Tunnel's private networks, users can connect to arbitrary non-browser based TCP/UDP applications, like databases. You can set up network policies that implement zero trust controls to define who and what can access those applications using the Cloudflare One Client.
ដោយប្រើបណ្តាញឯកជនរបស់ Cloudflare Tunnel អ្នកប្រើប្រាស់អាចភ្ជាប់ទៅកម្មវិធី TCP/UDP ដែលមានមូលដ្ឋានលើកម្មវិធីរុករកតាមអំពើចិត្ត ដូចជាមូលដ្ឋានទិន្នន័យជាដើម។ អ្នកអាចរៀបចំគោលការណ៍បណ្តាញដែលអនុវត្តការគ្រប់គ្រង zero trust ដើម្បីកំណត់ថាតើនរណា និងអ្វីដែលអាច access កម្មវិធីទាំងនោះដោយប្រើ Cloudflare One Client ។
Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែមHướng dẫn này cho thấy cách tạo một API cho phép bạn chạy truy vấn an toàn chống lại một cơ sở dữ liệu D1. API có thể được sử dụng để tùy chỉnh các điều khiển access và/hoặc giới hạn các bảng có thể được truy vấn.
This tutorial shows how to create an API that allows you to securely run queries against a D1 database. The API can be used to customize access controls and/or limit what tables can be queried.
ការបង្រៀននេះបង្ហាញពីរបៀបបង្កើត API ដែលអនុញ្ញាតឱ្យអ្នកដំណើរការសំណួរដោយសុវត្ថិភាពប្រឆាំងនឹងមូលដ្ឋានទិន្នន័យ D1 ។ API អាចត្រូវបានប្រើដើម្បីប្ដូរតាមបំណង access គ្រប់គ្រង និង/ឬកំណត់តារាងដែលអាចសួរបាន។
Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែមXem thêm ví dụ trong lộ trình → More examples in this path → More examples in this path →
Ba lộ trình độc lập — mỗi lộ trình chỉ gồm bài học và tài liệu trong phạm vi đó. Chọn lộ trình khác khi sẵn sàng, không cần học song song. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel.
Follow-along: DNS → proxy → SSL → WAF → cache — rồi mới rẽ API Shield hoặc Load Balancing Follow-along: DNS → proxy → SSL → WAF → cache — then branch to API Shield or Load Balancing Follow-along: DNS → proxy → SSL → WAF → cache — បន្ទាប់មកទើបបែកផ្លូវទៅ API Shield ឬ Load Balancing
Vào lộ trình này → Enter this path → Enter this path →Follow-along Worker-first: C3 + Wrangler, rồi storage, Pages (compat), operate và AI Follow-along Worker-first: C3 + Wrangler, then storage, Pages (compat), operate, and AI Follow-along Worker-first: C3 + Wrangler បន្ទាប់មក storage, Pages (compat), operate និង AI
Vào lộ trình này → Enter this path → Enter this path →Adopt AI an toàn từ user đến ứng dụng Adopt AI safely from users to applications Adopt AI safely from users to applications
Vào lộ trình này → Enter this path → Enter this path →Vận hành Cloudflare an toàn, ổn định và hiệu quả Operate Cloudflare safely, reliably, and efficiently Operate Cloudflare safely, reliably, and efficiently
Vào lộ trình này → Enter this path → Enter this path →Chưa chắc — làm bài chọn lộ trình Not sure — use the path selector Not sure — use the path selector · So sánh cả ba lộ trình Compare all three paths Compare all three paths