Lộ trình liên quan Related learning track

Application Services Application Services

Học lộ trình này Study this track

Bảo vệ API với Cloudflare Secure an API with Cloudflare

API thường bị abuse bởi bots, scrapers, credential stuffing, excessive requests và broken clients. APIs are often abused by bots, scrapers, credential stuffing, excessive requests, and broken clients.

Tài liệu Cloudflare (use case) → Official Cloudflare use case docs →

Kiến trúc gợi ý Suggested architecture

Mobile/Web Client → Cloudflare API security controls → API origin Mobile/Web Client → Cloudflare API security controls → API origin

Controls & stack Controls & stack

  • API Shield: discovery endpoint, schema validation, sequence analytics API Shield: endpoint discovery, schema validation, sequence analytics
  • WAF + managed rules cho pattern phổ biến WAF + managed rules for common patterns
  • Rate limiting theo endpoint (login, OTP, search, checkout) Endpoint-based rate limiting (login, OTP, search, checkout)
  • Bot protection cho traffic automation xấu Bot protection for harmful automation
  • mTLS/JWT validation cho client và auth endpoints mTLS/JWT validation for clients and auth endpoints
  • Logging/analytics để thấy top paths & top clients Logging/analytics to see top paths & clients

Tình huống khác (cùng lộ trình) Other scenarios (same track)

← Tất cả tình huống lộ trình này ← All scenarios in this track · Ba nhóm tình huống All three groups

Next step Next step

Tiếp tục hành trình học của bạn. Continue your learning journey.