Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Application Security

Google Enhances Protections in Cloud Armor Web Security Service

Google announced recently that it has expanded the capabilities of Cloud Armor, a service that provides distributed denial of service (DDoS) protections and a web application firewall (WAF) to keep customers safe from web attacks.

Google announced recently that it has expanded the capabilities of Cloud Armor, a service that provides distributed denial of service (DDoS) protections and a web application firewall (WAF) to keep customers safe from web attacks.

Generally available since 2019, Cloud Armor leverages the same infrastructure and technology that Google uses to protect its own internet-facing properties.

To expand the service’s capabilities, Google introduced Cloud Armor Adaptive Protection, which leverages machine learning to fend off Layer 7 DDoS attacks. Now in preview, the new functionality is available to all Cloud Armor customers, Google says.

Additionally, the Internet giant announced the general availability of a set of four new preconfigured WAF rules, along with a reference architecture, as well as a preview of new Cloud Armor protection for content delivered from Cloud CDN or Google Cloud Storage backend buckets.

By monitoring traffic out-of-band, Adaptive Protection learns what normal traffic patterns should be, building a continuously evolving baseline for each application or service. Thus, it can immediately spot and investigate suspicious traffic patterns and mitigate attacks in near-real time.

Google could previously mitigate volumetric- and protocol-based attacks (Layer 3 and Layer 4) at the edge, and is now targeting application layer (Layer 7) attacks that represent a growing threat. Such attacks, the company notes, employ legitimate web requests at volumes high enough to take down sites and services.

“This problem has grown increasingly acute as the size and frequency of DDoS attacks increases with the proliferation of widely-available DDoS attack tools and for-hire botnets. Since attacks can come from millions of individual IPs, manual triage and analysis to generate and enforce blocking rules becomes time and resource intensive, ultimately allowing high-volume attacks to impact applications,” Google says.

Alerts generated by Adaptive Protection, the company explains, are sent to the Cloud Armor dashboard, Cloud Logging, and Security Command Center. Next, attack-specific signatures and a WAF rule are generated to efficiently detect application-level attacks and mitigate them. Users are presented with the WAF rule and can choose whether to deploy it or not.

Advertisement. Scroll to continue reading.

Google already employs Adaptive Protection in Project Shield, the service that helps it protect the sites of news outlets, human rights organizations, and those used for election monitoring.

To get started with Adaptive Protection, Google’s customers can simply head to the Cloud Armor section in the Console and “enable” the policy. A subscription will be required for certain functions once the capability reaches general availability.

Related: Google Workspace Gets New Security Features

Related: Google: New Chrome Zero-Day Being Exploited

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how the LOtL threat landscape has evolved, why traditional endpoint hardening methods fall short, and how adaptive, user-aware approaches can reduce risk.

Watch Now

Join the summit to explore critical threats to public cloud infrastructure, APIs, and identity systems through discussions, case studies, and insights into emerging technologies like AI and LLMs.

Register

People on the Move

Cloud security startup Upwind has appointed Rinki Sethi as Chief Security Officer.

SAP security firm SecurityBridge announced the appointment of Roman Schubiger as the company’s new CRO.

Cybersecurity training and simulations provider SimSpace has appointed Peter Lee as Chief Executive Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.