Cloudflare AI Protection Portfolio Cloudflare AI Protection Portfolio
Cheatsheet này map rủi ro AI vào các lớp kiểm soát của Cloudflare One, Developer Platform và Application Security. Đây là defense-in-depth, không phải một sản phẩm đơn lẻ hay cam kết loại bỏ mọi rủi ro AI. This cheatsheet maps AI risks to Cloudflare One, Developer Platform, and Application Security controls. It is defense in depth, not a single product or a guarantee that every AI risk is eliminated.
Mô hình phòng thủ nhiều lớp Layered defense model
Users & devices → Zero Trust controls → sanctioned AI/SaaS → AI Gateway / application controls → model providers. Thi hành policy ở nhiều lớp: identity, web egress, SaaS posture, prompt/response, API và bot traffic. Users & devices → Zero Trust controls → sanctioned AI/SaaS → AI Gateway / application controls → model providers. Enforce policy at multiple layers: identity, web egress, SaaS posture, prompt/response, API, and bot traffic.
CASB: AI security posture & Shadow AI CASB: AI security posture and Shadow AI
Dùng CASB để phát hiện SaaS/AI chưa được phê duyệt, kiểm tra posture và tìm rủi ro về user hoặc access token. Kết hợp DLP để phát hiện sensitive content. Use CASB to discover unsanctioned SaaS/AI, assess posture, and find user or access-token risks. Pair it with DLP for sensitive-content detection.
Kiểm soátControls
- Inventory app, Shadow AI và security findingsInventory applications, Shadow AI, and security findings
- Scan misconfiguration, sensitive-data exposure và compliance postureScan misconfiguration, sensitive-data exposure, and compliance posture
- Review activity/logs để hỗ trợ điều tra sau sự cốReview activity and logs to support incident investigation
Rủi ro được giảm thiểuRisks addressed
- Data loss/misuse qua unsanctioned AIData loss or misuse through unsanctioned AI
- Key/token hygiene yếu và compliance gapsWeak key/token hygiene and compliance gaps
SWG & RBI: kiểm soát AI trên web SWG and RBI: control AI use on the web
Secure Web Gateway tạo visibility về AI tools trên traffic web và có thể steer user từ dịch vụ không được phê duyệt sang sanctioned alternative. Remote Browser Isolation giảm rủi ro upload file vào AI web app. Secure Web Gateway provides visibility into AI tools in web traffic and can steer users from unsanctioned services to approved alternatives. Remote Browser Isolation reduces the risk of file uploads to AI web apps.
Kiểm soátControls
- Discover/inventory AI destinations qua DNS và HTTP policyDiscover and inventory AI destinations through DNS and HTTP policy
- Block, allow hoặc redirect theo policy và identityBlock, allow, or redirect by policy and identity
- Dùng RBI cho browsing/upload risk caoUse RBI for high-risk browsing and uploads
Rủi ro được giảm thiểuRisks addressed
- Thiếu visibility để quản trị AI adoptionMissing visibility for AI adoption governance
- Data loss từ Shadow AI và file uploadData loss from Shadow AI and file uploads
Tài liệu chính thức ↗Official docs ↗ · swg · gateway · browser-isolation · warp
AI Gateway: routing, guardrails & audit AI Gateway: routing, guardrails, and audit
Đặt AI Gateway giữa application và provider để route model động, quan sát request, cache khi phù hợp và áp dụng guardrails. Gateway không thay thế application authorization hay WAF. Place AI Gateway between an application and providers for dynamic model routing, request visibility, appropriate caching, and guardrails. The gateway does not replace application authorization or a WAF.
Kiểm soátControls
- Dynamic routing/fallback để giảm failed request do provider capacityDynamic routing and fallback to reduce failed requests from provider capacity
- Logs, analytics và audit metadata; tránh log sensitive prompt không cần thiếtLogs, analytics, and audit metadata; avoid logging sensitive prompts unnecessarily
- Guardrails/DLP policy theo cấu hình và planGuardrails and DLP policy subject to configuration and plan
Rủi ro được giảm thiểuRisks addressed
- Service exhaustion và LLM request failureService exhaustion and failed LLM requests
- Data misuse và thiếu audit visibilityData misuse and missing audit visibility
Application Security: WAF, Firewall for AI & Bots Application Security: WAF, Firewall for AI, and bots
Bảo vệ AI application endpoint khỏi malicious automation và prompt/response risk. Firewall for AI là một lớp WAF; Bot Management và AI Crawl Control bảo vệ content/public endpoint, theo plan. Protect AI application endpoints from malicious automation and prompt/response risk. Firewall for AI is a WAF layer; Bot Management and AI Crawl Control protect content and public endpoints, subject to plan.
Kiểm soátControls
- Detect/block/moderate unsafe prompt, prompt injection và sensitive response theo policyDetect, block, or moderate unsafe prompts, prompt injection, and sensitive responses by policy
- Bot Analytics, AI Labyrinth và controls cho verified/unverified AI botsBot Analytics, AI Labyrinth, and controls for verified or unverified AI bots
- Rate limit public AI endpoint và verify user input server-sideRate-limit public AI endpoints and verify user input server-side
Rủi ro được giảm thiểuRisks addressed
- PII leak, harmful prompt và prompt injectionPII leaks, harmful prompts, and prompt injection
- Unauthorized AI crawling, bot abuse và export costUnauthorized AI crawling, bot abuse, and export cost
Tài liệu chính thức ↗Official docs ↗ · waf · bots · rate-limiting · turnstile
Radar & Cloudflare One (SASE) foundation Radar and Cloudflare One (SASE) foundation
Radar là threat/intelligence reference cho AI crawler awareness, không phải enforcement control. Cloudflare One kết hợp Access (ZTNA), Gateway/SWG, Tunnel, WARP, DLP, RBI và CASB để áp dụng policy theo identity, device và traffic. Radar is a threat-intelligence reference for AI crawler awareness, not an enforcement control. Cloudflare One combines Access (ZTNA), Gateway/SWG, Tunnel, WARP, DLP, RBI, and CASB to apply policy by identity, device, and traffic.
Kiểm soátControls
- Dùng Radar để hiểu AI crawler trends và security contextUse Radar to understand AI crawler trends and security context
- Bắt đầu với Access/identity, sau đó rollout SWG, DLP và CASB theo riskStart with Access and identity, then roll out SWG, DLP, and CASB according to risk
Rủi ro được giảm thiểuRisks addressed
- Thiếu situation awareness và policy foundationMissing situation awareness and policy foundation
- Rollout AI control không nhất quánInconsistent rollout of AI controls
Tài liệu chính thức ↗Official docs ↗ · access · ztna · tunnel · warp · dlp · casb
Áp dụng AI security trong lộ trình Apply AI security in the learning path
Đi từ Shadow AI và SASE controls đến AI Gateway, RAG và agent security trong lộ trình riêng. Move from Shadow AI and SASE controls to AI Gateway, RAG, and agent security in the dedicated track.