このページでは、特定ドメイン向けの新しいセキュリティダッシュボードで使えるセキュリティ設定を説明します。
新しいセキュリティダッシュボードでセキュリティ設定を開くには、Settings ページへ移動します。
Settings を開く ↗セキュリティ設定と検出ツールは、検出・緩和する脅威の種類ごとに分類されています。
Web application exploits セキュリティカテゴリでは、次の設定を管理できます。
- 検出ツール:
- Security Level 内の Under Attack mode
- マネージド security.txt
詳細は各リンク先を参照してください。
DDoS attacks セキュリティカテゴリには、Cloudflare が提供する複数の DDoS 攻撃対策サービスが表示されます。
DDoS 攻撃対策ツールを上書きするルールを作成できます。DDoS 攻撃対策のオーバーライドは、Advanced DDoS Protection サブスクリプション付きの Enterprise のお客様だけが利用できます。
DDoS 対策のオーバーライドについて詳しくは、次のリソースを参照してください。
加えて、次の設定を管理できます。
- Block AI Bots
- Bot Management(Enterprise のサブスクリプションによって異なります)
- Browser Integrity Check
- Challenge Passage
- Cloudflare managed ruleset
- AI Security for Apps
- Schema learning
- Schema validation(アップロード済みのスキーマが必要です)
- Under Attack mode(Security Level 内)
- SSL/TLS DDoS attack protection
Bot traffic セキュリティカテゴリでは、次の設定を管理できます。
- AI Labyrinth
- Block AI Bots
- Bot fight mode(Cloudflare プランによって異なります)
- Super Bot fight mode(Cloudflare プランによって異なります)
- Bot Management(Enterprise のサブスクリプションによって異なります)
- robots.txt による AI ボットトラフィックの管理
- API の sequence detection(セッション識別子の設定が必要です)
API abuse セキュリティカテゴリでは、次の設定を管理できます。
- Developer portal の作成
- Web asset discovery(Enterprise のサブスクリプションに含まれている場合は常に有効です。Enterprise サブスクリプションでは API endpoint discovery も含まれ、セッション識別子 の設定が必要です)
- Endpoint labels
- JWT validation(JWT 構成 の追加が必要です)
Client-side abuse セキュリティカテゴリでは、次の設定を管理できます。
- Continuous script monitoring:
- Cloudflare 所有ではなく自分のホスト名を使う Reporting endpoint(有料アドオン付きの Enterprise のお客様のみ)
- クライアントサイド不正レポートに記録するデータ(ホスト名のみ、または完全な URI)
- Email Address Obfuscation
- Hotlink Protection
次の表は、各設定の追加情報へのリンクです。
| 設定 | 以前のダッシュボードでの場所 |
|---|---|
| AI Labyrinth | Security > Bots > Configure Bot Fight Mode Security > Bots > Configure Super Bot Fight Mode Security > Bots > Configure Bot Management |
| AI Security for Apps | 該当なし |
| Block AI Bots | Security > Bots > Configure Bot Fight Mode Security > Bots > Configure Super Bot Fight Mode Security > Bots > Configure Bot Management |
| Bot Management: | Security > Bots |
| — JS detections | Security > Bots > Configure Super Bot Fight Mode Security > Bots > Configure Bot Management |
| — Auto-update machine learning | Security > Bots > Configure Bot Management |
| Browser integrity check | Security > Settings |
| Challenge Passage: Timeout | Security > Settings |
| Client certificates | SSL > Client Certificates |
| Cloudflare managed ruleset | Security > WAF > Managed rules タブ |
| Continuous script monitoring: | Security > Client-side security |
| — Reporting endpoint | Security > Client-side security > Settings |
| — Data processing | Security > Client-side security > Settings |
| — Alerts | Security > Client-side security > Settings Account Home > Notifications |
| 開発者ポータルを作成する | Security > API Shield > Settings |
| Custom fallthrough rules | Security > API Shield > Settings |
| Email Address Obfuscation | Scrape Shield |
| API endpoint discovery: | API Shield > Discovery |
| — Session identifiers | Security > API Shield > Settings |
| Endpoint labels | Security > Settings > Labels |
| Hotlink Protection | Scrape Shield |
| HTTP DDoS attack protection: | Security > DDoS |
| — オーバーライドを設定する | Security > DDoS |
| robots.txt で AI ボットトラフィックを指示する | Security > Bots > Configure Bot Fight Mode Security > Bots > Configure Super Bot Fight Mode Security > Bots > Configure Bot Management |
| IP access rules | Security > WAF > Tools タブ Security > WAF > Custom rules タブ |
| IP lists | Account Home > Manage Account > Configurations |
| JWT validation: | Security > API Shield > Settings |
| — JWT validation rules | Security > API Shield > API Rules |
| — Token configurations | Security > API Shield > Settings |
| Leaked credentials detection: | Security > Settings |
| — カスタムのユーザー名とパスワードの場所 | Security > Settings |
| Malicious uploads detection: | Security > Settings |
| — カスタムコンテンツの場所 | Security > Settings |
| mTLS rules | SSL/TLS > Client Certificates |
| Network-layer DDoS attack protection | Account Home > L3/4 DDoS > Network-layer DDoS Protection |
| OWASP Core ルールセット | Security > WAF > Managed rules タブ |
| 認証リクエストのレート制限 | Security > WAF > Rate limiting rules タブ |
| Replace insecure JavaScript libraries | Security > Settings |
| Schema learning: | Security > Web Assets > Operations |
| — Session identifiers | Security > API Shield > Settings |
| Schema validation | Security > API Shield > Schema Validation |
| — Operations | Security > Web Assets > Operations |
| — Active schemas | Security > API Shield > Schema Validation |
| Security level: I'm under attack mode | Security > Settings |
| Security.txt | Security > Settings |
| Sensitive data detection ルールセット | Security > Sensitive Data |
| Sequence detection: | Security > API Shield > API Rules |
| — Endpoints | Security > API Shield |
| — Session identifiers | Security > API Shield > Settings |
| Session identifiers | Security > API Shield > Settings |
| SSL/TLS DDoS attack protection | Security > DDoS |
| Token configurations | Security > API Shield > Settings |
| User agent blocking | Security > WAF > Tools タブ Security > WAF > Custom rules タブ |
| Zone lockdown | Security > WAF > Tools タブ Security > WAF > Custom rules タブ |