Google Cloud Service Extensions

Supported OS Linux Windows Mac OS

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください

Overview

Datadog App & API Protection extends visibility and inline threat mitigation to your Google Cloud Load Balancers using Google Cloud Service Extensions.

With this integration, you can detect and block attacks—such as API abuse, business logic exploitation, and code-layer threats—right at the edge of your cloud infrastructure.

This integration provides:

  • Inline threat detection and blocking at the load balancer using Datadog Security Signals
  • Real-time insights into application-layer attacks
  • Edge enforcement against OWASP API threats, credential stuffing, injection attacks, etc.

Setup

Installation

See Enabling App & API Protection for GCP Service Extensions for installation instructions.

Validation

To validate the installation of this integration, send known attack patterns to your load balancer. For example, you can trigger the Security Scanner Detected rule by running the following curl script:

for ((i=1;i<=250;i++)); 
do
    # Target existing service's routes
    curl https://your-load-balancer-url/existing-route -A dd-test-scanner-log;

    # Target non existing service's routes
    curl https://your-load-balancer-url/non-existing-route -A dd-test-scanner-log;
done

A few minutes after you enable the service extension and send known attack patterns, threat information appears in the Application Signals Explorer.

Troubleshooting

Need help? Contact Datadog Support.