Secure And Audit The Google Cloud Platform Perimeter

Audit

Ferris Argyle
Sep 3, 2018 · 2 min read

This article describes how Google Cloud Platform addresses the following traditional perimeter security question described in the concepts article: how do you audit traffic and data access, i.e. how do you know the controls worked as intended?

Google Cloud Platform provides a number of audit services corresponding to the solution components described in the prior articles…

Load Balancing logs (alpha)

HTTP(S) Load Balancing logs contain the general information shown in most GCP logs as well as HttpRequest log fields.

Limitations:

  • This product is in alpha.
  • HttpRequest.protocol is not populated.

App Engine HTTP request logs

App Engine HTTP request logs record requests sent to all App Engine Standard and Flexible apps, and are provided by default. You can supplement these with app logs in the App Engine Flexible environment.

If using a reverse proxy such as NGINX, add an HTTP header for the end user IP to be able to surface it in the App Engine request logs.

VPC flow logs

VPC flow logs record a sample of TCP and UDP network flows sent from and received by VM instances. This includes RDP traffic, since it’s TCP (and sometimes UDP).

Limitions:

  • VPC flow logs are downstream from the VM only.
  • They provide limited insight into managed data service (eg. Google Cloud Storage) access.

What’s next

Read the following to learn more about the concepts and solution components described in this article:

Read the following to learn about:

Google Cloud Platform - Community

Ferris Argyle

Written by

These are my personal writings; the views expressed in these pages are mine alone and not those of my employer, Google.

Google Cloud Platform - Community

A collection of technical articles published or curated by Google Cloud Platform Developer Advocates. The views expressed are those of the authors and don't necessarily reflect those of Google.

Welcome to a place where words matter. On Medium, smart voices and original ideas take center stage - with no ads in sight. Watch
Follow all the topics you care about, and we’ll deliver the best stories for you to your homepage and inbox. Explore
Get unlimited access to the best stories on Medium — and support writers while you’re at it. Just $5/month. Upgrade