Scan file uploads with an AI Inference firewall function
Create a function that sends an uploaded file to a model through AI Inference, and run it on a firewall so a malicious upload never reaches the origin.
You can scan an upload with a model and deny a malicious file, from Azion Console. The function runs on Firewall and calls the model through AI Inference. For the design this page builds, refer to Screen file uploads for malicious content.
Prerequisites
- An Azion account. To create one, refer to How to create an account on Azion.
- A firewall with the Functions module turned on. For what a function does on a firewall, refer to Functions for Firewall.
- A domain associated to that firewall, so the upload traffic reaches it.
- The upload routes to protect, such as
/uploador/documents/upload.
Create the firewall function
A function runs on a firewall when it registers a firewall handler. This one reads the request body, sends it to the model, and applies the verdict in the same request. To create it:
Access Azion Console > Products Menu > Libraries > Functions.
Enter a unique, descriptive name for the function.
In the Code tab, paste the function below.
In the Arguments tab, paste the JSON below.
The Code tab takes this function:
The Arguments tab takes this JSON:
The function is saved and available to instantiate on a firewall.
The function reads the request body and lets an image content type through untouched. It decodes base64 content, sends it to the model with the prompt from the arguments, and applies the action. The action, deny in this example, runs only when the model answers true. On any error, the function logs the message and lets the request continue.
The arguments select Mistral 3 Small, whose id is casperhansen-mistral-small-24b-instruct-2501-awq. Make sure the model you choose is available and configured in your account. For every id you can pass, refer to AI models.
The handler runs on Functions. For every field Azion.AI.run accepts, refer to Model invocation. For what happens after the call, refer to How AI Inference works.
Enable the firewall modules
The function runs on a firewall, and a firewall runs a function only when its Functions module is on. To prepare the firewall:
In Azion Console, go to Products Menu > Firewall.
In the Main Settings tab, turn on the DDoS Protection, Functions, Network Shield, and Web Application Firewall modules.
The firewall now runs the modules this design depends on, and it can hold a function instance.
Instantiate the function on the firewall
A function instance binds the function to one firewall. To create the instance:
The instance appears in the Functions Instances tab. It does not run until a Rules Engine rule selects it.
Add the rule that runs the function
A Rules Engine rule sets the criteria that trigger the instance. To run it on the uploads your application receives:
In the Criteria section, select the Request URI variable.
Enter an upload route as the argument, such as /upload.
In the Behaviors section, select Run Function.
The rule runs the function on every request whose URI starts with that route. A file the model calls malicious is denied before the origin receives it. Changes can take a few minutes to propagate. Wait before you send an upload that matches the criteria.
Monitor and tune the policy
A model decides what the policy blocks, so its record is the only way to check it. Watch these signals in Real-Time Metrics and Real-Time Events:
- The rate of uploads blocked, allowed, and quarantined.
- Patterns by country, IP, ASN, route, and time.
- Events correlated with the security incidents your team reports.
Then tune the policy against what you read:
- The prompt in the Arguments tab, which sets how strictly the model answers.
- Whether a suspect upload is denied or held for review in Object Storage.
- The Web Application Firewall and Network Shield rules on the same firewall.
- The volume the function sends to the model, within AI Inference limits.
- The false positives and false negatives your analysts label, fed back into the prompt.
The signals show what the function decided, and each adjustment changes what the next reading shows.