Security from First Principles

Security Engineering for Fintech

คอร์ส Security Engineering แบบ end-to-end สำหรับ engineer ที่ต้องสร้างและดูแลระบบจริง เริ่มจาก security mindset, threat modeling และ cryptography ต่อด้วย identity, web, API, mobile, network และ AWS security ก่อนจบด้วย advanced attacks, software supply chain และการออกแบบระบบ Fintech ตั้งแต่ mobile app จนถึง production cloud

27 บทเรียน6 partsSecurity

Course trail

เส้นทางการเรียน

Part 1 — Security Foundations

Part 2 — Identity & Web Security

บทที่ 5Identity & AuthenticationIdentity lifecycle, password policy, credential stuffing, account enumeration, rate limiting และ authentication telemetry ตามแนวทางปัจจุบันบทที่ 6Strong Authentication & Account RecoveryMFA, passkeys, phishing resistance, step-up authentication, authenticator binding และ recovery ที่ไม่กลายเป็นทางลัดยึดบัญชีบทที่ 7Session & Token SecurityCookie, bearer token, JWT/opaque token, fixation, hijacking, timeout, rotation, revocation และ refresh-token reuse detectionบทที่ 8Authorization & Access ControlRBAC, ABAC, ReBAC, BOLA/IDOR, function/property authorization, multi-tenant isolation และ maker-checker สำหรับ privileged actionบทที่ 9Web Security ModelHTTP, origin, Same-Origin Policy, cookie, CORS, browser credentials, trusted proxy headers และ TLS termination ที่กำหนด security boundary ของเว็บบทที่ 10OWASP Top 10 in PracticeOWASP Top 10:2025 ผ่าน root cause และ failure ของระบบการเงิน พร้อมวิธีใช้ร่วมกับ ASVS โดยไม่ตีความว่าเป็น certificationบทที่ 11Injection & Input SecurityValidation, canonicalization, parameterization และ contextual encoding สำหรับ SQL/NoSQL, command, path, template และ deserializationบทที่ 12Browser, File & Content SecurityXSS, CSRF, CSP, Trusted Types, clickjacking, open redirect, browser storage และ secure file pipeline สำหรับเอกสาร KYC

Part 3 — API & Mobile Security

Part 4 — Network Security

Part 5 — Cloud Security on AWS

Part 6 — Advanced Security Engineering

How to Read This Course

  • Part 1 อ่านเรียงลำดับ เพราะ threat modeling, cryptography และ Secure Development Lifecycle เป็นภาษากลางของทุก Part ที่ตามมา
  • Part 2–4 ไล่ตามเส้นทางของ request จริง: identity และ browser → API และ mobile → network
  • Part 5 นำ control เหล่านั้นไปวางบน AWS ตั้งแต่ account boundary จนถึง incident response
  • Part 6 รวมช่องโหว่ระดับ advanced แล้วจบด้วย architecture และ go-live checklist ของระบบ Fintech

ตัวอย่างในคอร์สใช้สถานการณ์ทั่วไปจาก mobile wallet, public API, operations portal, double-entry ledger, KYC document service และ workload บน AWS โดยไม่มีชื่อองค์กรหรือ ระบบสมมติเฉพาะ เพื่อแสดงว่า control ในแต่ละชั้นเชื่อมกันอย่างไร ไม่ใช่เรียนช่องโหว่ เป็นรายการแยกจากกัน

คอร์สนี้เหมาะกับ software engineer, platform engineer, tech lead และ solution architect ที่คุ้นเคยกับ HTTP API, database และ cloud เบื้องต้น ไม่จำเป็นต้องมีพื้นฐาน Security มาก่อน

Scope and Safety

ตัวอย่างมีไว้เพื่อการเรียนรู้

ตัวอย่าง request, policy และ configuration ตัดรายละเอียดบางส่วนออกเพื่อให้เห็นแนวคิด ต้องผ่านการ review, test และปรับตาม threat model ของระบบจริงก่อนใช้ใน production เนื้อหาจะอธิบายวิธีป้องกันและการทดสอบเฉพาะระบบที่ได้รับอนุญาตให้ทดสอบเท่านั้น

[!CAUTION] Security control ไม่ได้แปลว่า compliant โดยอัตโนมัติ ส่วนที่กล่าวถึง PDPA, PCI DSS, KYC, audit และข้อกำกับของธุรกิจการเงินเป็น ข้อพิจารณาเชิงวิศวกรรม ไม่ใช่คำแนะนำทางกฎหมาย การตัดสินใจเรื่องขอบเขตข้อมูล, ระยะเวลาเก็บ, การรายงานเหตุ และการยอมรับความเสี่ยงต้องเป็นของผู้มีอำนาจจาก Security, Risk, Compliance และ Legal ขององค์กร

Reference Families

เอกสารมาตรฐานและบริการ cloud เปลี่ยนได้เสมอ เนื้อหาจะหลีกเลี่ยงการจำหมายเลขเวอร์ชัน โดยไม่จำเป็น และระบุจุดที่ต้องตรวจ official documentation ของระบบที่ใช้งานจริง