บทที่ 24 · Part 5 — Cloud Security on AWS
AWS Data & Workload Protection
KMS/key policy, secret lifecycle, S3/Object Lock, database encryption, IMDSv2, ECS/EKS/Lambda isolation และ artifact security
การเปิด encryption checkbox เป็นเพียง control หนึ่งใน data lifecycle หาก principal อ่านข้อมูลได้ตาม policy KMS จะ decrypt ให้ตามสิทธิ์ และหาก key ถูกลบผิด ข้อมูลที่เก็บแบบทนทานอาจอ่านไม่ได้ถาวร Data protection จึงต้องออกแบบ confidentiality, integrity, availability, lifecycle และ workload isolation พร้อมกัน
Learning Outcomes
- ออกแบบ KMS key policy, grants, separation of duties และ rotation โดยเข้าใจข้อจำกัดได้
- วาง secret lifecycle ที่รวม consumer rollout, revoke และ incident response ได้
- ป้องกัน S3/database data ด้วย access, encryption, backup และ retention controls ได้
- ลด EC2 metadata/container/Kubernetes attack surface ได้
- แยก identity และ isolation semantics ของ ECS, EKS, ECR และ Lambda ได้
Start with Data Classification
ก่อนเลือก service/control ต้องทราบ:
- data type และ sensitivity
- owner/controller/custodian
- source, consumers และ allowed purposes
- tenant/subject/record boundaries
- storage, transit, processing และ export locations
- retention, deletion, legal hold และ backup copy
- RTO/RPO และ recovery authority
- key/secret dependency
classification ควรมีผลต่อ architecture และ policy ไม่ใช่ label ที่ไม่มี enforcement
Encryption ไม่แทน Authorization
encryption at rest ป้องกันบาง threat เช่น storage media/snapshot access นอก authorized service path แต่
principal ที่มี GetObject และใช้ key ได้ยังอ่านข้อความผ่าน service ตามปกติ ดังนั้นต้องมีทั้ง:
- identity/resource authorization
- tenant/object-level application authorization
- transport encryption และ peer validation
- encryption at rest/key control
- logging/detection
- backup/retention/deletion
- data minimization และ output control
field-level/client-side encryption อาจลด trust ต่อ storage/service layer แต่เพิ่ม key distribution, query, rotation, recovery และ observability complexity
AWS KMS Mental Model
AWS Key Management Service จัดการ KMS keys และ cryptographic operations ผ่าน service control plane ข้อมูลขนาดใหญ่มักใช้ envelope encryption: data key เข้ารหัส payload และ KMS key ปกป้อง data key
ประเด็นสำคัญ:
- KMS key มี identity/policy/state/lifecycle
- key policy เป็นฐานของ authorization
- IAM allow จะไม่มีผล หาก key policy ไม่เปิดให้ account delegate ตามรูปแบบที่ใช้
- resource service เช่น S3/RDS อาจเรียก KMS ในนาม principal ผ่าน service integration
- ciphertext/decryptability ผูกกับ Region/key/state/context ตาม operation
Key Policy and Separation of Duties
แยกบทบาทอย่างน้อย:
- Key administrator: สร้าง/configure/enable/disable/rotate policy แต่ไม่ควร decrypt data
- Key user: encrypt/decrypt หรือสร้าง data key ตาม workload
- Service role: ใช้ key ผ่าน service/context ที่จำกัด
- Auditor: อ่าน configuration/log โดยไม่มี key-use permission
ควรจำกัด:
- principal และ cross-account access
- cryptographic operations
- resource/service ผ่าน
kms:ViaServiceเมื่อเหมาะสม - encryption context
- grants และผู้สร้าง grant
- key deletion/disable/policy change
Key Deletion คือ Data Availability Decision
การ schedule deletion หรือทำ key ใช้ไม่ได้อาจทำให้ backup, database, log และ retained object อ่านไม่ได้ ต้องมี multi-person authority, delay/alert, dependency inventory และ tested recovery process
Encryption Context
encryption context คือ non-secret key-value metadata ที่ผูกกับ ciphertext แบบ authenticated data decrypt ต้องส่ง context ตรงกับตอน encrypt และใช้เป็น policy condition ได้
ข้อควรระวัง:
- ไม่ถูกเข้ารหัส
- อาจปรากฏใน CloudTrail/logs
- ห้ามใส่ PII, credential หรือ secret
- canonical name/value และ case ต้องสอดคล้อง
- consumer ทุกตัวต้องส่ง context ที่ถูกต้อง
- context ไม่แทน authorization ของ business object หาก caller กำหนดค่าเองได้
KMS Grants
grant มอบ key-use permission ให้ principal และมักใช้กับ integrated AWS services มี lifecycle แยกจาก key policy
แนวทาง:
- จำกัด operations และ grantee
- ใช้ constraints/encryption context เมื่อรองรับ
- จำกัด principal ที่สร้าง/retire/revoke grant
- inventory grants และลบเมื่อ resource/lifecycle จบ
- เข้าใจ eventual consistency และ grant token ใน workflow ที่ต้องใช้ทันที
grant ที่หลงเหลือหลัง resource ถูกย้าย/ปิดอาจเป็น access path ที่ review มองข้าม
Key Rotation
automatic rotation ของ KMS key ใช้ได้กับ key type/origin ที่รองรับ เมื่อ rotate:
- logical key/ARN เดิมยังอยู่
- key material เก่ายังถูกเก็บเพื่อ decrypt ciphertext เดิม
- data เดิมไม่ถูก re-encrypt อัตโนมัติ
- compromised old material ไม่ถูก revoke ด้วย rotation
asymmetric, HMAC หรือ custom key store บางแบบต้องใช้ manual replacement ตาม support matrix
rotation objective ต้องชัดว่าเป็น cryptoperiod hygiene, migration, algorithm change หรือ incident response กรณี compromise อาจต้องสร้าง key ใหม่, re-encrypt/reissue data, เปลี่ยน policy และ revoke path เดิม
Secrets Manager
secret คือ credential/token/key material ที่ application ต้องใช้ ไม่ควรอยู่ใน source, image, AMI, CI log, Terraform state ที่เปิดกว้าง หรือ environment dump
Secrets Manager ช่วย:
- encrypt secret at rest ด้วย KMS
- version/staging labels
- rotation workflow
- resource policy และ cross-account pattern
- caching library/private connectivity
- CloudTrail integration
แต่การเปิด rotation schedule ไม่รับประกันว่า rotation สำเร็จ ต้องทดสอบ:
- สร้าง pending credential
- ตั้งค่า provider/resource
- validate credential ใหม่
- promote current version อย่าง atomic
- ให้ consumer refresh cache/reconnect
- revoke previous credential หลัง overlap ที่กำหนด
- rollback เมื่อ partial failure
Secret Rotation อาจสร้าง Outage
database pool, long-running worker และ partner client อาจ cache secret นานกว่า overlap window ต้องมี consumer inventory, metrics และ staged rotation ไม่ควร invalidate credential เดิมก่อน validate ใหม่
Amazon S3
S3 เข้ารหัส object upload ใหม่ด้วย SSE-S3 เป็น default ตั้งแต่ปี 2023 แต่ default encryption:
- ไม่แก้ public/cross-account access
- ไม่เปลี่ยน authorization
- ไม่ rewrite object เดิมเมื่อเปลี่ยน default
- ไม่แทน TLS, versioning, backup หรือ retention
Access Controls
- เปิด S3 Block Public Access ในระดับ organization/account/bucket ตาม requirement
- ใช้ Bucket owner enforced/disable ACLs เมื่อรองรับ use case
- จำกัด bucket policy และ access point policy
- require TLS ด้วย policy condition
- จำกัด source VPC endpoint/organization/account เมื่อเหมาะสม
- inventory pre-signed URL และ expiry/permission ของ signer
- เปิด access logging/data events ตาม investigation need
Block Public Access มี precedence หลายระดับและใช้ setting ที่ restrictive ที่สุดที่ applicable แต่ policy review ยังจำเป็นสำหรับ trusted cross-account principal และ data exfiltration
SSE-S3, SSE-KMS and Client-Side Encryption
| Mode | Key control | Trade-off |
|---|---|---|
| SSE-S3 | S3 managed | ง่ายและลด key operations |
| SSE-KMS | KMS policy/audit/control เพิ่ม | KMS quota/cost/policy/availability dependency |
| Client-side | application คุม plaintext/key path มากขึ้น | query, rotation, recovery และ client complexity สูง |
SSE-KMS bucket key ลด KMS request/cost บางรูปแบบ แต่เปลี่ยน encryption-context/audit granularity ที่ต้องเข้าใจ
S3 Versioning and Object Lock
versioning ช่วย recover จาก overwrite/delete แต่ไม่ใช่ immutable backup หาก principal ลบ version ได้
S3 Object Lock ให้ WORM protection ต่อ object version และต้องเปิด versioning:
- Governance mode: ผู้มี bypass permission สามารถลด/ข้าม retention ได้
- Compliance mode: protected version ลบไม่ได้แม้ root จน retention หมด
- Legal hold: ไม่มี expiry จน authorized principal ยกเลิก
Object Lock ไม่ทำให้ข้อมูลอ่านได้ตลอด หาก KMS key สูญหาย retained ciphertext อาจอ่านไม่ได้ถาวร ต้องทดสอบ restore ทั้ง object, metadata, key และ application dependency
Relational Database Service
RDS encryption at rest ครอบคลุม underlying storage, logs, automated backups, read replicas และ snapshots ที่เกี่ยวข้องตาม service behavior แต่ยังต้องดู:
- database account/role และ credential lifecycle
- network path/Security Group/TLS
- query parameterization และ application authorization
- snapshot sharing/export/copy
- public accessibility และ endpoint DNS
- audit/error/slow-query log sensitivity
- backup retention, PITR, cross-Region/account recovery
- KMS key disable/deletion impact
database encryption ไม่ป้องกัน SQL injection ที่อ่านข้อมูลผ่าน authorized connection
DynamoDB
DynamoDB encrypts data at rest by default แต่ access/data-model controls ยังเป็นหน้าที่ของ application:
- IAM จำกัด table/index/action
- condition expression ไม่แทน tenant authorization
- partition/sort key ต้องไม่เปิด cross-tenant query path
- Streams/export/backup/PITR มี policy และ retention ของตน
- global table เพิ่ม Region/data-residency/key considerations
- capacity/concurrency/conditional writes ปกป้อง integrity/availability
transactional/conditional write ช่วย enforce state invariant แต่ business invariant ที่ข้าม service ยังต้องออกแบบเพิ่ม
Backup Is a Security Control
backup ต้องป้องกัน ransomware, operator error และ control-plane compromise:
- แยก account/role และ vault policy
- immutable retention ตาม requirement
- cross-Region/account copy เมื่อ threat model ต้องการ
- monitor backup failure และ deletion-policy change
- inventory encryption keys/dependencies
- test restore สู่ isolated environment
- วัด RTO/RPO จาก exercise ไม่ใช่ configuration
backup ที่สร้างสำเร็จแต่ restore ไม่ได้เป็นเพียง stored failure
EC2 Workload Protection
EC2 ให้ control สูงและทำให้ลูกค้ารับผิดชอบ guest OS/application มากขึ้น:
- hardened, minimal, patched AMI
- remove unused package/service/port
- instance profile แบบ least privilege
- EBS encryption และ snapshot policy
- host logging/EDR/runtime telemetry ตาม risk
- no secrets in user data/AMI
- SSM Session Manager หรือ audited access แทน public SSH เมื่อเหมาะสม
- immutable replacement มากกว่า long-lived manual mutation
Instance Metadata Service
IMDS ให้ temporary credential และ instance metadata แก่ workload Require IMDSv2 เมื่อ compatible:
- ใช้ session-oriented token
- configure account/AMI/instance defaults
- จำกัด hop limit/access ตาม architecture
- block container/untrusted process access เมื่อไม่จำเป็น
IMDSv2 ลด exploit path บางแบบแต่ไม่แก้ SSRF root cause และไม่ลด permission ของ over-privileged role
Container Security Model
container image เป็น packaging/isolation mechanism บางชั้น ไม่ใช่ VM boundary เสมอไป Controls:
- minimal trusted base image และ pinned digest
- non-root user
- read-only root filesystem เมื่อทำได้
- drop Linux capabilities และ no privileged mode
- resource/ulimit controls
- no Docker socket/host path/sensitive device mount
- secret ผ่าน managed runtime path ไม่ bake ใน image
- runtime filesystem/process/network detection ตาม risk
Amazon ECS
แยก identity ให้ถูก:
- Task role: permission ที่ application container ใช้
- Task execution role: ECS agent/runtime ใช้ pull image, fetch config และส่ง log ตาม integration
container ทุกตัวใน task อาจเข้าถึง task-role credential ตาม network namespace/model ต้องไม่รวม container ที่ ต่าง trust ระดับกันไว้ task เดียวโดยไม่วิเคราะห์
ECS บน shared EC2 host ไม่ถือว่า container เป็น strong security boundary ส่วน Fargate task มี isolation boundary ของตน แต่ application/image/IAM/network controls ยังจำเป็น
Amazon EKS
Kubernetes เพิ่ม control plane และ identity หลายชั้น:
- AWS IAM access to cluster
- Kubernetes RBAC/service account
- pod workload identity
- admission/Pod Security controls
- node role/runtime
- network policy
- secret/configuration
pod-to-pod traffic ถูก allow โดย default จนมี NetworkPolicy ที่ implementation enforce และ VPC CNI network policy ไม่ได้เปิดโดย default ต้อง enable/verify feature และสร้าง default-deny policy ตาม namespace
ใช้ EKS Pod Identity หรือ IRSA ให้ role ต่อ workload ไม่ให้ทุก pod รับ node role จำกัดผู้แก้ service account, pod spec และ role trust เพราะเส้นทางเหล่านี้เปลี่ยน identity ได้
Namespace ไม่ใช่ Strong Tenant Boundary โดยตัวเอง
cluster admin, node, admission, network, storage และ shared control plane ยังเป็น trust paths workload ต่าง trust สูงอาจต้องแยก cluster/account เพิ่มตาม threat model
Amazon ECR and Image Supply Chain
ECR enhanced scanning ใช้ Amazon Inspector วิเคราะห์ OS และ language packages แบบ continuous หรือ scan-on-push ตาม configuration แต่ scan result ไม่พิสูจน์ว่า image ปลอดภัยทั้งหมด
pipeline ควร:
- build ใน isolated, ephemeral environment
- pin base/dependency และเก็บ SBOM/provenance
- scan source/dependency/image/IaC
- sign artifact และ verify policy ก่อน deploy
- deploy ด้วย immutable digest ไม่ mutable tag อย่างเดียว
- block critical finding ตาม defined policy/exception
- rebuild เมื่อ base package เปลี่ยน ไม่แก้ container ที่กำลังรัน
- retain artifact/evidence ตาม investigation need
AWS Lambda
Lambda ลด host/runtime operations บางส่วน แต่ function ยังต้องดูแล:
- execution role แบบ function-specific least privilege
- event source authentication/validation และ confused-deputy protection
- dependency/layer integrity
- secret retrieval/cache/rotation
- concurrency/reserved concurrency และ downstream protection
/tmpdata lifecycle และ logging- VPC/egress path
- environment variable exposure และ KMS permissions
function URL หรือ API trigger ที่ public ต้องมี authentication, authorization, WAF/rate/abuse controls ตาม path
Data Exposure Detection
use cases ที่ควรตรวจ:
- KMS key policy/grant/disable/deletion เปลี่ยน
- secret read/rotation failure หรือ access จาก principal ใหม่
- S3 bucket/access point/public policy/ACL เปลี่ยน
- unusual object/database export/snapshot share
- backup/vault/retention protection ถูกแก้
- instance profile/task role/pod identity เปลี่ยน
- privileged container, public node/service หรือ admission bypass
- unsigned/unapproved image digest ถูก deploy
detection ต้องรวม data-plane events เฉพาะที่จำเป็น เพราะ management event อย่างเดียวอาจไม่เห็น object read
Review Checklist
- data classification เชื่อม access, retention, backup, key และ logging policy
- encryption ไม่ถูกใช้แทน tenant/object/application authorization
- KMS แยก administrator/user และจำกัด key policy/grant/context/service
- encryption context ไม่มี PII/secret และ caller ไม่ forge authorization context ได้
- rotation objective ชัด ไม่เข้าใจผิดว่า re-encrypt/revoke old material
- secret rotation test consumer cache, overlap, revoke และ rollback
- S3 public/cross-account/access point/pre-signed paths ถูก inventory
- Object Lock/backup retention ทดสอบ restore พร้อม KMS dependency
- RDS/DynamoDB มี network, identity, query/data-model และ recovery controls
- EC2 require IMDSv2 เมื่อ compatible และ role มี least privilege
- ECS task/execution roles แยก และ container isolation ตรง threat model
- EKS ใช้ workload identity, admission และ enforced default-deny NetworkPolicy
- image pipeline pin/scan/sign/verify digest พร้อม exception lifecycle
- Lambda role/event/dependency/secret/concurrency/egress ถูกจำกัด
สรุป
AWS data protection ต้องรักษาทั้ง access, cryptographic key, recovery และ workload path KMS rotation ไม่ได้ re-encrypt ข้อมูลเดิม, S3 default encryption ไม่แก้ public policy และ container scan ไม่พิสูจน์ความปลอดภัย Control ที่ดีจึงต้องมี owner, lifecycle, negative test, telemetry และ restore/incident exercise