บทที่ 24 · Part 5 — Cloud Security on AWS

AWS Data & Workload Protection

KMS/key policy, secret lifecycle, S3/Object Lock, database encryption, IMDSv2, ECS/EKS/Lambda isolation และ artifact security

การเปิด encryption checkbox เป็นเพียง control หนึ่งใน data lifecycle หาก principal อ่านข้อมูลได้ตาม policy KMS จะ decrypt ให้ตามสิทธิ์ และหาก key ถูกลบผิด ข้อมูลที่เก็บแบบทนทานอาจอ่านไม่ได้ถาวร Data protection จึงต้องออกแบบ confidentiality, integrity, availability, lifecycle และ workload isolation พร้อมกัน

Learning Outcomes

  • ออกแบบ KMS key policy, grants, separation of duties และ rotation โดยเข้าใจข้อจำกัดได้
  • วาง secret lifecycle ที่รวม consumer rollout, revoke และ incident response ได้
  • ป้องกัน S3/database data ด้วย access, encryption, backup และ retention controls ได้
  • ลด EC2 metadata/container/Kubernetes attack surface ได้
  • แยก identity และ isolation semantics ของ ECS, EKS, ECR และ Lambda ได้

Start with Data Classification

ก่อนเลือก service/control ต้องทราบ:

  • data type และ sensitivity
  • owner/controller/custodian
  • source, consumers และ allowed purposes
  • tenant/subject/record boundaries
  • storage, transit, processing และ export locations
  • retention, deletion, legal hold และ backup copy
  • RTO/RPO และ recovery authority
  • key/secret dependency

classification ควรมีผลต่อ architecture และ policy ไม่ใช่ label ที่ไม่มี enforcement

Encryption ไม่แทน Authorization

encryption at rest ป้องกันบาง threat เช่น storage media/snapshot access นอก authorized service path แต่ principal ที่มี GetObject และใช้ key ได้ยังอ่านข้อความผ่าน service ตามปกติ ดังนั้นต้องมีทั้ง:

  • identity/resource authorization
  • tenant/object-level application authorization
  • transport encryption และ peer validation
  • encryption at rest/key control
  • logging/detection
  • backup/retention/deletion
  • data minimization และ output control

field-level/client-side encryption อาจลด trust ต่อ storage/service layer แต่เพิ่ม key distribution, query, rotation, recovery และ observability complexity

AWS KMS Mental Model

AWS Key Management Service จัดการ KMS keys และ cryptographic operations ผ่าน service control plane ข้อมูลขนาดใหญ่มักใช้ envelope encryption: data key เข้ารหัส payload และ KMS key ปกป้อง data key

ประเด็นสำคัญ:

  • KMS key มี identity/policy/state/lifecycle
  • key policy เป็นฐานของ authorization
  • IAM allow จะไม่มีผล หาก key policy ไม่เปิดให้ account delegate ตามรูปแบบที่ใช้
  • resource service เช่น S3/RDS อาจเรียก KMS ในนาม principal ผ่าน service integration
  • ciphertext/decryptability ผูกกับ Region/key/state/context ตาม operation

Key Policy and Separation of Duties

แยกบทบาทอย่างน้อย:

  • Key administrator: สร้าง/configure/enable/disable/rotate policy แต่ไม่ควร decrypt data
  • Key user: encrypt/decrypt หรือสร้าง data key ตาม workload
  • Service role: ใช้ key ผ่าน service/context ที่จำกัด
  • Auditor: อ่าน configuration/log โดยไม่มี key-use permission

ควรจำกัด:

  • principal และ cross-account access
  • cryptographic operations
  • resource/service ผ่าน kms:ViaService เมื่อเหมาะสม
  • encryption context
  • grants และผู้สร้าง grant
  • key deletion/disable/policy change

Key Deletion คือ Data Availability Decision

การ schedule deletion หรือทำ key ใช้ไม่ได้อาจทำให้ backup, database, log และ retained object อ่านไม่ได้ ต้องมี multi-person authority, delay/alert, dependency inventory และ tested recovery process

Encryption Context

encryption context คือ non-secret key-value metadata ที่ผูกกับ ciphertext แบบ authenticated data decrypt ต้องส่ง context ตรงกับตอน encrypt และใช้เป็น policy condition ได้

ข้อควรระวัง:

  • ไม่ถูกเข้ารหัส
  • อาจปรากฏใน CloudTrail/logs
  • ห้ามใส่ PII, credential หรือ secret
  • canonical name/value และ case ต้องสอดคล้อง
  • consumer ทุกตัวต้องส่ง context ที่ถูกต้อง
  • context ไม่แทน authorization ของ business object หาก caller กำหนดค่าเองได้

KMS Grants

grant มอบ key-use permission ให้ principal และมักใช้กับ integrated AWS services มี lifecycle แยกจาก key policy

แนวทาง:

  • จำกัด operations และ grantee
  • ใช้ constraints/encryption context เมื่อรองรับ
  • จำกัด principal ที่สร้าง/retire/revoke grant
  • inventory grants และลบเมื่อ resource/lifecycle จบ
  • เข้าใจ eventual consistency และ grant token ใน workflow ที่ต้องใช้ทันที

grant ที่หลงเหลือหลัง resource ถูกย้าย/ปิดอาจเป็น access path ที่ review มองข้าม

Key Rotation

automatic rotation ของ KMS key ใช้ได้กับ key type/origin ที่รองรับ เมื่อ rotate:

  • logical key/ARN เดิมยังอยู่
  • key material เก่ายังถูกเก็บเพื่อ decrypt ciphertext เดิม
  • data เดิมไม่ถูก re-encrypt อัตโนมัติ
  • compromised old material ไม่ถูก revoke ด้วย rotation

asymmetric, HMAC หรือ custom key store บางแบบต้องใช้ manual replacement ตาม support matrix

rotation objective ต้องชัดว่าเป็น cryptoperiod hygiene, migration, algorithm change หรือ incident response กรณี compromise อาจต้องสร้าง key ใหม่, re-encrypt/reissue data, เปลี่ยน policy และ revoke path เดิม

Secrets Manager

secret คือ credential/token/key material ที่ application ต้องใช้ ไม่ควรอยู่ใน source, image, AMI, CI log, Terraform state ที่เปิดกว้าง หรือ environment dump

Secrets Manager ช่วย:

  • encrypt secret at rest ด้วย KMS
  • version/staging labels
  • rotation workflow
  • resource policy และ cross-account pattern
  • caching library/private connectivity
  • CloudTrail integration

แต่การเปิด rotation schedule ไม่รับประกันว่า rotation สำเร็จ ต้องทดสอบ:

  1. สร้าง pending credential
  2. ตั้งค่า provider/resource
  3. validate credential ใหม่
  4. promote current version อย่าง atomic
  5. ให้ consumer refresh cache/reconnect
  6. revoke previous credential หลัง overlap ที่กำหนด
  7. rollback เมื่อ partial failure

Secret Rotation อาจสร้าง Outage

database pool, long-running worker และ partner client อาจ cache secret นานกว่า overlap window ต้องมี consumer inventory, metrics และ staged rotation ไม่ควร invalidate credential เดิมก่อน validate ใหม่

Amazon S3

S3 เข้ารหัส object upload ใหม่ด้วย SSE-S3 เป็น default ตั้งแต่ปี 2023 แต่ default encryption:

  • ไม่แก้ public/cross-account access
  • ไม่เปลี่ยน authorization
  • ไม่ rewrite object เดิมเมื่อเปลี่ยน default
  • ไม่แทน TLS, versioning, backup หรือ retention

Access Controls

  • เปิด S3 Block Public Access ในระดับ organization/account/bucket ตาม requirement
  • ใช้ Bucket owner enforced/disable ACLs เมื่อรองรับ use case
  • จำกัด bucket policy และ access point policy
  • require TLS ด้วย policy condition
  • จำกัด source VPC endpoint/organization/account เมื่อเหมาะสม
  • inventory pre-signed URL และ expiry/permission ของ signer
  • เปิด access logging/data events ตาม investigation need

Block Public Access มี precedence หลายระดับและใช้ setting ที่ restrictive ที่สุดที่ applicable แต่ policy review ยังจำเป็นสำหรับ trusted cross-account principal และ data exfiltration

SSE-S3, SSE-KMS and Client-Side Encryption

ModeKey controlTrade-off
SSE-S3S3 managedง่ายและลด key operations
SSE-KMSKMS policy/audit/control เพิ่มKMS quota/cost/policy/availability dependency
Client-sideapplication คุม plaintext/key path มากขึ้นquery, rotation, recovery และ client complexity สูง

SSE-KMS bucket key ลด KMS request/cost บางรูปแบบ แต่เปลี่ยน encryption-context/audit granularity ที่ต้องเข้าใจ

S3 Versioning and Object Lock

versioning ช่วย recover จาก overwrite/delete แต่ไม่ใช่ immutable backup หาก principal ลบ version ได้

S3 Object Lock ให้ WORM protection ต่อ object version และต้องเปิด versioning:

  • Governance mode: ผู้มี bypass permission สามารถลด/ข้าม retention ได้
  • Compliance mode: protected version ลบไม่ได้แม้ root จน retention หมด
  • Legal hold: ไม่มี expiry จน authorized principal ยกเลิก

Object Lock ไม่ทำให้ข้อมูลอ่านได้ตลอด หาก KMS key สูญหาย retained ciphertext อาจอ่านไม่ได้ถาวร ต้องทดสอบ restore ทั้ง object, metadata, key และ application dependency

Relational Database Service

RDS encryption at rest ครอบคลุม underlying storage, logs, automated backups, read replicas และ snapshots ที่เกี่ยวข้องตาม service behavior แต่ยังต้องดู:

  • database account/role และ credential lifecycle
  • network path/Security Group/TLS
  • query parameterization และ application authorization
  • snapshot sharing/export/copy
  • public accessibility และ endpoint DNS
  • audit/error/slow-query log sensitivity
  • backup retention, PITR, cross-Region/account recovery
  • KMS key disable/deletion impact

database encryption ไม่ป้องกัน SQL injection ที่อ่านข้อมูลผ่าน authorized connection

DynamoDB

DynamoDB encrypts data at rest by default แต่ access/data-model controls ยังเป็นหน้าที่ของ application:

  • IAM จำกัด table/index/action
  • condition expression ไม่แทน tenant authorization
  • partition/sort key ต้องไม่เปิด cross-tenant query path
  • Streams/export/backup/PITR มี policy และ retention ของตน
  • global table เพิ่ม Region/data-residency/key considerations
  • capacity/concurrency/conditional writes ปกป้อง integrity/availability

transactional/conditional write ช่วย enforce state invariant แต่ business invariant ที่ข้าม service ยังต้องออกแบบเพิ่ม

Backup Is a Security Control

backup ต้องป้องกัน ransomware, operator error และ control-plane compromise:

  • แยก account/role และ vault policy
  • immutable retention ตาม requirement
  • cross-Region/account copy เมื่อ threat model ต้องการ
  • monitor backup failure และ deletion-policy change
  • inventory encryption keys/dependencies
  • test restore สู่ isolated environment
  • วัด RTO/RPO จาก exercise ไม่ใช่ configuration

backup ที่สร้างสำเร็จแต่ restore ไม่ได้เป็นเพียง stored failure

EC2 Workload Protection

EC2 ให้ control สูงและทำให้ลูกค้ารับผิดชอบ guest OS/application มากขึ้น:

  • hardened, minimal, patched AMI
  • remove unused package/service/port
  • instance profile แบบ least privilege
  • EBS encryption และ snapshot policy
  • host logging/EDR/runtime telemetry ตาม risk
  • no secrets in user data/AMI
  • SSM Session Manager หรือ audited access แทน public SSH เมื่อเหมาะสม
  • immutable replacement มากกว่า long-lived manual mutation

Instance Metadata Service

IMDS ให้ temporary credential และ instance metadata แก่ workload Require IMDSv2 เมื่อ compatible:

  • ใช้ session-oriented token
  • configure account/AMI/instance defaults
  • จำกัด hop limit/access ตาม architecture
  • block container/untrusted process access เมื่อไม่จำเป็น

IMDSv2 ลด exploit path บางแบบแต่ไม่แก้ SSRF root cause และไม่ลด permission ของ over-privileged role

Container Security Model

container image เป็น packaging/isolation mechanism บางชั้น ไม่ใช่ VM boundary เสมอไป Controls:

  • minimal trusted base image และ pinned digest
  • non-root user
  • read-only root filesystem เมื่อทำได้
  • drop Linux capabilities และ no privileged mode
  • resource/ulimit controls
  • no Docker socket/host path/sensitive device mount
  • secret ผ่าน managed runtime path ไม่ bake ใน image
  • runtime filesystem/process/network detection ตาม risk

Amazon ECS

แยก identity ให้ถูก:

  • Task role: permission ที่ application container ใช้
  • Task execution role: ECS agent/runtime ใช้ pull image, fetch config และส่ง log ตาม integration

container ทุกตัวใน task อาจเข้าถึง task-role credential ตาม network namespace/model ต้องไม่รวม container ที่ ต่าง trust ระดับกันไว้ task เดียวโดยไม่วิเคราะห์

ECS บน shared EC2 host ไม่ถือว่า container เป็น strong security boundary ส่วน Fargate task มี isolation boundary ของตน แต่ application/image/IAM/network controls ยังจำเป็น

Amazon EKS

Kubernetes เพิ่ม control plane และ identity หลายชั้น:

  • AWS IAM access to cluster
  • Kubernetes RBAC/service account
  • pod workload identity
  • admission/Pod Security controls
  • node role/runtime
  • network policy
  • secret/configuration

pod-to-pod traffic ถูก allow โดย default จนมี NetworkPolicy ที่ implementation enforce และ VPC CNI network policy ไม่ได้เปิดโดย default ต้อง enable/verify feature และสร้าง default-deny policy ตาม namespace

ใช้ EKS Pod Identity หรือ IRSA ให้ role ต่อ workload ไม่ให้ทุก pod รับ node role จำกัดผู้แก้ service account, pod spec และ role trust เพราะเส้นทางเหล่านี้เปลี่ยน identity ได้

Namespace ไม่ใช่ Strong Tenant Boundary โดยตัวเอง

cluster admin, node, admission, network, storage และ shared control plane ยังเป็น trust paths workload ต่าง trust สูงอาจต้องแยก cluster/account เพิ่มตาม threat model

Amazon ECR and Image Supply Chain

ECR enhanced scanning ใช้ Amazon Inspector วิเคราะห์ OS และ language packages แบบ continuous หรือ scan-on-push ตาม configuration แต่ scan result ไม่พิสูจน์ว่า image ปลอดภัยทั้งหมด

pipeline ควร:

  • build ใน isolated, ephemeral environment
  • pin base/dependency และเก็บ SBOM/provenance
  • scan source/dependency/image/IaC
  • sign artifact และ verify policy ก่อน deploy
  • deploy ด้วย immutable digest ไม่ mutable tag อย่างเดียว
  • block critical finding ตาม defined policy/exception
  • rebuild เมื่อ base package เปลี่ยน ไม่แก้ container ที่กำลังรัน
  • retain artifact/evidence ตาม investigation need

AWS Lambda

Lambda ลด host/runtime operations บางส่วน แต่ function ยังต้องดูแล:

  • execution role แบบ function-specific least privilege
  • event source authentication/validation และ confused-deputy protection
  • dependency/layer integrity
  • secret retrieval/cache/rotation
  • concurrency/reserved concurrency และ downstream protection
  • /tmp data lifecycle และ logging
  • VPC/egress path
  • environment variable exposure และ KMS permissions

function URL หรือ API trigger ที่ public ต้องมี authentication, authorization, WAF/rate/abuse controls ตาม path

Data Exposure Detection

use cases ที่ควรตรวจ:

  • KMS key policy/grant/disable/deletion เปลี่ยน
  • secret read/rotation failure หรือ access จาก principal ใหม่
  • S3 bucket/access point/public policy/ACL เปลี่ยน
  • unusual object/database export/snapshot share
  • backup/vault/retention protection ถูกแก้
  • instance profile/task role/pod identity เปลี่ยน
  • privileged container, public node/service หรือ admission bypass
  • unsigned/unapproved image digest ถูก deploy

detection ต้องรวม data-plane events เฉพาะที่จำเป็น เพราะ management event อย่างเดียวอาจไม่เห็น object read

Review Checklist

  • data classification เชื่อม access, retention, backup, key และ logging policy
  • encryption ไม่ถูกใช้แทน tenant/object/application authorization
  • KMS แยก administrator/user และจำกัด key policy/grant/context/service
  • encryption context ไม่มี PII/secret และ caller ไม่ forge authorization context ได้
  • rotation objective ชัด ไม่เข้าใจผิดว่า re-encrypt/revoke old material
  • secret rotation test consumer cache, overlap, revoke และ rollback
  • S3 public/cross-account/access point/pre-signed paths ถูก inventory
  • Object Lock/backup retention ทดสอบ restore พร้อม KMS dependency
  • RDS/DynamoDB มี network, identity, query/data-model และ recovery controls
  • EC2 require IMDSv2 เมื่อ compatible และ role มี least privilege
  • ECS task/execution roles แยก และ container isolation ตรง threat model
  • EKS ใช้ workload identity, admission และ enforced default-deny NetworkPolicy
  • image pipeline pin/scan/sign/verify digest พร้อม exception lifecycle
  • Lambda role/event/dependency/secret/concurrency/egress ถูกจำกัด

สรุป

AWS data protection ต้องรักษาทั้ง access, cryptographic key, recovery และ workload path KMS rotation ไม่ได้ re-encrypt ข้อมูลเดิม, S3 default encryption ไม่แก้ public policy และ container scan ไม่พิสูจน์ความปลอดภัย Control ที่ดีจึงต้องมี owner, lifecycle, negative test, telemetry และ restore/incident exercise

Further Reading