บทที่ 23 · Part 5 — Cloud Security on AWS
AWS Network & Edge Security
VPC routing, Security Group/NACL, private endpoints, trusted ingress, WAF/Shield, egress controls, Network Firewall และ flow visibility
คำว่า “อยู่ใน private subnet” บอกเพียงส่วนหนึ่งของเส้นทาง network ไม่ได้บอกว่า workload มีสิทธิ์อะไร ติดต่อปลายทางใด หรือ attacker ที่ยึด role แล้วจะทำอะไรได้ AWS network security จึงต้องอ่าน routing, resource policy, workload identity และ application authorization ร่วมกัน
Learning Outcomes
- แยก VPC, subnet, route, Internet/NAT Gateway และ Transit Gateway ตามหน้าที่ได้
- ใช้ Security Group กับ Network ACL โดยเข้าใจ stateful/stateless semantics ได้
- ออกแบบ trusted ingress และ DDoS/WAF controls แบบหลายชั้นได้
- ใช้ VPC endpoint/PrivateLink โดยไม่เข้าใจผิดว่า private path แทน IAM ได้
- วาง egress control, Network Firewall และ flow telemetry พร้อมระบุ blind spots ได้
VPC Mental Model
VPC เป็น logically isolated network ที่กำหนด address ranges, subnets, route tables, gateways, endpoints และ resource-level controls การมี VPC ไม่ได้สร้าง default trust ให้ resource ภายใน
packet จะไปถึงปลายทางได้เมื่อองค์ประกอบที่เกี่ยวข้องยอมรับพร้อมกัน เช่น:
- route table มีเส้นทาง
- gateway/attachment/endpoint ทำงาน
- Security Group อนุญาต flow
- Network ACL อนุญาตทั้ง 2 ทิศ
- firewall/proxy policy ยอมรับ
- destination service/resource policy ยอมรับ
- identity/application authorization ยอมรับ operation
network reachability เป็นเพียง prerequisite ไม่ใช่ permission ของ business action
Public and Private Subnets
subnet เป็น public เมื่อ route ทำให้ resource ที่มี public address ติดต่อ Internet Gateway ได้ ส่วน private
subnet ไม่มี direct route ดังกล่าว ชื่อ tag เช่น private-a ไม่ได้พิสูจน์ topology จริง
Internet Gateway
รองรับ communication ระหว่าง VPC กับ Internet สำหรับ resource ที่มี routing/address/control เหมาะสม การ attach gateway อย่างเดียวไม่เปิดทุก resource แต่ route และ public addressing ที่ผิดอาจสร้าง exposure
NAT Gateway
ช่วยให้ resource ใน private subnet เริ่ม outbound connection ไปภายนอกและรับ response ของ flow นั้น NAT ไม่ทำ content inspection, identity authorization หรือ destination trust และไม่ได้ป้องกัน data exfiltration
Private ไม่เท่ากับ Isolated
private workload อาจมี path ผ่าน NAT, Transit Gateway, peering, VPN, Direct Connect, VPC endpoint, load balancer หรือ compromised peer การประเมินต้องเริ่มจาก effective routes และ policies จริง
Reference Traffic Paths
แต่ละ arrow ควรมี protocol, source/destination identity, encryption, authorization, telemetry, owner และ failure behavior ไม่ควรอนุญาตด้วย CIDR กว้างเพราะ “เป็น traffic ภายใน”
Security Groups
Security Group หรือ SG เป็น stateful allow-only filter ที่ผูกกับ elastic network interface/resource:
- ไม่มี explicit deny rule
- response traffic ของ established flow ผ่านตาม state โดยไม่ต้องมี mirror rule ทุกกรณี
- reference SG อื่นเป็น source/destination ได้ใน topology ที่รองรับ
- rule ที่กว้าง เช่น
0.0.0.0/0หรือ::/0ต้องมีเหตุผล - SG ไม่เข้าใจ HTTP path, user หรือ transaction intent
ใช้ SG ตาม workload role เช่น edge-to-api, api-to-database, worker-to-partner proxy แทน SG ร่วมที่เปิด port กว้างทั้ง environment
Stateful ไม่ได้แปลว่า Session Security
state tracking รู้จัก network flow ไม่รู้ว่า application session ถูก revoke แล้วหรือ request ได้รับอนุมัติหรือไม่ เมื่อ incident เปลี่ยน SG connection ที่ tracked อยู่บางแบบอาจไม่ถูกตัดทันที ต้อง test และ revoke application credential/session ร่วมกัน
Network ACLs
Network ACL หรือ NACL เป็น stateless subnet-level filter:
- รองรับ allow และ deny
- evaluate ตาม rule number จากต่ำไปสูงแล้วหยุดที่ match แรก
- inbound/outbound ต้องอนุญาตแยกกัน รวม ephemeral return ports
- ใช้เป็น coarse subnet guardrail หรือ explicit block บางกรณี
- ไม่รองรับ application context และมีข้อยกเว้น traffic ภายใน AWS บางชนิด
NACL ไม่สามารถ block AmazonProvidedDNS/Route 53 Resolver หรือ Instance Metadata Service ต้องใช้ DNS Firewall, host/workload controls, IMDS settings และ identity policy ตามกรณี
| มิติ | Security Group | Network ACL |
|---|---|---|
| Scope | resource/ENI | subnet |
| Rules | allow only | allow และ deny |
| State | stateful | stateless |
| Order | evaluate rule set | lowest rule number first |
| Return traffic | tracked flow | ต้องเขียน rule |
| เหมาะกับ | workload reachability | coarse subnet guardrail |
Routing Boundaries
VPC Peering
เชื่อม VPC แบบ non-transitive การเปิด route กับ SG เพียงอย่างเดียวไม่แก้ overlapping CIDR, DNS, central inspection หรือ scale governance
Transit Gateway
รวม VPC/VPN/Direct Connect routing ผ่าน hub และ route tables หลายชุด ช่วย segmentation ที่ scale แต่ misroute 1 จุดมี blast radius สูง ต้องแยก attachment domains, propagate อย่างตั้งใจและ log changes
VPN and Direct Connect
สร้าง hybrid path แต่ไม่ได้ทำให้ on-premises trusted โดยอัตโนมัติ ใช้ route filtering, segmentation, encryption ตาม threat model, workload identity และ application authorization เพิ่ม
VPC Endpoints and PrivateLink
VPC endpoint ให้ resource ติดต่อ supported AWS/service endpoint โดยไม่ต้องผ่าน public Internet path
- Gateway endpoint: ใช้กับ supported services เช่น S3/DynamoDB ผ่าน route table
- Interface endpoint: สร้าง ENI/private IP ด้วย AWS PrivateLink
ประโยชน์คือควบคุม path และลด public/NAT dependency แต่ต้องดู:
- endpoint policy
- Security Group ของ interface endpoint
- service resource policy เช่น S3 bucket policy
- DNS behavior/private DNS
- workload IAM role
- Region/account/service availability
- logging และ quota
default endpoint policy อาจอนุญาตทุก action/principal/resource ที่ endpoint service รองรับ ควรจำกัดตาม use case Endpoint policy เป็น policy เพิ่มอีกชั้น ไม่แทน IAM หรือ resource policy ของ service
PrivateLink ไม่ใช่ Data Authorization
PrivateLink ทำให้ consumer ติดต่อ service ผ่าน private address/path แต่ provider ยังต้อง authenticate caller, authorize tenant/object/action, validate request และจำกัด provider-side network
Trusted Ingress
public application ควรกำหนดเส้นทาง ingress ที่อนุญาตชัด:
- DNS ชี้ไป controlled edge
- CloudFront/API Gateway/load balancer terminate หรือ forward TLS ตาม architecture
- AWS WAF ตรวจ HTTP(S) request ใน integration point ที่รองรับ
- origin รับ traffic จาก trusted path เท่านั้นเมื่อทำได้
- application authenticate/authorize และ enforce business invariants
หาก origin ยังเข้าตรงได้ attacker อาจ bypass WAF, cache, bot control หรือ request normalization ที่ edge
Edge Services ทำหน้าที่ต่างกัน
| Service | หน้าที่เด่น | ไม่ได้แทน |
|---|---|---|
| CloudFront | CDN/edge distribution, origin access, TLS | application authorization |
| API Gateway | API front door, auth integration, throttling, transformation | database/ledger invariant |
| ALB | L7 load balancing/routing/TLS | WAF rule หรือ user permission |
| AWS WAF | HTTP(S) rule, managed rule, rate/bot controls | DDoS capacity และ business fraud logic |
| Shield Standard | baseline DDoS protection ที่รวมกับบริการ AWS | application degradation/runbook |
| Shield Advanced | enhanced detection/mitigation/support/cost features | secure architecture ทุกชั้น |
managed rule ต้อง tune, monitor false positives และ update ส่วน rate-based rule ไม่เท่ากับ per-account business limit
DDoS and Resilience
AWS capacity/edge services ช่วยรับ volumetric attack แต่ application ยังต้อง:
- reject unauthorized/invalid request ก่อนงานแพง
- cap body, decompression, execution time และ concurrency
- protect database, queue และ partner quotas
- cache เฉพาะข้อมูลที่ปลอดภัยต่อ tenant/identity
- load shed และ prioritize critical flows
- มี degraded/read-only mode ตาม business decision
- monitor cost anomaly และ scaling limit
Availability Policy ที่กระทบธุรกรรม
การ block Region, country, customer segment หรือปิด flow สำคัญต้องมี Product/Operations/Risk owner และ pre-approved runbook โค้ดไม่ควรตัดสิน residual business risk เอง
Egress Control
egress เป็นทั้ง dependency path และ exfiltration path ต้องใช้หลายชั้น:
- route table และ NAT/egress architecture
- Security Group กับ Network Firewall/proxy
- controlled DNS resolver และ DNS Firewall ตาม use case
- VPC endpoint/endpoint policy สำหรับ AWS services
- workload IAM role และ resource policy
- application destination allowlist ที่ canonicalize/resolve อย่างปลอดภัย
- TLS service identity และ request signing/authentication
- bytes/destination/failure telemetry
domain allowlist อย่างเดียวมีความเสี่ยงจาก redirect, DNS rebinding, wildcard, shared hosting และ provider compromise ส่วน IP allowlist แข็งเกินกับ dynamic provider และไม่ได้ยืนยัน service identity
AWS Network Firewall
AWS Network Firewall รองรับ stateless/stateful inspection และ managed/custom rules ใน VPC architecture ที่กำหนด เส้นทางที่ใช้ stateful inspection ต้อง symmetric routing ให้ traffic 2 ทิศผ่าน firewall endpoint เดียวกัน ไม่เช่นนั้น state/inspection อาจผิดหรือ traffic ถูก drop
ก่อน deploy:
- ระบุ centralized หรือ distributed inspection model
- ตรวจ route ทั้ง request/response และ Availability Zone
- กำหนด fail-open/fail-closed behavior ตาม capability/risk
- estimate throughput, quota, latency และ cost
- stage rules ด้วย alert/monitoring ก่อน block เมื่อเหมาะสม
- ป้องกัน policy/route/firewall log จาก unauthorized change
- ทดสอบ failure ของ endpoint, route และ dependency
firewall rule ไม่แก้ over-privileged workload identity หรือ application flaw
DNS Security
Route 53 Resolver, private hosted zones, forwarding rules และ external resolvers สร้าง name-resolution plane ที่ต้อง govern:
- จำกัดผู้สร้าง/เปลี่ยน hosted zone และ resolver rule
- inventory domain ownership และ dangling records
- log query ตาม privacy/retention requirement
- ใช้ DNS Firewall กับ known threat/domain policy ตาม use case
- ป้องกัน split-horizon confusion และ resolver bypass ผ่าน egress
- monitor unusual domain, entropy, volume และ failure
การใช้ custom/external DNS อาจทำให้ AWS detection บางแหล่งมองไม่เห็น query
VPC Flow Logs
Flow Logs บันทึก metadata เช่น interfaces, addresses, ports, protocol, bytes และ accept/reject ตาม field/version ที่เลือก ไม่ใช่ packet capture และไม่เห็น application payload ภายใน TLS
ข้อจำกัดที่ต้องระบุ:
- traffic บางชนิดถูก exclude
- records อาจ skip ตาม capacity/internal error
- aggregation window ทำให้ timing ไม่ละเอียดเท่า packet
- accept ไม่ได้แปลว่า application authorize
- reject ไม่ได้บอกเหตุทุกชั้น
- retention/access/query cost ต้องออกแบบ
ใช้ร่วมกับ CloudTrail, DNS, load balancer/WAF, firewall, application และ endpoint logs เพื่อ reconstruct event
Change and Detection Use Cases
ควร alert หรือ review:
- route/Internet Gateway/NAT/peering/Transit Gateway เปลี่ยน
- SG/NACL เปิด public หรือ high-risk port
- endpoint policy เปลี่ยนกว้างขึ้น
- WAF/Shield/firewall/logging ถูกปิดหรือ bypass
- public IP/load balancer/API endpoint ใหม่
- unusual rejected flows, port sweep หรือ east-west fan-out
- egress destination/bytes/DNS pattern ใหม่
- direct-origin traffic ที่ไม่ผ่าน trusted edge
detection ต้อง map กลับ owner, expected deployment และ containment path
Review Checklist
- subnet classification มาจาก effective route ไม่ใช่ชื่อ/tag
- SG แยกตาม workload flow, ไม่มี public/wide rule ที่ไร้เหตุผล
- NACL stateless rules ครอบคลุม return traffic และไม่ถูกใช้แทน service-specific control
- hybrid/peering/transit routes แยก environment/data zone และตรวจ propagation
- private endpoint มี scoped endpoint/SG/resource/IAM policies
- public origin รับผ่าน trusted edge เท่านั้นเมื่อ architecture รองรับ
- WAF/Shield/rate controls มี owner, tuning, capacity และ degradation runbook
- egress ครอบคลุม route, DNS, firewall/proxy, endpoint และ workload identity
- Network Firewall stateful path symmetric และทดสอบ failure mode
- Flow Logs มี coverage/retention/access พร้อมบันทึก blind spots
- network change/detection เชื่อม expected deployment, owner และ containment
สรุป
AWS network security เป็นการประกอบ routing, stateful/stateless filters, edge, endpoints, identity และ application controls Public/private บอก reachability บางส่วนเท่านั้น VPC endpoint ไม่แทน IAM, NAT ไม่แทน egress policy และ Flow Logs ไม่แทน packet/application evidence Architecture ที่ดีทำให้ path ที่อนุญาตมีน้อย อธิบายได้ และตรวจความเปลี่ยนแปลงได้