บทที่ 20 · Part 4 — Network Security

Network Defense, Detection & Zero Trust

IDS/IPS/NDR, reconnaissance, DNS/MITM/DDoS defense, Zero Trust identity/policy และ network containment ที่มี telemetry/runbook

firewall อาจ block traffic ที่ไม่อนุญาตได้เกือบทั้งหมด แต่ credential ที่ถูกขโมยยังสร้าง connection ที่ policy ยอมรับ หรือ workload ที่ถูกยึดอาจส่งข้อมูลผ่าน HTTPS ไปยัง destination ที่ดูปกติ Network defense จึงต้องรวม prevention, identity, detection, response และ recovery

Learning Outcomes

  • แยก firewall, IDS, IPS และ NDR พร้อม sensor blind spots ได้
  • ตรวจ reconnaissance, DNS/MITM และ encrypted-traffic anomalies ได้
  • ออกแบบ DDoS defense หลายชั้นและ graceful degradation ได้
  • ใช้ Zero Trust กับ user/device/workload/resource โดยไม่เชื่อ network location ได้
  • วาง network containment ที่ reversible, auditable และไม่ทำลาย evidence ได้

Detection เริ่มจาก Use Case

อย่าเริ่มจาก “เก็บทุก packet” ให้เริ่มจากเหตุที่ต้องตรวจ เช่น:

  • public service ถูก scan/โจมตี parser
  • workload ติดต่อ command-and-control หรือ destination ใหม่
  • credential ใช้จาก network/device/context ผิดปกติ
  • east-west lateral movement หรือ port sweep
  • DNS query มี tunneling/beaconing pattern
  • data transfer volume ผิด baseline
  • policy/routing/firewall ถูกเปลี่ยน

แต่ละ use case ต้องมี telemetry, detection logic, owner, severity, runbook, containment authority และ test

Firewall, IDS, IPS และ NDR

ControlModeจุดแข็งจุดระวัง
Firewallallow/deny path/stateลด reachabilityไม่รู้ business intent และ policy drift
IDSpassive alertลด inline availability riskไม่ block และต้องมี response
IPSinline detect/blockหยุด pattern ได้ทันทีfalse positive/latency/choke point
NDRbehavior/metadata analyticseast-west/anomaly/contextbaseline, encrypted visibility, cost/noise

ตำแหน่ง sensor สำคัญ: ก่อน/หลัง TLS termination, edge, workload, egress และ data zone เห็นข้อมูลต่างกัน

Encrypted Traffic Visibility

TLS ทำให้ passive sensor ไม่เห็น payload แต่ยังมี metadata:

  • source/destination/port/bytes/duration/direction
  • DNS/SNI/certificate/handshake metadata ตาม protocol และ privacy policy
  • connection frequency/beaconing/failure
  • proxy/API/application audit หลัง termination

การ decrypt ทุก traffic สร้าง key/privacy/performance/high-value interception risk ควรเลือกตาม threat/data และใช้ endpoint/application telemetry ร่วมกัน

Reconnaissance และ Scanning

attacker หา inventory/version/route ก่อนโจมตี สัญญาณ:

  • connection ไปหลาย ports/hosts ในเวลาสั้น
  • 404/401/403/path enumeration
  • TLS/HTTP fingerprints ผิด client baseline
  • DNS enumeration และ certificate transparency discovery
  • cloud control-plane/list actions

rate limit/WAF/firewall ลด noise แต่ asset inventory, patch, minimal exposure และ safe error ลดข้อมูล/พื้นผิว อย่า block scanner แล้วปล่อย debug service เปิดอยู่

DNS Attacks and Defense

ThreatControls
Cache poisoning/spoofingprotected resolver, DNSSEC validation ตาม architecture, TLS peer verification
Domain takeoverDNS/cloud/SaaS ownership inventory + decommission check
Tunneling/exfiltrationresolver policy/log, query/volume analytics, egress restriction
Rebindingdestination re-validation, IP range policy, isolated fetcher
DDoS/amplificationmanaged authoritative/resolver capacity, no open recursion, response controls

encrypted/custom DNS อาจ bypass enterprise resolver visibility ต้องมี device/workload egress policy และ privacy decision

MITM และ Local Network Threats

ARP spoofing/rogue Wi-Fi/proxy สามารถคั่น traffic ระดับ local ได้ Controls:

  • TLS พร้อม certificate/service identity validation
  • secure network access และ switch/Wi-Fi protections ตาม environment
  • no plaintext credential/protocol
  • VPN/private tunnel เมื่อ threat model ต้องการ แต่ยัง verify application peer
  • mTLS/workload identity สำหรับ service boundary
  • user/device notification ไม่ควรแทน cryptographic verification

ถ้า client accept-all certificate MITM ชนะแม้ cipher แข็งแรง

DDoS Defense หลายชั้น

LayerStrategy
Network/transportanycast/scrubbing/provider capacity, SYN/connection protection
Edge/HTTPCDN, WAF, bot/rate controls, request size/time limits
Applicationcheap reject, bounded work, cache safe content, load shedding
Dependencyqueue/bulkhead/concurrency/quota, downstream protection
Businessprioritize critical flow, degraded/read-only mode
Operationsdashboard, provider contacts, runbook, communication/game day

autoscaling อย่างเดียวอาจเพิ่มค่าใช้จ่ายหรือดัน load ไป database/provider Degradation policy ที่กระทบ การเข้าถึงเงินต้องมี Product/Operations/Risk owner และทดสอบก่อนเหตุ

Protect Expensive Endpoints

login, OTP, KYC upload, report/export, search และ GraphQL อาจใช้ resource/vendor cost สูง:

  • validate/authorize ก่อนงานแพง
  • per-subject/object/global concurrency
  • cost-aware rate limit
  • async queue + bounded worker
  • response/upload/decompression limits
  • cache เฉพาะผลที่ไม่รั่วข้าม identity

Zero Trust ไม่ใช่ Product

NIST SP 800-207 วางหลักว่าไม่ให้ implicit trust จาก physical/network location หรือ asset ownership และ focus การป้องกันที่ resource

หลักสำคัญ:

  • authenticate/authorize subject และ device ก่อน session/resource access
  • policy ใช้ identity, device/workload, resource, environment และ current signals
  • least privilege ต่อ session/action
  • assume network compromised และ protect communication
  • observe asset/traffic/access และ re-evaluate/revoke ได้
  • cloud-native ใช้ application/service/workload identity เพิ่มจาก IP/user

“อยู่ office/VPN/private subnet” ไม่ใช่เหตุผลให้ข้าม authorization

Policy Decision and Enforcement

Zero Trust architecture มักมี:

  • Policy Engine ตัดสินจาก policy/risk
  • Policy Administrator สร้าง/ยุติ session/credential/config
  • Policy Enforcement Point บังคับทางเข้าถึง resource
  • identity/device/resource/telemetry sources

failure semantics ต้องชัด: ถ้า identity/device/policy source ล่ม privileged access จะ deny, ลดสิทธิ์, ใช้ cached decision นานเท่าไร หรือเข้าทาง break-glass อย่างไร

Continuous Verification หมายถึงอะไร

ไม่ได้หมายถึงบังคับ MFA ทุก request แต่หมายถึง policy สามารถใช้ current signal และ re-evaluate เมื่อ:

  • identity/role/account state เปลี่ยน
  • device posture/credential risk เปลี่ยน
  • resource sensitivity/action สูงขึ้น
  • session behavior ผิดปกติ
  • threat intelligence/incident บอก compromise

ผลอาจเป็น allow, step-up, scope ลด, terminate, quarantine หรือ review โดยคำนึงถึง false positive

Workload Identity

service-to-service Zero Trust ต้องมี:

  • unique workload identity ไม่ shared secret หลาย service
  • short-lived credential/certificate
  • audience/service/action scope
  • mTLS/token verification + application authorization
  • deployment/image/environment binding ตาม platform
  • rotation/revocation และ telemetry
  • policy ไม่อิง IP อย่างเดียว

compromised workload ที่มี identity ถูกต้องยังต้องถูกจำกัดด้วย resource/action scope และ egress

Detection Engineering Loop

  1. ระบุ threat/use case และ expected evidence
  2. map telemetry coverage/blind spots
  3. สร้าง logic + severity/context
  4. replay/simulate test event
  5. วัด false positive/negative และ detection latency
  6. เชื่อม runbook/containment
  7. review หลัง architecture/attack/incident เปลี่ยน

alert ที่ไม่มีคนรับหรือ containment permission เป็นเพียง log query

Network Containment

ตัวเลือกตาม incident:

  • revoke identity/session/key ก่อน network block เมื่อ root cause เป็น credential
  • quarantine workload ด้วย restrictive policy/security group
  • block destination/domain/IP อย่าง time-bound
  • disable route/peering/partner connection
  • sinkhole/redirect telemetry ตาม authorization
  • shift service เข้า degraded mode

Preserve Evidence และ Availability

การ terminate instance, reboot หรือเปลี่ยน route อาจทำลาย volatile evidence/availability containment ควร reversible เมื่อทำได้, บันทึก actor/reason/time, มี decision authority และประสาน incident/forensic/legal/compliance owners ตาม scope

network stateful control อาจไม่ตัด established connection ทันที ต้อง test behavior จริงและ revoke application credential ร่วมด้วย

Telemetry and Privacy

packet/DNS/proxy/device data อาจมี personal/sensitive information กำหนด:

  • purpose และ fields ที่จำเป็น
  • access/segregation
  • retention/deletion
  • sampling/redaction
  • cross-region/vendor transfer
  • incident evidence hold

การเก็บมากที่สุดไม่เท่ากับ detection ดีที่สุด และเพิ่ม breach scope

Testing Checklist

  • detection use case ระบุ telemetry/owner/runbook/containment/test
  • sensor placement เห็นก่อน/หลัง TLS และ east-west/egress ตาม need
  • encrypted traffic ใช้ metadata + endpoint/app telemetry โดยมี privacy policy
  • reconnaissance ลดด้วย minimal exposure/patch/safe errors ไม่ block อย่างเดียว
  • DNS ownership/resolver/rebinding/exfiltration มี lifecycle controls
  • DDoS ครอบคลุม network-edge-app-dependency-business-operations
  • Zero Trust ไม่ grant implicit trust จาก office/VPN/private IP
  • policy ใช้ user/device/workload/resource/context และมี failure semantics
  • workload identity short-lived/scoped/revocable ไม่ shared secret
  • containment reversible/audited/preserve evidence และตัด credential ด้วย

สรุป

Network defense ไม่จบที่ firewall Prevention ลด surface, identity/policy จำกัด access, telemetry ตรวจสิ่งที่ผ่าน control และ response จำกัดผล Zero Trust คือ architecture ที่ไม่ให้ implicit trust จาก network location และ re-evaluate access ตาม current context

Further Reading