บทที่ 20 · Part 4 — Network Security
Network Defense, Detection & Zero Trust
IDS/IPS/NDR, reconnaissance, DNS/MITM/DDoS defense, Zero Trust identity/policy และ network containment ที่มี telemetry/runbook
firewall อาจ block traffic ที่ไม่อนุญาตได้เกือบทั้งหมด แต่ credential ที่ถูกขโมยยังสร้าง connection ที่ policy ยอมรับ หรือ workload ที่ถูกยึดอาจส่งข้อมูลผ่าน HTTPS ไปยัง destination ที่ดูปกติ Network defense จึงต้องรวม prevention, identity, detection, response และ recovery
Learning Outcomes
- แยก firewall, IDS, IPS และ NDR พร้อม sensor blind spots ได้
- ตรวจ reconnaissance, DNS/MITM และ encrypted-traffic anomalies ได้
- ออกแบบ DDoS defense หลายชั้นและ graceful degradation ได้
- ใช้ Zero Trust กับ user/device/workload/resource โดยไม่เชื่อ network location ได้
- วาง network containment ที่ reversible, auditable และไม่ทำลาย evidence ได้
Detection เริ่มจาก Use Case
อย่าเริ่มจาก “เก็บทุก packet” ให้เริ่มจากเหตุที่ต้องตรวจ เช่น:
- public service ถูก scan/โจมตี parser
- workload ติดต่อ command-and-control หรือ destination ใหม่
- credential ใช้จาก network/device/context ผิดปกติ
- east-west lateral movement หรือ port sweep
- DNS query มี tunneling/beaconing pattern
- data transfer volume ผิด baseline
- policy/routing/firewall ถูกเปลี่ยน
แต่ละ use case ต้องมี telemetry, detection logic, owner, severity, runbook, containment authority และ test
Firewall, IDS, IPS และ NDR
| Control | Mode | จุดแข็ง | จุดระวัง |
|---|---|---|---|
| Firewall | allow/deny path/state | ลด reachability | ไม่รู้ business intent และ policy drift |
| IDS | passive alert | ลด inline availability risk | ไม่ block และต้องมี response |
| IPS | inline detect/block | หยุด pattern ได้ทันที | false positive/latency/choke point |
| NDR | behavior/metadata analytics | east-west/anomaly/context | baseline, encrypted visibility, cost/noise |
ตำแหน่ง sensor สำคัญ: ก่อน/หลัง TLS termination, edge, workload, egress และ data zone เห็นข้อมูลต่างกัน
Encrypted Traffic Visibility
TLS ทำให้ passive sensor ไม่เห็น payload แต่ยังมี metadata:
- source/destination/port/bytes/duration/direction
- DNS/SNI/certificate/handshake metadata ตาม protocol และ privacy policy
- connection frequency/beaconing/failure
- proxy/API/application audit หลัง termination
การ decrypt ทุก traffic สร้าง key/privacy/performance/high-value interception risk ควรเลือกตาม threat/data และใช้ endpoint/application telemetry ร่วมกัน
Reconnaissance และ Scanning
attacker หา inventory/version/route ก่อนโจมตี สัญญาณ:
- connection ไปหลาย ports/hosts ในเวลาสั้น
- 404/401/403/path enumeration
- TLS/HTTP fingerprints ผิด client baseline
- DNS enumeration และ certificate transparency discovery
- cloud control-plane/list actions
rate limit/WAF/firewall ลด noise แต่ asset inventory, patch, minimal exposure และ safe error ลดข้อมูล/พื้นผิว อย่า block scanner แล้วปล่อย debug service เปิดอยู่
DNS Attacks and Defense
| Threat | Controls |
|---|---|
| Cache poisoning/spoofing | protected resolver, DNSSEC validation ตาม architecture, TLS peer verification |
| Domain takeover | DNS/cloud/SaaS ownership inventory + decommission check |
| Tunneling/exfiltration | resolver policy/log, query/volume analytics, egress restriction |
| Rebinding | destination re-validation, IP range policy, isolated fetcher |
| DDoS/amplification | managed authoritative/resolver capacity, no open recursion, response controls |
encrypted/custom DNS อาจ bypass enterprise resolver visibility ต้องมี device/workload egress policy และ privacy decision
MITM และ Local Network Threats
ARP spoofing/rogue Wi-Fi/proxy สามารถคั่น traffic ระดับ local ได้ Controls:
- TLS พร้อม certificate/service identity validation
- secure network access และ switch/Wi-Fi protections ตาม environment
- no plaintext credential/protocol
- VPN/private tunnel เมื่อ threat model ต้องการ แต่ยัง verify application peer
- mTLS/workload identity สำหรับ service boundary
- user/device notification ไม่ควรแทน cryptographic verification
ถ้า client accept-all certificate MITM ชนะแม้ cipher แข็งแรง
DDoS Defense หลายชั้น
| Layer | Strategy |
|---|---|
| Network/transport | anycast/scrubbing/provider capacity, SYN/connection protection |
| Edge/HTTP | CDN, WAF, bot/rate controls, request size/time limits |
| Application | cheap reject, bounded work, cache safe content, load shedding |
| Dependency | queue/bulkhead/concurrency/quota, downstream protection |
| Business | prioritize critical flow, degraded/read-only mode |
| Operations | dashboard, provider contacts, runbook, communication/game day |
autoscaling อย่างเดียวอาจเพิ่มค่าใช้จ่ายหรือดัน load ไป database/provider Degradation policy ที่กระทบ การเข้าถึงเงินต้องมี Product/Operations/Risk owner และทดสอบก่อนเหตุ
Protect Expensive Endpoints
login, OTP, KYC upload, report/export, search และ GraphQL อาจใช้ resource/vendor cost สูง:
- validate/authorize ก่อนงานแพง
- per-subject/object/global concurrency
- cost-aware rate limit
- async queue + bounded worker
- response/upload/decompression limits
- cache เฉพาะผลที่ไม่รั่วข้าม identity
Zero Trust ไม่ใช่ Product
NIST SP 800-207 วางหลักว่าไม่ให้ implicit trust จาก physical/network location หรือ asset ownership และ focus การป้องกันที่ resource
หลักสำคัญ:
- authenticate/authorize subject และ device ก่อน session/resource access
- policy ใช้ identity, device/workload, resource, environment และ current signals
- least privilege ต่อ session/action
- assume network compromised และ protect communication
- observe asset/traffic/access และ re-evaluate/revoke ได้
- cloud-native ใช้ application/service/workload identity เพิ่มจาก IP/user
“อยู่ office/VPN/private subnet” ไม่ใช่เหตุผลให้ข้าม authorization
Policy Decision and Enforcement
Zero Trust architecture มักมี:
- Policy Engine ตัดสินจาก policy/risk
- Policy Administrator สร้าง/ยุติ session/credential/config
- Policy Enforcement Point บังคับทางเข้าถึง resource
- identity/device/resource/telemetry sources
failure semantics ต้องชัด: ถ้า identity/device/policy source ล่ม privileged access จะ deny, ลดสิทธิ์, ใช้ cached decision นานเท่าไร หรือเข้าทาง break-glass อย่างไร
Continuous Verification หมายถึงอะไร
ไม่ได้หมายถึงบังคับ MFA ทุก request แต่หมายถึง policy สามารถใช้ current signal และ re-evaluate เมื่อ:
- identity/role/account state เปลี่ยน
- device posture/credential risk เปลี่ยน
- resource sensitivity/action สูงขึ้น
- session behavior ผิดปกติ
- threat intelligence/incident บอก compromise
ผลอาจเป็น allow, step-up, scope ลด, terminate, quarantine หรือ review โดยคำนึงถึง false positive
Workload Identity
service-to-service Zero Trust ต้องมี:
- unique workload identity ไม่ shared secret หลาย service
- short-lived credential/certificate
- audience/service/action scope
- mTLS/token verification + application authorization
- deployment/image/environment binding ตาม platform
- rotation/revocation และ telemetry
- policy ไม่อิง IP อย่างเดียว
compromised workload ที่มี identity ถูกต้องยังต้องถูกจำกัดด้วย resource/action scope และ egress
Detection Engineering Loop
- ระบุ threat/use case และ expected evidence
- map telemetry coverage/blind spots
- สร้าง logic + severity/context
- replay/simulate test event
- วัด false positive/negative และ detection latency
- เชื่อม runbook/containment
- review หลัง architecture/attack/incident เปลี่ยน
alert ที่ไม่มีคนรับหรือ containment permission เป็นเพียง log query
Network Containment
ตัวเลือกตาม incident:
- revoke identity/session/key ก่อน network block เมื่อ root cause เป็น credential
- quarantine workload ด้วย restrictive policy/security group
- block destination/domain/IP อย่าง time-bound
- disable route/peering/partner connection
- sinkhole/redirect telemetry ตาม authorization
- shift service เข้า degraded mode
Preserve Evidence และ Availability
การ terminate instance, reboot หรือเปลี่ยน route อาจทำลาย volatile evidence/availability containment ควร reversible เมื่อทำได้, บันทึก actor/reason/time, มี decision authority และประสาน incident/forensic/legal/compliance owners ตาม scope
network stateful control อาจไม่ตัด established connection ทันที ต้อง test behavior จริงและ revoke application credential ร่วมด้วย
Telemetry and Privacy
packet/DNS/proxy/device data อาจมี personal/sensitive information กำหนด:
- purpose และ fields ที่จำเป็น
- access/segregation
- retention/deletion
- sampling/redaction
- cross-region/vendor transfer
- incident evidence hold
การเก็บมากที่สุดไม่เท่ากับ detection ดีที่สุด และเพิ่ม breach scope
Testing Checklist
- detection use case ระบุ telemetry/owner/runbook/containment/test
- sensor placement เห็นก่อน/หลัง TLS และ east-west/egress ตาม need
- encrypted traffic ใช้ metadata + endpoint/app telemetry โดยมี privacy policy
- reconnaissance ลดด้วย minimal exposure/patch/safe errors ไม่ block อย่างเดียว
- DNS ownership/resolver/rebinding/exfiltration มี lifecycle controls
- DDoS ครอบคลุม network-edge-app-dependency-business-operations
- Zero Trust ไม่ grant implicit trust จาก office/VPN/private IP
- policy ใช้ user/device/workload/resource/context และมี failure semantics
- workload identity short-lived/scoped/revocable ไม่ shared secret
- containment reversible/audited/preserve evidence และตัด credential ด้วย
สรุป
Network defense ไม่จบที่ firewall Prevention ลด surface, identity/policy จำกัด access, telemetry ตรวจสิ่งที่ผ่าน control และ response จำกัดผล Zero Trust คือ architecture ที่ไม่ให้ implicit trust จาก network location และ re-evaluate access ตาม current context